Darktrace Blog Posts
Archive
Todos los blogs
Gracias. Hemos recibido su envío.
¡Ups! Algo salió mal al enviar el formulario.
This blog analyzes the Socks5Systemz botnet observed targeting multiple customers across the Darktrace customer base in 2023. Darktrace’s anomaly-based approach to threat detection enabled it to identify malicious activity associated with the botnet before any threat intelligence had been published.
2024
Mar 22, 2024
No se ha encontrado ningún artículo.
This blog details Darktrace’s investigation into the Pikabot loader malware, observed across multiple customers in 2023. In an October 2023 incident, Darktrace identified Pikabot employing new tactics that may have bypassed traditional security measures. With Darktrace’s support, the customer was able to contain the attack and prevent it from escalating into a ransomware infection.
2024
Mar 19, 2024
No se ha encontrado ningún artículo.
Cloud Migration is a gateway to a new era of efficiency, scalability, and opportunity. This is not just a technological shift but a revolution in how businesses operate, innovate, and scale in the digital landscape. This blog will cover strategies, types, and risks associated with cloud migration.
2024
Mar 12, 2024
Cloud
This blog discusses an example of a malicious actor utilizing the cloud storage service Dropbox in order to carry out a phishing attack against a Darktrace customer. Thanks to Darktrace/Email and Apps, this compromise was promptly brought to the attention of the customer and shut down.
2024
Mar 8, 2024
Apps
Email
This blog, written by Jamie Woodland, Head of Technology at Community Housing Limited, describes their experience adding Darktrace’s AI-assisted incident response and AI cyber-attack simulation to enhance incident response efforts for their security team.
2024
Mar 4, 2024
No se ha encontrado ningún artículo.
In October 2023, the network of a Darktrace customer was targeted with ALPHV, or BlackCat, ransomware. An investigation into the attack revealed the usage of methods associated with the Nitrogen campaign, such as ‘malvertising’ and the distribution of malicious Python packages.
2024
Feb 29, 2024
No se ha encontrado ningún artículo.
Quasar is a legitimate remote administration tool that has become popular among threat actors due to its range of capabilities and availability in open source. This blog details how Darktrace detected this tool without using signatures and how Darktrace RESPOND can be configured to block its malicious usage.
2024
Feb 23, 2024
No se ha encontrado ningún artículo.
In this blog we discuss Gootloader, a popular loader malware variant that was observed affecting a Darktrace customer in late 2023. Darktrace was able to identify and contain the suspicious attack activity before it could become a disruptive network compromise.
2024
Feb 15, 2024
No se ha encontrado ningún artículo.
This blog explores a series of CoinLoader compromises observed by Darktrace in late 2023. CoinLoader is a loader malware known to carry out cryptocurrency mining on infected devices. Darktrace’s autonomous detection and response capabilities allowed it to identify and shut down compromises in the first instance.
2024
Feb 8, 2024
No se ha encontrado ningún artículo.
Since January 15, 2024, Darktrace’s SOC and Threat Research teams have observed a surge in malicious activities targeting Ivanti Connect Secure (CS) and Ivanti Policy Secure (PS) appliances. This blog provides details of these activities, along with details of Darktrace's coverage of associated patterns of network traffic..
2024
Jan 26, 2024
No se ha encontrado ningún artículo.
This blog explores Darktrace’s investigation into a series of CyberCartel compromises that were detected across its customer base throughout 2023. CyberCartel is known to target government agencies and taxpaying individuals throughout Latin America.
2024
Jan 8, 2024
No se ha encontrado ningún artículo.
In late August 2023, Darktrace observed malicious actors exploiting vulnerabilities on Ivanti Sentry servers within customer networks. Following these successful exploits, a variety of cryptomining and reconnaissance tools were delivered. In this blog, we will provide details of these chains of activity, along with details of Darktrace/Network’s coverage of the steps involved in them.
2023
Dec 20, 2023
No se ha encontrado ningún artículo.
Generative AI and other open-source tools are allowing threat actors to launch targeted 'one-on-one' attacks at scale. Security tools that apply AI in the wrong way won't see new and targeted attacks coming - but Self-Learning AI that trains itself on your data can. This blog compares cyber security AI approaches and methods.
2023
Dec 13, 2023
No se ha encontrado ningún artículo.