TrendAI Modern Bank Heist: The Industrial Age of Cybercrime | #cybercrime | #infosec


Business email compromise (BEC) and reverse business email compromise (RBEC) schemes, both enhanced by deepfakes, followed at 28%.

Nearly four in 10 (37%) of respondents confirmed instances of “island hopping”, where attackers compromise an organisation’s infrastructure and then use it as a launch point against customers.

All of this comes at a time when 54% of organisations report no increase in security budget, a situation TrendAI describes as leaving security leadership “structurally subordinated”.

Steganography hides attack traffic

To conceal attack infrastructure, cybercriminals are embedding commands within image pixels that malware can retrieve later.

One example cited by TrendAI is the Daserf backdoor, which uses steganographic algorithms such as RC4 alongside base64 encoding.

This method allows Daserf to establish covert command-and-control channels that can pass beneath traditional traffic inspection.

Nation-state actors, including Pawn Storm, use steganography in combination with legitimate cloud services to avoid endpoint monitoring altogether.

Cybercriminals are also known to exploit compromised cloud storage buckets to distribute malicious code hidden inside images.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW