LAS VEGAS – Palo Alto Networks Unit 42 leaders warn of today's global threat landscape creating a perfect storm for attackers to go under the radar, meanwhile ransomware, business email compromise, and phishing attacks continue to surge.

The vendor’s threat intelligence arm was founded in 2014 and has been focused on nation-state actors. “I think the combination of events that are going on today is pretty favorable for the nation-state actors,” Wendi Whitmore, SVP of cyber consulting and threat intelligence at Palo Alto Networks Unit 42, said during a keynote at this week’s Palo Alto Networks Ignite event.

She listed the Shamoon attacks, the SolarWinds hack, and the cyber conflict between Russia and Ukraine as recent examples of major attacks that dominated headlines. And as organizations are too busy dealing with data breaches, supply chain attacks, and other threats every day, this creates a perfect storm for attackers.

“So if you put yourself in the shoes of nation-state actors, you can see how every day when you hear about the Optus breach where 40 million people were impacted …You're hearing about Lapsus$ and its attacks conducting against Uber, Microsoft, Samsung, Okta. Some of the biggest organizations in the world are being breached by the cybercriminal activities,” Whitmore said. “And you can see that if you're a nation-state actor who's looking to continue doing what you've been doing, compromising intellectual property, conducting espionage, establishing a foothold in environments, that this is great because the world and certainly security defenders are bombarded by activity every day. And you really then have an opportunity to potentially fly under the radar.”

Ransomware, Business Email Compromise, Phishing Attacks on the Rise

Meanwhile, ransomware, business email compromise, and phishing attacks continue to be the highlight of this year’s threat landscape, Ryan Olson, VP of threat intelligence at Palo Alto Networks Unit 42 told press during the event.

“2021 certainly was a lot of ransomware, so it was 2022,” he said. “From a contract perspective, especially what we see in our [incident response] cases, it's about a third ransomware and about a third business email compromise.”

Olson pointed out that business email compromise is a major threat but normally doesn't get as much attention as ransomware. But there were 19,000 plus business email compromise cases globally last year, which is more than ransomware cases.

“And it doesn't get a lot of publicity, partly because I think the average number is around $120,000 as what was stolen, which doesn't get the headlines. It's not a $50 million ransom payment. It doesn't shut the company down. And quite frankly, many of the people who are hit by these scams are embarrassed by them. They feel like they were just tricked and they made a mistake and they don't really want to go and talk about it publicly. But it's a billion-dollar fraud every year,” Olson warns.

The third threat he mentioned is phishing attacks and insider threats. “A couple of the trends that were notable for me – one was the attacks from Lapsus$, simply because they were ridiculously successful for a group of near-skipped script kiddies like teenagers who didn't have great OpSec and realize that if they wanted to get access to the backend of a big telecom provider, they could just find someone who works there and pay them some money and they would give them access to the network. That is terrifying to anyone from an insider threat perspective that you could have.”

“You might have a company with 100,000 employees and any one of them can be subject to a relatively small payment with otherwise pretty mature controls. But if they agree to just allow access, and they're going to click their MFA button, whatever it might be at the time that the request comes in. You now have given them access to the network, and Lapsus$ had a lot of success,” Olson said.

He noted some of those techniques deployed by the attackers are relatively straightforward but will end up as “an arrow in the quiver for every threat actor in the future.”

Photo (L-R): Sam Rubin, VP of GTM Strategy; Wendi Whitmore, SVP of cyber consulting and threat intelligence; Ryan Olson, VP of threat intelligence at Palo Alto Networks Unit 42