Article Banner Image

Threat Intelligence

February 21, 2024

Q4 2023 Threat Landscape Report: Threat Actors Breach the Outer Limits

Kroll’s Q4 analysis shows ransomware groups increasingly gaining initial access through external remote services. The quarter presented a complex security landscape with a mix of both positive and negative trends: positively, activity associated with larger ransomware-as-a-service (RaaS) operations, like LOCKBIT and BLACKCAT, declined. However, negative patterns continued, like the ongoing focus of threat actors on the professional services industry (continuing a key trend from Q3 and earlier on in 2023).

Interestingly, there was a notable drop in phishing attempts in Q4 in comparison to Q3. However, this was counterbalanced by the continued evolution of these phishing tactics, for example with a rise in the use of QR codes. Linked to this, yet another trend we observed following on from Q3 was the ongoing dominance of business email compromise (BEC) attacks. 

Kroll observed the renewal of other familiar threats in Q4, such as a rise in ransomware. Even previously terminated malware groups, like the one behind QAKBOT, regrouped and redefined their strategies (with, for example, a reply-chain phishing campaign delivering PIKABOT). These and other trends observed in Q4 2023 point to a testing 2024 for organizations.

Q4 2023 Threat Timeline

Loading component...

Sector Analysis—Professional Services Remain a Key Focus For Attackers

In Q4, Kroll observed that attackers focused heavily on the professional services industry, with slight increases also observed in the health care sector, particularly in respect to ransomware activity. The focus on the professional services industry is the continuation of a trend noted throughout 2023 and follows an sharp increase in cases impacting the sector from 2022 to 2023.

Top 5 Impacted Sectors: 2022 Vs. 2023 (All Threat Incident Types)

Threat Incident Types

Kroll continued to see email compromise dominate as an incident type in Q4. As expected after a lull in Q3, ransomware rebounded during the fourth quarter, accounting for 23% of all cases.

Year-on-Year Comparison: Most Common Threat Incident Types 2022 Vs. 2023

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...