• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
Latest News

Trellix Finds Escalation of Cyberattacks Targeting Critical Infrastructure as Geopolitical Tensions Rise

April 27, 2022 TechDecisions Staff

New Report Details Wiper Malware Aimed at Ukraine and Upsurge in Cyber Threats from Likely Russian-backed Actor in the Fourth Quarter of 2021

News Highlights


  • Advanced persistent threat (APT) actors most often targeted the transportation and shipping sectors in Q4 2021.
  • APT29, believed to conduct operations for Russian government entities, ranked most active among nation-state groups in Q4 2021.
  • Following arrests of REvil ransomware gang members, Lockbit ransomware became the most detected in Q4 2021.
  • Living off the Land (LotL) attacks exploited Microsoft Excel and other native tools to successfully target high-ranking political leaders and executives.
  • Malware was the technique used most often in Q4 2021, accounting for 46% of total cyber incidents.
  • Individuals were the most targeted attack sector, with a 73% increase in detected incidents in Q4 2021.

SAN JOSE, Calif.–(BUSINESS WIRE)–Trellix, the cybersecurity company delivering the future of extended detection and response (XDR), today released its Threat Labs Report: April 2022, examining cybercriminal behavior over the last six months. Key findings from the report include individual consumers being the No. 1 target of cybercriminals, closely followed by the healthcare vertical. Additionally, the transportation, shipping, manufacturing and information technology industries showed a sharp increase in threats.

“We’re at a critical juncture in cybersecurity and observing increasingly hostile behavior across an ever-expanding attack surface,” said Christiaan Beek, Lead Scientist and Principal Engineer, Trellix Threat Labs. “Our world has fundamentally changed. The fourth quarter signaled the shift out of a two-year pandemic which cybercriminals used for profit and saw the Log4Shell vulnerability impact hundreds of millions of devices, only to continue cyber momentum in the new year where we’ve seen an escalation of international cyber activity.”

Threats to Critical Infrastructure

Q4 2021 saw increased cyberactivity targeting sectors essential to the function of society:

  • Transportation and shipping were the target of 27% of all advanced persistent threat (APT) — activity by adversarial and stealthy actors — detections.
  • Healthcare was the second most targeted sector, bearing 12% of total detections.
  • From Q3 to Q4 2021 threats to manufacturing increased 100%, and threats to information technology increased 36%.
  • Of Trellix customers, the transportation sector was targeted in 62% of all observed detections in Q4 2021.

Earlier this month, Trellix released a global Cyber Readiness Report investigating how critical infrastructure providers are preparing for cyberattacks. It found many critical infrastructure providers have not implemented cybersecurity best practices despite high-profile breaches.

Threats to Ukraine

Trellix Threat Labs has been investigating wiper malware and other cyberthreats targeting Ukraine. Wipers render devices within targeted organizations useless by destroying the memory critical to how the devices operate. Trellix analysis of the Whispergate and HermeticWiper malware used before and during the invasion of Ukraine details the similarities and differences of the two strains used to destabilize Ukrainian IT systems by destroying the communications within the country.

Today’s report lists threat actors targeting Ukraine, including Actinium APT, Gamaredon APT, Nobelium APT (also known as APT29), UAC-0056 and Shuckworm APT. Of all APT activity Trellix observed in Q4 2021, APT29 accounted for 30% of the detections.

The report details recommendations for organizations seeking to proactively protect their environment from tactics these actors use. For more background on cyber activity targeting Ukraine, visit the Trellix Threat Center and Threat Labs Blog.

Tactics, Techniques & Procedures

Trellix observed the continued use of Living off the Land (LotL) methods, where criminals use existing software and controls native to a device to execute an attack. Windows Command Shell (CMD) (53%) and PowerShell (44%) were the most-frequently used NativeOS Binaries, and Remote Services (36%) was the most-used Administrative Tool in Q4 2021.

Trellix Threat Labs recently found LotL techniques deployed by DarkHotel, a suspected South Korean APT group, using Excel files to successfully infiltrate luxury hotels and glean information on prominent guests traveling for work and conferences.

Earlier this year, Trellix Threat Labs also identified a multi-stage espionage attack on a prime minister’s office to surveille high-ranking government officials and defense sector business executives. This campaign featured the use of Microsoft’s OneDrive as a Command and Control (C2) server and Excel to gain access to victim environments.

Other methods and techniques gaining traction among cyber adversaries in recent months:

  • Cobalt Strike ranked highest among tools used by APT groups in Q4 2021 — a 95% increase from Q3.
  • Obfuscated files or information, followed by credentials from web browsers, and file and directory discovery were the techniques observed most in Q4 2021.
  • Malware was used most often in reported incidents in Q4 2021, accounting for 46% of total incidents and increasing 15% from Q3 2021.

Threats to Individuals

Notably, the report found a significant — 73% — increase in cyber incidents targeting individuals and positioned people as the top attack sector in Q4 2021. This includes threats executed through social media, mobile devices and other services where consumers store data and credentials. For example, in Q4 2021 Facebook discovered spyware campaigns targeting users around the world and another criminal group leveraged Joker malware to target Android users globally. These attacks are typically politically motivated to follow a person’s interactions and contacts.

This follows the release of In the Crosshairs: Organizations and Nation-State Cyber Threats, a report from Trellix and the Center for Strategic and International Studies which found access to consumer data was and likely will continue to be the motive for nearly half of state-backed cyberattacks.

Q4 2021 Threat Activity

  • Ransomware Families. Lockbit (21%) was the most prevalent ransomware family detected in Q4 2021 — a 21% increase from Q3 — followed by Cuba (18%), and Conti (16%).
  • Ransomware Arrests. REvil/Sodinokibi, the top Ransomware Family detected in Q3 2021, did not rank among most prevalent detections in Q4 due to Global Law Enforcement interventions.
  • Ransomware Increase. Substantial increases in ransomware activity were observed in Italy (793%), the Netherlands (318%), and Switzerland (173%) in Q4 2021. India (70%) and the United Kingdom (47%) also experienced notable increases compared to Q3.
  • Malware Families. RedLine Stealer (20%), Raccoon Stealer (17%), Remcos RAT (12%), LokiBot (12%), and Formbook (12%) amounted to almost 75% of malware families observed in Q4 2021.

Methodology

Threat Labs Report: April 2022 leverages proprietary data from Trellix’s network of over 1 billion sensors along with open-source intelligence and Trellix Threat Labs investigations into prevalent threats like ransomware and nation-state activity. Telemetry related to detection of threats is used for the purposes of this report. A detection is when a file, URL, IP-address or other indicator is detected and reported via the Trellix XDR ecosystem.

Additional Resources

  • Report: Threat Labs Report: April 2022
  • Blog: Trellix Threat Labs Report: Cyberattacks Targeting Critical Infrastructure Rise Along with Geopolitical Tensions
  • Site: Trellix Threat Center

About Trellix

Trellix is a global company redefining the future of cybersecurity. The company’s open and native extended detection and response (XDR) platform helps organizations confronted by today’s most advanced threats gain confidence in the protection and resilience of their operations. Trellix’s security experts, along with an extensive partner ecosystem, accelerate technology innovation through machine learning and automation to empower over 40,000 business and government customers. More at https://trellix.com.

Contacts

Media Contact
Sarah Erman

[email protected]

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Related Content:

  • Virgin Media O2 Partners with VMware to Complete…
  • SEON Expands Advanced Digital Device Fingerprinting to Counter…
  • Akumina Announces 86% Year-over-Year SaaS Bookings Growth as…
  • Skykit Survey: Sharing Data Dashboards Broadly with Employees…

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.