VOOZH about

URL: https://thenewstack.io/modern-attack-methods-jeopardize-cybersecurity-strategies/

⇱ Modern Attack Methods Jeopardize Cybersecurity Strategies - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-11-23 06:00:56
Modern Attack Methods Jeopardize Cybersecurity Strategies
contributed,sponsor-kasten,sponsored,sponsored-post-contributed,
Security / Software Development

Modern Attack Methods Jeopardize Cybersecurity Strategies

There’s a greater than ever need to fight at light speed against cyberbreaches. To ensure defense success, let’s look at a few of the latest threats.
Nov 23rd, 2022 6:00am by Rick Vanover and Dave Russell
👁 Featued image for: Modern Attack Methods Jeopardize Cybersecurity Strategies
Image via Unsplash.
Kasten sponsored this post. Insight Partners is an investor in Kasten and TNS.

For years, cybercriminals have kept up a steady campaign of ransomware attacks, largely by introducing new malware components that threaten to take down entire systems. Statista says 71% of businesses have been victimized by ransomware in 2022 — and hackers show no signs of stopping.

But while malware continues to evolve, the biggest change in today’s attacks is being perpetuated by the hackers themselves. They’re using new malicious techniques to eliminate companies’ ability to plan and communicate, which can ultimately produce a more lethal attack.

One of hackers’ recent methods is to use three to four different chains of attacks simultaneously. Coordinated attacks involving phishing, spam, spoofing, and social engineering open up multiple threat vectors, making it more difficult for a company to respond. But it doesn’t stop there. Methods like intermittent and temporal encryption pose large threats to organizations because they create data quality issues and allow threat actors to use subtle tactics to move under the radar.

Kasten by Veeam® is the Kubernetes backup leader. Its Kasten K10, cloud native data management platform, provides DevOps teams with Kubernetes backup/restore, DR and application mobility. It has deep integrations with relational and NoSQL databases, Kubernetes distributions and clouds providers.  Insight Partners is an investor in Kasten and TNS.
Learn More
The latest from Kasten

The best defense is to prepare for the worst: adopt zero trust architecture and build a strategy around fast responses. There’s a greater than ever need for software and applications to fight at light speed against cyber-breaches. But to ensure defense success, let’s first look at a few of the latest threats.

Intermittent Encryption

Intermittent encryption, or partial encryption, is a new technique threat actors are using to evade detection and corrupt targets’ files more quickly. It’s efficient and deceptive. Encrypting files takes a long time, so cursory data analyses can usually flag malware activity going on under the surface. But new attack methods enable hackers to encrypt parts of files on an intermittent basis, keeping CPU usage low and making it harder for conventional and behavior-based ransomware tools to spot underhanded behavior.

Fileless Attacks Avoid Detection

Another way of evading detection is to employ fileless techniques while deploying ransomware. This is the way advanced persistent threats and nation-state attackers often operate. The attacks they deploy use legitimate, publicly available software tools that can be found in a target’s environment. Threat actors can slip by if they avoid using process names or file hashes that have already been flagged as dangerous indicators

Vulnerabilities in VoIP

The popular “Lorenz ransomware” attacks have tapped a vulnerability that had been used in voice-over-IP devices as an onramp into corporate phone systems and computer networks. Experts say the Lorenz group has pursued the “double exploitation” tactic: selling the data it steals and offering access to victims’ systems to other online attacker groups.

Cybercrime as a Service

The hacker community itself is diversifying. In recent years a “cybercrime as a service” sector has emerged with initial access brokers (IABs) offering the ability to breach companies, steal credentials, and sell access to other attackers. IABs sell to other ransomware operators, who outsource the collection of victims while they focus on extortion and developing their malware. In 2021, there were more than 1,300 IAB listings on major cybercrime forums monitored by the KELA Cyber Intelligence Center.

Multiple Groups Targeting the Same Victim

In KELA’s recent ransomware report, researchers reported that ransomware groups have been attacking each other’s victims over time. For example, three separate groups either claimed a hack on a U.S.-based auto dealer or disclosed identical information about the hack on their own leak sites.

Ways to Combat Ransomware

For businesses to win the ransomware battle, they need education, implementation, and remediation. The best remedy for a security breach is prevention. This can be improved in several ways.

  • Education: Employees need continuing education to ensure that cyber-attackers are not being given access to data and systems they need to initiate a ransomware attack.
  • The 3-2-1-1-0 rule: Offsite and offline backups are necessary to mitigate the effects of ransomware. The 3-2-1-1-0 rule requires that there should always be at least three copies of important data, on at least two different types of media, with at least one off-site, one offline, with zero unverified backups or backups completing with errors.
  • Plan for remediation: Don’t pay the ransom. The only option is to restore data. Implementing a full backup and disaster recovery plan gives organizations the ability to recover data in event of a ransomware attack, minimizing the risk of financial and reputational damage.
  • Build an experienced team: If there were a positive aspect of the ransomware trend is that companies are aware of the threat and willing to allocate additional resources to hire new people to work on ransomware attacks.
  • Embed a continuous compliance system into your security strategy: The best continuous compliance systems link your software production system, supply chains, and data backup and recovery platforms to mobilize instant mitigation and guidance for a solution.
  • Create a security-first culture: Call it zero trust or what you will, but given the high rate of human error behind cybersecurity breaches, and the need for C-suite sign-off to elevate security measures, it is crucial to foster a security-first mentality in company culture. Employees should be trained and aware of potential threats (think phishing emails or clicks) and comfortable to report any breaches immediately.
  • Embrace data protection, backup, and recovery: According to the Veeam Data Protection Trends Report 2022, nearly 90% of organizations are at risk of losing precious data, with 93% unable to recover at least some of their stolen data.

Although the ransomware threat continues to rise and it becomes more challenging to detect a bad actor’s next move, organizations can still fight back and strengthen data security.

Kasten by Veeam® is the Kubernetes backup leader. Its Kasten K10, cloud native data management platform, provides DevOps teams with Kubernetes backup/restore, DR and application mobility. It has deep integrations with relational and NoSQL databases, Kubernetes distributions and clouds providers.  Insight Partners is an investor in Kasten and TNS.
Learn More
The latest from Kasten
TRENDING STORIES
Rick Vanover is the senior director of product strategy for Veeam Software. Rick's IT experience includes system administration and IT management, with virtualization being the central theme of his career recently.
Read more from Rick Vanover
A 30-year veteran in the storage industry, Dave Russell is vice president of enterprise strategy at Veeam, responsible for driving strategic product and go-to-market programs, spearheading industry engagement and evangelizing Veeam's vision for cloud data management at key events across...
Read more from Dave Russell
Kasten sponsored this post. Insight Partners is an investor in Kasten and TNS.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Kasten, Pragma, Veeam.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.