zerofox logo
Advisories

ZeroFox Intelligence 2024 Key Forecast and 2023 Conclusions

|by Alpha Team

banner image

ZeroFox Intelligence 2024 Key Forecast and 2023 Conclusions

TLP:CLEAR

In this ZeroFox Intelligence Assessment, ZeroFox researchers provide a forecast of anticipated cyber threats in 2024 while also including conclusions from observations in 2023.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download View the full report here.

Key Findings

  • The threat from ransomware and digital extortion will very likely remain elevated in 2024, following a record number of extortion incidents observed in 2023. Ransomware groups are likely to continue diversifying their targets over the next year, encompassing small to medium-sized organizations that are more likely reliant upon an aging network infrastructure and often lack sufficient cybersecurity awareness and expertise. Additionally, newly-formed ransomware groups are expected to demonstrate proficiency faster than ever before, largely owing to the proliferation of off-the-shelf tools that will continue to lower entry barriers for would-be threat actors.
  • Initial access brokers (IABs) will almost certainly continue to pose a significant threat to organizations across industries in 2024. The vast majority of access deals will continue to take place off-forum, as IABs will likely continue to prefer private means of communication to sell access and leverage trusted relationships with specific buyers. Illicit access sales are also very likely to continue underpinning the threat from ransomware operators, with security teams needing to be increasingly aware of IABs targeting them directly and indirectly via their upstream operating partners.
  • The threat from social engineering will likely continue on an upward trajectory in 2024.
  • Measured growth in the use of artificial intelligence (AI) for both malicious and defensive applications is anticipated, particularly in information operations (including to spread mis-, dis-, and malinformation), social engineering campaigns, and various threat actor tactics, techniques, and procedures (TTPs). It is likely that AI will continue to be leveraged and experimented with to accelerate reconnaissance of high-value or weak targets, to speed the identification and exploitation of vulnerabilities, and to facilitate malicious payload development and delivery.
  • Critical infrastructure sectors, such as finance, energy, and healthcare, will likely continue to see the greatest cyber-physical threats. Organizations within these sectors will remain the most attractive targets for threat actors, who are expected to continue pursuing lucrative outcomes in the form of intelligence collection, disruptive impacts, and ransom payments. It is also very likely that geopolitical factors will continue to influence the probability for major cyber events that can have severe or catastrophic physical impacts.
  • Multiple key elections taking place in 2024 are expected to drive an increase in various threat actor campaigns throughout the year, including an uptick in election-related scams, disruptive threats, and the spread of disinformation. Both malicious and non-malicious actors will likely increase their use of generative AI and synthetic media to create more effective and persuasive content during 2024 elections, exacerbating the threat posed by mis- and disinformation.
  • An uptick in both the discovery and exploitation of zero-day vulnerabilities in 2024 is predicted, likely underpinned by a shift in the tactics of cybercriminal adversaries as they continue to pivot away from traditional methods of data exfiltration toward a heightened focus on exploiting vulnerabilities for increased financial gain.

Tags: tlp:clear,  all industries,  global