Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

26 New Threat Groups Spotted in 2024: CrowdStrike

CrowdStrike has published its 2025 Global
Threat Report, which warns of faster breakout time and an increase in Chinese activity. 

CrowdStrike insider fake hack

CrowdStrike this week published its 2025 Global
Threat Report, which summarizes the latest adversary tactics and techniques, as well as important trends that defined 2024.

The cybersecurity giant started tracking 26 new threat groups in 2024, which brought the total number of adversaries known by the company to 257. 

CrowdStrike pointed out that China-linked activity surged, with a 150% increase seen across all sectors, and a rise of 200-300% in industries such as financial services, media, manufacturing, and industrials and engineering compared to 2023

One interesting aspect that CrowdStrike has been tracking is breakout time, the time it takes threat actors to move from initial access to high-value assets. This breakout time is important because that is how much time defenders have to detect and respond to an attack before the hackers start establishing deeper control. 

In 2024, the average breakout time in the case of cybercrime intrusions dropped to 48 minutes, from 62 minutes in 2023, and the fastest breakout seen by CrowdStrike last year was just 51 seconds.

Over half of the vulnerabilities seen by CrowdStrike last year were related to initial access, which the company says reinforces the need to secure exposed systems. It also noted that identity-based attacks are increasingly favored over traditional malware attacks. 

Advertisement. Scroll to continue reading.

Access broker activity surged in 2024, increasing by 50% compared to the previous year, and valid credential abuse was involved in 35% of cloud incidents.

The security firm found that 79% of the detections in 2024 were free of malware, which is a significant increase compared to five years ago, when only 40% of detections were malware-free.

The company also found that vishing attacks “skyrocketed”, increasing by 442% between the first and second half of the year. 

“As adversaries scale identity-based attacks and vulnerability exploitation, organizations must adopt proactive defense strategies, including identity verification, risk-based patching, and early detection of credential abuse, to disrupt adversary operations before they escalate,” CrowdStrike recommends. 

The full CrowdStrike 2025 Global
Threat Report is available in PDF format.

Related: WEF Report Reveals Growing Cyber Resilience Divide Between Public and Private Sectors

Related: China Targeted Foreign Investment, Sanctions Offices in Treasury Hack

Related: Cybersecurity Funding Reached $9.5 Billion in 2024

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.