Photo Depicting a Threat Actor Typing on Keyboard at Night
© Sasun Bughdaryan/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

A new dark web report highlights info-stealing malware among the top cyber threats of 2023. While criminals continue to use well-known info-stealers like Raccoon, Vidar, and Redline, researchers also discovered four new variants that are quickly growing in popularity.

These emerging variants are Stealc, Risepro, Lumma, and Silencer, cyber threat intelligence company Cybersixgill said in its State of the Underground 2024 report on Feb. 21.

Info stealers have become increasingly popular in recent years. As the name implies, this sneaky malware can infect your device and swipe your username, password, banking details, and other sensitive information. Criminals may use this stolen data for other nefarious schemes or sell it on the dark web.

Ransomware also evolved in 2023, becoming more targeted and demanding, with criminal operations growing in “professionalism and efficiency,” Cybersixgill said.

Despite a drop in the overall number of ransomware attacks in 2023, the top five ransomware groups — LockBit, CL0P, ALPHV, BlackBasta, and Vice Society — were responsible for 65% of all attacks, and the top 10 for 80% of attacks.

“While advances in threat intelligence and cybersecurity, more stringent regulation, and stepped-up law enforcement activities are putting a dent in cybercriminals’ efforts, malicious actors are focusing on tactics and targets that generate the greatest return,” Dov Lerner, Security Research Lead at Cybersixgill, said in a press release.

Well-Known Info Stealers Continue to Dominate

According to Cybersixgill, Raccoon Stealer had a 56% share of all stealer listings on dark web marketplaces in 2023, followed by Vidar (17%) and Redline (13%).

In June 2023, a study by Group-IB listed Racoon, Vidar, and Redline as the info-stealers used to harvest over 100,000 ChatGPT credentials.

The popularity of these stealers — especially Raccoon’s continued dominance despite the arrest of one of its key administrators in 2022 — illustrates the cybercriminal community’s reliance on them.

But new stealers are also springing up quickly. For instance, on Feb. 22, a newcomer to the underground forum “Crackingx” caused a stir by offering the source code for a sophisticated info-stealer written in Rust programming language.

Ransomware Remains a Major Threat

Cybersixgill also notes that ransomware-as-a-service (Raas) — a business model where ransomware developers sell or lease their malware to other cybercriminals — proliferated on the dark web in 2023. The use of artificial intelligence (AI) for malicious purposes also became more widespread.

The report revealed there were 4,056 ransomware attacks in 2023, representing a -9.2% decline from 2022. However, ransomware groups focused on industries that can afford to pay higher ransoms, with the average payout rising to about $1.5 million in 2023.

“The U.S. accounted for 56% of all ransomware attacks in 2023,” Cybersixgill said.

LockBit — which had its servers and other infrastructure seized by law enforcement this month — maintained its position as the most active ransomware group, accounting for 24% of all ransomware attacks in 2023.

Beyond stealers and ransomware, the report highlighted a 25% increase in stolen credit card data in 2023, with over 12 million cases reported. Notably, the U.S. saw a particularly sharp increase in compromised cards, potentially linked to geopolitical tensions, the report said.

A report by NordVPN last year also showed that over half of the stolen bank cards on the dark web are from the U.S.

As law enforcement continues its crackdown on cybercrime, communication among threat actors has moved to messaging platforms like Telegram, the report said. However, both forums and messaging platforms saw reduced activity in 2023.

Meanwhile, the sale of compromised remote desktop protocol (RDP) ports has practically stopped, reflecting a change in cybercriminal tactics, while the number of compromised endpoints increased by 88% in 2023.

“Interestingly, 75% of compromised endpoints recorded by Cybersixgill in 2023 occurred within the first 6 months of the year, with January achieving a monthly total at a level not previously seen since February 2021,” Cybersixgill said in a statement to VPNOverview.

Key Security Recommendations for Netizens and Organizations

Looking ahead to 2024, Cybersixgill predicts that cybercriminals will continue to adopt AI technology for their illicit activities.

“Threat actors, including ransomware actors, are already using AI to increase the efficiency and effectiveness of aspects of cyber operations, such as reconnaissance, phishing and coding. This trend will almost certainly continue to 2025 and beyond,” the company’s statement said.

To combat these escalating risks, here are some security recommendations for netizens everywhere:

  • Use strong, unique passwords for each account to mitigate the risk of multiple account compromises.
  • Enable multi-factor authentication to add an extra layer of security against unauthorized access.
  • Regularly monitor your financial statements for any unauthorized activity.
  • Set software updates to download automatically.
  • Be wary of unsolicited communications and avoid clicking links or downloading attachments from unknown sources.
  • Use reputable security solutions to provide a defense layer against various cyber threats, including ransomware and stealer malware. For starters, use a strong, trusted antivirus. We’ve conducted extensive tests on antivirus solutions, and Norton emerged on top of our list.

Cybersixgill recommends the following to enhance the cybersecurity posture of organizations:

  • Use advanced defensive strategies to counteract the sophisticated use of emerging technologies like AI and machine learning by threat actors.
  • Continuously monitor for leaks of your assets, employees, and customer data across the cybercriminal underground. Also, set up customizable alerts for leaked credentials or credit card data.
  • Identify high-risk vulnerabilities before they are widely recognized.
  • Educate staff in cybersecurity best practices.
  • Ensure that all software is kept up to date with the latest security patches, especially in light of vulnerabilities like the major MOVEit Transfer issue.

For more news, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment