https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Channel Research


Shutterstock

Cloaked hacker

Trellix Report: Business Service Providers Heavily Targeted by Cybercriminals

  • Written by Edward Gately
  • July 18, 2022
Ransomware payouts declined during the first quarter.

A new Trellix threat report shows companies providing IT, finance and other types of consulting and contract services are increasingly targeted by cybercriminals.

The Trellix summer 2022 threat report analyzes cybersecurity trends and attack methods from the first quarter of 2022. It also features research from Trellix Threat Labs into connected health care and access control systems.

Key findings from the Trellix report include:

  • Business services accounted for 64% of total U.S. ransomware detections and was the second most targeted sector behind telecom across global ransomware detections, malware detections and nation-state backed attacks in the first quarter.
  • Following the January arrests of members of the REvil ransomware gang, payouts to attackers declined. Trellix also observed ransomware groups building lockers targeting virtualization services with varied success. Leaked chats from the quarter’s second most active ransomware gang, Conti, publicly expressed allegiance to the Russian administration. This seems to confirm the government is directing cybercriminal enterprises.
  • Telemetry analysis revealed phishing URLs and malicious document trends in email security. Most malicious emails detected contained a phishing URL used to steal credentials or lure victims to download malware. Trellix also identified emails with malicious documents and executables like infostealers and trojans attached.

Surprising Findings

Christiaan Beek is Trellix‘s lead scientist and senior principal engineer.

Trellix's Christiaan Beek

Trellix’s Christiaan Beek

“The persisting success of living off the land (LotL) and email attacks that use vulnerabilities that have been known for years surprises me,” he said. “Many businesses ignore suggested expert guidance, opening the door to preventable attacks. The consequence of such outdated strategies is further reflected in our findings.”

Additionally, the aftermath of the Conti group’s internal communications leak provided surprising data, Beek said.

“While the group’s initial reaction was to doubledown, there was a notable overall drop in activity from the largest ransomware gangs in this latest report,” he said. “This decrease was contextualized by a new trend: ransomware gangs publicly aligning themselves with nation-states to target critical infrastructure. In tandem, we have seen increased activity from groups that make use of the focus on Ukraine to infiltrate Russian companies and governments, contributing to a shocking 490% increase in incidents targeting Russia.”

One of the biggest impacts criminals can have on a business services organization is shutting down their clients’ operations, Beek said.

“We saw this with the attack on Kaseya when a number of grocery stores had to shut down,” he said. “This causes loss of income for the business, but also has potential for resounding effects to the public’s daily lives. Another example is the increasing attacks on health care providers. Health care is a non-stop operation with a focus on patient health. Disrupting hospital systems impacts care, treatment and
scheduled surgeries, creating the potential for literal life-and-death situations.”

MSPs, MSSPs Need Cyber Incident Response Plans

MSPs and MSSPs can’t let the weight of their responsibility to keep their clients operational impact their ability to mitigate an attack quickly and strategically, Beek said. It’s table stakes to have a cyber incident response plan.

“Supply chain attacks have been a tremendous focus since some major attacks resulted in the breach of critical infrastructure,” he said. “MSPs should be aware that they are an interesting target through which threat actors can access multiple victims; similar to the movie Lord of the Rings, one ring rules them all.”

Although financial sanctions due to the Russia-Ukraine conflict slowed down some ransomware operations, several groups are ramping up their attacks and new groups are surfacing, Beek said. Additionally, with cryptocurrency prices on the low end, cryptocurrency mining and attacks related to gaining cryptocurrency are increasing.

“It’s like buying stock when prices are low and aiming for the near future to expect the value to go up — like a short-term investment,” he said.

It’s encouraging to see ransomware rates and payouts to gangs declining, Beek added.

“This signals a few things,” he said. “The public and businesses are getting more confident in reporting ransomware activity rather than paying out, and law enforcement actions against cybercriminals deters activity.”

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Edward Gately or connect with him on LinkedIn.
Tags: MSPs VARs/SIs Best Practices Channel Research Cloud Security Strategy Vertical Markets

Most Recent


  • Beyond Pride
    'Beyond Pride,' a Free DE&I Webinar on Workplace Culture for LGBTQ+
    Allies and awareness are key to helping LGBTQ+ employees feel safe.
  • Navigate business
    How Partners Can Navigate Economic Uncertainty, Possible Recession Ahead
    The biggest mistake is companies waiting too long to reduce costs.
  • Cyber insurance
    Now Is the Time to Consider Cyber Insurance for Your Business
    If your business is online and accesses sensitive data, the need for cyber insurance is becoming critical.
  • Telarus leadership team
    Images: Telarus Hosts Partner Summit, Gives Partner, Supplier Awards
    See who landed Telarus' top partner award.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • trends speech cloud
    QuoteWerks 2022 Trends Report: Continued Concerns With Product Sourcing Rampant
  • investing in remote work
    Hybrid Work = Cloud: How Partners Can Seize the Moment
  • Alternative Cloud
    Report: More Organizations Sourcing Alternatives to AWS, Azure, Google Cloud
  • Threat Detection Malware
    Microsoft Office Most Targeted Software for Malware Attacks

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Images: Telarus Hosts Partner Summit, Gives Partner, Supplier Awards

August 5, 2022

7 Channel People Making Waves This Week at Kaseya, AT&T, Cohesity, More

August 5, 2022

The Gately Report: Zscaler Tracks New, Increasingly Dangerous Ransomware Group, Most Targeted Types of People

August 5, 2022

Industry Perspectives

View all

Seize the Application Modernization Opportunity

August 2, 2022

A Growth Mindset: Your Organization’s Strategic Differentiator

August 1, 2022

Timely Tips for Non-Negotiable Patch Updates

July 29, 2022

Webinars

View all

Outsmarting RaaS: Implementation Strategies To Help Your Clients Before, During, and After a Ransomware Attack

August 23, 2022

Why it is Important to Upgrade Aging Servers and How to use Live Optics to Upgrade Efficiently

August 25, 2022

Executives at Home are Not Alright: An Intro to Digital Executive Protection

September 8, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

May 6, 2022

Twitter

ChannelFutures

[email protected] produced a 50-minute webinar on creating a work culture in which LGBTQ+ employees feel safe. You can… twitter.com/i/web/status/1…

August 8, 2022
ChannelFutures

#MSPSummit preview: Surviving, thriving during economic rough seas with @SL-Index's Peter Kujawa.… twitter.com/i/web/status/1…

August 8, 2022
ChannelFutures

.@ConnectWise says use #cyberinsurance policies to protect from worst of cyberattack repercussions, but first beef… twitter.com/i/web/status/1…

August 8, 2022
ChannelFutures

Check out our pictures from the #TelarusPartnerSummit that @telarus hosted in Salt Lake City.… twitter.com/i/web/status/1…

August 5, 2022
ChannelFutures

Channel People Making Waves This Week Include: @spoonen, @RoyArsan, @TheAnneChow, @AnuragTechaisle… twitter.com/i/web/status/1…

August 5, 2022
ChannelFutures

.@RingCentral plans #layoffs after strong Q2 earnings. dlvr.it/SW7kd5 https://t.co/OIlLuYgyLJ

August 5, 2022
ChannelFutures

.@msftsecurity makes upgrades to #MicrosoftDefender. dlvr.it/SW7cpg https://t.co/KbPsyM8eYe

August 5, 2022
ChannelFutures

.@ZeroFox goes public after #SPAC merger. #cybersecurity dlvr.it/SW7NjC https://t.co/IhaO9vgDh7

August 5, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X