Resources
Research
Resource Library
January 15, 2024
Cyber Conflict And The Erosion Of Trust: Introducing the Cyber Resilience Scorecard
Introducing the Cyber Resilience Scorecard
SecurityScorecard introduces the Cyber Resilience Scorecard, offering leaders and decisionmakers a comprehensive view of global cyber risk.
Our study evaluates geographic regions worldwide for cyber risk preparedness and assesses its correlation with GDP — not only in their own organizations but also in that of their partners
and vendors. We also present insights into threat actors’ identities and the geographical origins behind cyber incidents.
Download the full report by submitting the form.
Cyber Threat Intelligence
January 12, 2024
Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days
Chinese state-sponsored group continues to actively compromise Cisco devices possibly affected by vulnerabilities publicly disclosed in 2019
The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team has identified new infrastructure that appears to be linked to the threat actor group tracked as Volt Typhoon. Volt Typhoon is a state-sponsored group based in China that typically focuses on espionage and information gathering.
Approximately 30% of the Cisco RV320/325 devices observed by SecurityScorecard in a 37-day period may have been compromised by Volt Typhoon.
Cyber Threat Intelligence
January 12, 2024
SecurityScorecard Validation Assessment Summary
Online found SecurityScorecard’s footprinting to be very accurate. Over the course of testing Online evaluated SecurityScorecard’s data for a total of 13 unique, unrelated, and randomly selected domains and found SecurityScorecard’s attribution process to have an accuracy of 95%. The accuracy for positively attributing IP Addresses was found to be 94% while for DNS Records it was found to be 100%.
January 10, 2024
North Korean State-Sponsored Cyber Attack: Unveiling the Intricacies of Threat Actor Group Andariel
SecurityScorecard threat intelligence research on state-sponsored cyberattacks
This SecurityScorecard threat research sheds light on a significant cyber attack attributed to North Korean state-sponsored actors known as Andariel, emphasizing the critical role that South Korea plays both as a target and a source of infrastructure for these threat actors.
The STRIKE Team’s comprehensive analysis revealed new details. Please submit the form to download the full report.
Cyber Threat Intelligence
January 8, 2024
The Increase in Ransomware Attacks on Local Governments
What makes organizations in the public sector vulnerable to ransomware?
Public Sector
STRIKE Team
January 8, 2024
Third-Party Data Breaches in the Energy Sector
Learn more in this resource.
January 8, 2024
School District Attack Illustrates Ongoing Threat of Ransomware to Public Education
Interested in reading the report later? Download it. Download Now Executive Summary After a large U.S. school district recently announced that it had suffered a ransomware attack, SecurityScorecard consulted in-house data and strategic partnership sources to enrich the public reporting on the incident. Many of the issues SecurityScorecard’s ratings platform found to affect this district
Public Sector
January 8, 2024
A detailed analysis of the Menorah malware used by APT34
Executive summary Menorah malware was used by the APT34 group, which targeted organizations in the Middle East and was discovered by Trend Micro in August this year. The malware creates a mutex to ensure that only one copy is running at a single time. It extracts the hostname and the username and computes a hash
January 8, 2024
Cyber Risk Intelligence Update: Hacktivist Involvement in Israel-Hamas War Reflects Possible Shift in Threat Actor Focus
The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team has continued its monitoring of threat actors involved in the war between Israel and Hamas and has integrated this monitoring into its ongoing deep and dark web (DDW) collections. Key takeaways Analysis of these collections appears, as of October 20, to support the following conclusions:
January 8, 2024
A Deep Dive Into ALPHV/BlackCat Ransomware
Executive summary ALPHV/BlackCat is the first widely known ransomware written in Rust. The malware must run with an access token consisting of a 32-byte value (–access-token parameter), and other parameters can be specified. The ransomware comes with an encrypted configuration that contains a list of services/processes to be stopped, a list of whitelisted directories/files/file extensions,
STRIKE Team
January 7, 2024
Brute Force Attempts May Have Preceded Ransomware Attack on School District
Executive Summary: Vice Society Ransomware Group Attack Following reports that an attack by the Vice Society ransomware group was responsible for disrupting a US school district’s operations, SecurityScorecard researchers reviewed available data from internal sources and strategic partnerships. SecurityScorecard’s platform revealed that the school district suffered from issues that our previous research found common among
