Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      Zuckerberg used open source to scale AI – now the lock-in begins

      14 July 2025

      South Africa begins complex job of overhauling media laws

      13 July 2025

      Nvidia CEO to hold high-stakes media briefing in Beijing

      13 July 2025

      Blue Label Telecoms to change its name as restructuring gathers pace

      11 July 2025

      Get your ID delivered like pizza – home affairs’ latest digital shake-up

      11 July 2025
    • World

      Grok 4 arrives with bold claims and fresh controversy

      10 July 2025

      Bitcoin pushes higher into record territory

      10 July 2025

      Cupertino vs Brussels: Apple challenges Big Tech crackdown

      7 July 2025

      Grammarly acquires e-mail start-up Superhuman

      1 July 2025

      Apple considers ditching its own AI in Siri overhaul

      1 July 2025
    • In-depth

      Siemens is battling Big Tech for AI supremacy in factories

      24 June 2025

      The algorithm will sing now: why musicians should be worried about AI

      20 June 2025

      Meta bets $72-billion on AI – and investors love it

      17 June 2025

      MultiChoice may unbundle SuperSport from DStv

      12 June 2025

      Grok promised bias-free chat. Then came the edits

      2 June 2025
    • TCS

      TCS+ | MVNX on the opportunities in South Africa’s booming MVNO market

      11 July 2025

      TCS | Connecting Saffas – Renier Lombard on The Lekker Network

      7 July 2025

      TechCentral Nexus S0E4: Takealot’s big Post Office jobs plan

      4 July 2025

      TCS | Tech, townships and tenacity: Spar’s plan to win with Spar2U

      3 July 2025

      TCS+ | First Distribution on the latest and greatest cloud technologies

      27 June 2025
    • Opinion

      In defence of equity alternatives for BEE

      30 June 2025

      E-commerce in ICT distribution: enabler or disruptor?

      30 June 2025

      South Africa pioneered drone laws a decade ago – now it must catch up

      17 June 2025

      AI and the future of ICT distribution

      16 June 2025

      Singapore soared – why can’t we? Lessons South Africa refuses to learn

      13 June 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CambriLearn
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Company News » FortiGuard Labs reports ransomware variants almost double in six months

    FortiGuard Labs reports ransomware variants almost double in six months

    Promoted | Exploit trends demonstrate the endpoint remains a target as work-from-anywhere continues.
    By Fortinet29 August 2022
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    Fortinet has announced the latest FortiGuard Labs Global Threat Landscape Report. View the report here. Highlights include:

    • The ransomware threat is adapting with more variants enabled by ransomware-as-a-service (RaaS).
    • Work-from-anywhere endpoints remain targets for cyber adversaries to gain access to corporate networks. Operational technology (OT) and IT environments are both attractive targets as cyber adversaries search for opportunities in the growing attack surface and IT/OT convergence.
    • Destructive threat trends are evolving, as evidenced by the spread of wiper malware as part of adversary toolkits.
    • Cyber adversaries are embracing more reconnaissance and defence evasion techniques to increase precision and destructive weaponization across the cyberattack chain.

    “Cyber adversaries are advancing their playbooks to thwart defense and scale their criminal affiliate networks. They are using aggressive execution strategies such as extortion or wiping data as well as focusing on reconnaissance tactics pre-attack to ensure better return on threat investment. To combat advanced and sophisticated attacks, organisations need integrated security solutions that can ingest real-time threat intelligence, detect threat patterns, and correlate massive amounts of data to detect anomalies and automatically initiate a coordinated response across hybrid networks.”  — Derek Manky, chief security strategist & VP Global Threat Intelligence, FortiGuard Labs

    Ransomware variant growth shows evolution of crime ecosystems

    Ransomware remains a threat and cyber adversaries continue to invest significant resources into new attack techniques. In the past six months, FortiGuard Labs has seen a total of 10 666 ransomware variants, compared to just 5 400 in the previous six-month period. That is nearly 100% growth in ransomware variants in half a year. RaaS, with its popularity on the dark Web, continues to fuel an industry of criminals forcing organisations to consider ransomware settlements. To protect against ransomware, organisations, regardless of industry or size, need a proactive approach. Real-time visibility, protection and remediation, coupled with zero-trust network access (ZTNA) and advanced endpoint detection and response (EDR), are critical.

    Exploit trends show OT and the endpoint are still irresistible targets

    The digital convergence of IT and OT and the endpoints enabling WFA remain key vectors of attack as adversaries continue to target the growing attack surface.

