TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

How Global Cyberthreats Changed Over 2021

2021-12-01 · Read original ↗

ATT&CK techniques detected

2 predictions
T1046Network Service Discovery
92%
"##ql port 3306 during q3 2021. - lithuania was one of the top source countries for scans around the world during this period, but this is more likely russian cyber - attackers hijacking lithuanian infrastructure. top scanned ports since the internet began, threat actors have scan…"
T1046Network Service Discovery
50%
", january - june 2021 versus july - september 2021. remote access scanning the top three global ports are used for remote administration and logins, meaning that a single successful authentication gives an attacker a direct login to an organization ’ s infrastructure. how commonl…"

Summary

Scans continue against remote logins like VNC, RDP, and SSH, as well as MySQL and Elasticsearch. And what’s going on in Malaysia and Lithuania?