Public Sector
STRIKE Team
December 14, 2023
Cyber Threat Intelligence Update: New Claims of Attacks Against Israeli SCADA Systems
Executive Summary SecurityScorecard’s ongoing collections from hacktivist channels involved in cyber activity provoked by the conflict in Gaza highlight the international scope of the conflict, with hacktivist groups in Indonesia and Malaysia claiming attacks against organizations in Israel and allied states. As in the other channels SecurityScorecard analyzed previously, these newly-added channels mainly discuss relatively
December 14, 2023
Cyber Risk Intelligence: SecurityScorecard Analysis of Traffic Involving Storm-0558 IoCs
Executive Summary On July 11th, 2023, Microsoft disclosed that a threat actor had obtained a Microsoft private encryption key that allowed attackers to generate tokens enabling access to customers’ Exchange Online and Outlook[.]com accounts. Subsequent research found that the compromised key could have granted access to a wider variety of applications including Azure Active Directory,
December 12, 2023
Japan’s Nikkei 225 Index: The State of Cybersecurity in Japan
The Nikkei 225 Cyber Threat Landscape
Companies were ranked based on various factors, such as network security, potential malware exploits, and patching cadence. To measure cyber risk, SecurityScorecard delivers standardized “A to F” letter grades that measure and validate organizations’ security posture and supply chains in real time. Validation of SecurityScorecard scores using statistical analysis demonstrates that companies with an F rating have a 13.8x greater likelihood of a data breach than companies with an A.
To download the full report, please submit your information.
Cyber Threat Intelligence
Security Ratings
December 5, 2023
Cyber Risk Intelligence: Idaho National Laboratory Data Breach
On November 20, a spokesperson for Idaho National Laboratory (INL) confirmed that it had suffered a data breach. The confirmation followed the SiegedSec threat actor group’s circulation of claims that it had “accessed hundreds of thousands of user, employee and citizen data” on social media and hacking forums.
Public Sector
December 5, 2023
Energy Sector Cybersecurity Report: Navigating Third-Party Cyber Risk
SecurityScorecard Threat Research
SecurityScorecard threat researchers have identified that 90% of the world’s largest energy companies experienced a third party breach in the past 12 months.
Fueling the global economy and daily life, reliance on the energy sector elevates it as a prime target for cyberattacks. Amid economic and political uncertainties, concerns about safeguarding this vital sector intensifies. Attacks on energy not only result in financial losses and disruptions but also ripple through manufacturing, healthcare, and transportation sectors.
Download the full report by submitting the form.
Cyber Threat Intelligence
December 4, 2023
Cyber Risk Intelligence: Iran-Linked Attack on U.S. Water Treatment Facility
On November 25, a U.S. municipal water authority confirmed that one of its booster stations had suffered an attack by a threat actor group known as CyberAv3ngers, which analysts believe acts in support of Iranian geopolitical interests.
Public Sector
November 17, 2023
Cyber Risk Intelligence: Exploitation of CVE-2023-47246
Executive Summary On November 8, SysAid disclosed that the Cl0p ransomware group had exploited a previously unknown vulnerability, now tracked as CVE-2023-47246, in SysAid’s on-premise IT Service Management (ITSM) software. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted SecurityScorecard’s Attack Surface Intelligence data and a partner’s network flow (NetFlow) data to identify
October 20, 2023
A Deep Dive into Cactus Ransomware
Executive summary Cactus ransomware was discovered in March 2023. The malware creates a mutex called “b4kr-xr7h-qcps-omu3cAcTuS” to ensure that only one copy is running at a time. Persistence is achieved by creating a scheduled task named “Updates Check Task”. The ransomware requires an AES key to decrypt the encrypted public RSA key stored in the
October 20, 2023
New Deep and Dark Web Collections Regarding the Israel-Hamas War
Executive Summary With the outbreak of the ongoing war between Israel and Hamas, SecurityScorecard rapidly expanded its deep and dark web (DDW) collections to include messaging channels affiliated with Hamas and other militant groups. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team combined automated analysis of these collections using SecurityScorecard’s large language model
October 16, 2023
Cyber Risk Intelligence: Cyber Activity, Israeli Industrial Control Systems, and the Israel-Hamas War
Executive Summary Following the outbreak of war between Israel and Hamas on October 7, 2023, a wide variety of threat actors began claiming responsibility for cyberattacks against entities linked to both sides of the conflict. Thus far, the attacks claimed by hacktivist groups have been relatively weak in both their impact and sophistication. However, on
Cyber Threat Intelligence