    Many exploits of vulnerabilities at the endpoint involve unauthorised users gaining access to a system with a goal of lateral movement to get deeper into corporate networks — for example, a spoofing vulnerability (CVE 2022-26925) placed high in volume, as well as a remote code execution (RCE) vulnerability (CVE 2022-26937).

    Also, analysing endpoint vulnerabilities by volume and detections reveals the relentless path of cyber adversaries attempting to gain access by maximising both old and new vulnerabilities.

    In addition, when looking specifically at OT vulnerability trends, the sector was not spared. A wide range of devices and platforms experienced in-the-wild exploits, demonstrating the cybersecurity reality of increased IT and OT convergence and the disruptive goals of adversaries.

    Advanced endpoint technology can help mitigate and effectively remediate infected devices at an early stage of an attack. In addition, services such as a digital risk protection service (DRPS) can be used to do external surface threat assessments, find and remediate security issues, and help gain contextual insights on current and imminent threats.

    Destructive threat trends continue, with wipers widening

    Wiper malware trends reveal a disturbing evolution of more destructive and sophisticated attack techniques continuing with malicious software that destroys data by wiping it clean. The war in Ukraine fuelled a substantial increase in disk-wiping malware among threat actors primarily targeting critical infrastructure.

    FortiGuard Labs identified at least seven major new wiper variants in the first six months of 2022 that were used in various campaigns against government, military and private organisations. This number is significant because it is close to the number of wiper variants that have been publicly detected since 2012.

    Additionally, the wipers did not stay in one geographical location but were detected in 24 countries besides Ukraine. To minimise the impact of wiper attacks, network detection and response (NDR) with self-learning artificial intelligence is helpful to better detect intrusions. Also backups must be stored off-site and offline.

    FortiGuard Labs’ Derek Manky

    Defence evasion remains top attack tactic

    Examining adversarial strategies reveals takeaways about how attack techniques and tactics are evolving. FortiGuard Labs analysed the functionality of detected malware to track the most prevalent approaches over the last six months.

    Among the top eight tactics and techniques focused on the endpoint, defence evasion was the most employed tactic by malware developers. They are often using system binary proxy execution to do so.

    Hiding malicious intentions is one of the most important things for adversaries. Therefore, they are attempting to evade defences by masking them and attempting to hide commands using a legitimate certificate to execute a trusted process and carry out malicious intent.

    In addition, the second most popular technique was process injection, where criminals work to inject code into the address space of another process to evade defences and improve stealth.

    Organisations will be better positioned to secure against the broad toolkits of adversaries armed with this actionable intelligence. Integrated, AI and ML-driven cybersecurity platforms with advanced detection and response capabilities powered by actionable threat intelligence are important to protect across all edges of hybrid networks.

    AI-powered security across the extended attack surface

    When organisations gain a deeper understanding of the goals and tactics used by adversaries through actionable threat intelligence, they can better align defences to adapt and react to quickly changing attack techniques proactively. Threat insights are critical to help prioritise patching strategies to better secure environments. Cybersecurity awareness and training are also important as the threat landscape changes to keep employees and security teams up-to-date.

    Organisations need security operations that can function at machine speed to keep up with the volume, sophistication and rate of today’s cyber threats. AI and machine learning-powered prevention, detection and response strategies based on a cybersecurity mesh architecture allow for much tighter integration and increased automation, as well as a more rapid, coordinated and effective response to threats across the extended network.

    • This promoted content was paid for by the party concerned


    Derek Manky FortiGuard Labs Fortinet
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleHow SkyWire is helping build smart cities and villages
    Next Article Sony to buy mobile game developer in push beyond consoles

    Related Posts

    NEC XON expands cyber shield with Fortinet-backed managed services

    3 July 2025

    NEC XON and Fortinet join forces to strengthen telco, ISP cybersecurity

    25 February 2025

    NEC XON achieves prestigious Fortinet partner designation in South Africa

    10 February 2025
    Add A Comment

    Comments are closed.

    Company News

    $125-trillion traded: Binance redefines global finance in just eight years

    11 July 2025

    NEC XON welcomes HPE acquisition of Juniper Networks

    11 July 2025

    LTE Cat 1 vs Cat 1 bis – what’s the difference?

    11 July 2025
    Opinion

    In defence of equity alternatives for BEE

    30 June 2025

    E-commerce in ICT distribution: enabler or disruptor?

    30 June 2025

    South Africa pioneered drone laws a decade ago – now it must catch up

    17 June 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.