TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Huntress

2024: Revisiting a Year in Threats | Huntress

2024-12-31 · Read original ↗

ATT&CK techniques detected

6 predictions
T1486Data Encrypted for Impact
98%
“: safepay ransomware october introduced a new ransomware variant with no prior reporting in the industry. by uncovering incidents where safepay was deployed, we were able to provide analysis of the ransomware ' s behavior and detection opportunities. revisit the blog : cleo softw…”
T1486Data Encrypted for Impact
95%
“tuesday : boinc software exploited by socgholish july saw new behaviors from the malware socgholish, including the use of the legitimate volunteer computing software boinc. through malicious installations, boinc could be configured to connect to look - a - like servers to collect…”
T1190Exploit Public-Facing Application
68%
“2024 : revisiting a year in threats | huntress before you pop the bubbly and count down to a new year, let ’ s reminisce for a moment. looking back on the past 365 days, it was clear cybercriminals had no intention of slowing down. but neither did we. our analysts worked tireless…”
T1080Taint Shared Content
49%
“: safepay ransomware october introduced a new ransomware variant with no prior reporting in the industry. by uncovering incidents where safepay was deployed, we were able to provide analysis of the ransomware ' s behavior and detection opportunities. revisit the blog : cleo softw…”
T1190Exploit Public-Facing Application
38%
“- 2024 - 1709 - a catastrophe for control : understanding the screenconnect authentication bypass ( cve - 2024 - 1709 & cve - 2024 - 1708 ) - think your screenconnect server is hacked? here ’ s what to look for. - slashandgrab screenconnect post - exploitation in the wild ( cve -…”
T1219Remote Access Tools
34%
“- 2024 - 1709 - a catastrophe for control : understanding the screenconnect authentication bypass ( cve - 2024 - 1709 & cve - 2024 - 1708 ) - think your screenconnect server is hacked? here ’ s what to look for. - slashandgrab screenconnect post - exploitation in the wild ( cve -…”

Summary

Take a look back at some of the biggest threats we observed and analyzed in 2024.