CrowdStrike's latest report highlighted the stark reality that while the cyberattack speed continues to accelerate at an alarming rate, with the fastest breakout time observed at just 2 minutes and 7 seconds, the majority (70%) of incidents still take more than 12 hours to resolve.
The security vendor defines breakout time as the time after adversaries gain initial access to a network, how it takes them to “break out” and move laterally from the compromised host to other hosts within the environment.
In its 10th annual Global Threat Report, CrowdStrike found the average breakout time for interactive eCrime intrusion activity in 2023 was 62 minutes, which represents a significant decrease from the 79-minute average recorded in 2022.
“In years past, we've seen this breakout time kind of go from hours to 84 minutes, to 79 minutes, and now 62 minutes, so the adversary continues to get faster and faster,” Adam Meyers, CrowdStrike SVP of Counter Adversary Operations, said during a press pre-briefing, adding the fastest breakout time decreased from around 7 minutes in 2022 to 2 minutes and 7 seconds last year. “The adversary continues to get faster and faster.”
The report uses a real-world hands-on attack as an example to illustrate the speed at which attackers can compromise a system. In this detailed example, attackers used 39 minutes and 26 seconds to Successfully compromise identity with a brute-force attack. Then, it took an adversary less than 5 minutes from Initial login with valid credentials, dropping a legitimate signed tool to gather system information to attempting to deploy ransomware. The attackers later used 4 minutes and 38 seconds to open the control panel attempting to identify security software in use.
This example highlights that a significant portion of the attack time is dedicated to breaking in and gaining initial access, often through exploiting weak or stolen credentials.
“Once an initial compromise occurs, it only takes seconds for adversaries to drop tools and/or malware on a victim’s environment during an interactive intrusion,” CrowdStrike’s report wrote. “However, the saying ”time is money“ holds true for adversaries. More than 88% of the attack time was dedicated to breaking in and gaining initial access. By reducing or eliminating this time, adversaries free up resources to conduct more attacks.”
Interactive intrusion on the riseCrowdStrike also warns of the widespread use of hands-on or “interactive intrusion” techniques.
The term “interactive intrusion” is used to describe activity where adversaries actively execute actions on a host to accomplish their objectives. Unlike automated malware attacks that depend on the deployment of malicious tooling and scripts, interactive intrusions leverage the creativity and problem-solving skills of human adversaries, the vendor explained.
“These individuals can mimic expected user and administrator behavior, making it difficult for defenders to differentiate between legitimate user activity and a cyberattack,” the report wrote.
In 2023, the report found a 60% year-over-year surge in the number of interactive intrusion campaigns, with a 73% increase in the second half compared to 2022, as adversaries increasingly exploit stolen credentials to gain initial access at targeted organizations.
“They are malware-free, they don't use malware for that initial access, that means you're using an exploit to come in through an unmanaged device, or their social-engineering their way in or they're buying access through or stealing credentials or something like that,” Meyers said.
He added the interactive intrusion campaigns involve “a human operator being behind all the data.”
“It's not so much a malware that gets deployed through email and somebody opens it up and deploys the malware and then it becomes part of a botnet, right? That's not really an interactive intrusion. That's that's more what a lot of organizations have traditionally seen,” Meyers said. “When I say interactive intrusion or hands on the keyboard, there's a human on the other side of that incident, and we can see them change and adapt and move.”
Comments