This page was machine-translated and may differ from the original. View original
AhnLab Forecasts Cyber Security Threats in Preparation for the Hyper-connected Era
Diversification of Targeted Ransomware and Mobile Cyber Attacks Expected
AhnLab announced the cyber security threats expected in 2020 to respond to the acceleration of digital transformation.
The five major anticipated security threats are: the full-scale launch of targeted ransomware attacks, the emergence of cloud security threats, increased security threats to special purpose systems and OT, the sophistication of information gathering and theft attacks, and the diversification of mobile cyber attack methods.
AhnLab announced the cyber security threats expected in 2020.
Targeted ransomware attacks intensify
In 2019, ransomware attacks targeting companies and organizations became increasingly frequent around the world, and in Korea as well, Clop ransomware caused damage to numerous companies and organizations.
In 2020, ransomware in the form of Advanced Persistent Threats (APTs) that continuously attack specific targets is expected to continue.
Enterprise-targeted ransomware is expanding its reach into various industrial sectors, and it appears likely to launch indiscriminate attacks on companies and individuals through 'fileless attacks,' which utilize advanced social engineering techniques and system vulnerabilities to directly execute malicious code on a computer without a file.
>
Cloud Security Threats Emerge
In line with the recent trend of many companies migrating their business infrastructure to the cloud to reduce costs and improve operational efficiency, attackers are also expected to focus their attention on cloud environments.
In 2019, there was already a case where customer information stored on cloud servers was leaked at a U.S. financial firm. In 2020, it is expected that security incidents will increase not only due to external attacks on cloud infrastructure but also due to technical flaws in the cloud system itself or user configuration errors.
Increased Security Threats to Special Purpose Systems and OT
In 2020, hacking attacks targeting POS (Point of Sales) devices, ATM (Automated Teller Machine), and OT (Operational Technology) environments in industrial facilities are expected to increase.
Reflecting the growing trend toward a cashless society involving card payments and fund transfers in Korea and around the world, attacks on points where direct financial transactions occur, such as POS systems and ATMs, are expected to increase.
Considering that there were attacks on social infrastructure such as factories and power plants around the world in 2019, it is predicted that as smart factories expand due to the acceleration of the ICT-based Fourth Industrial Revolution, cyber attacks on Industrial Control Systems (ICS) of power plants and industrial facilities will also increase.
Advanced intelligence gathering and extermination attacks
Traditional cyber attacks that infiltrate systems to collect and steal critical information from users or organizations are expected to continue. The scope of information targeted by attackers is expanding beyond IDs and passwords to include personal information and internal corporate data.
As the environment in which most information is transmitted and received within IT infrastructure expands, it appears that all possible information within the IT infrastructure domain will be attacked in 2020. Accordingly, traditional forms of information gathering and theft attacks are expected to remain a major pillar of security threats this year.
Diversification of mobile cyber attack methods
Mobile cyber attacks are expected to diversify from methods that deceive users for financial gain to forms that target the app supply chain itself.
Recently, attackers have been creating and distributing malicious SDKs (Software Development Kits) that are difficult for even mobile app developers to detect. The intention is to ensure that if a mobile app developer uses such an SDK, they end up creating and distributing malicious apps regardless of their original intent.
Through this, attackers can create an environment to distribute apps that perform malicious activities without engaging in direct attacks. Since there is a possibility that such malicious apps could be distributed through legitimate app stores like Google Play, the scale of damage could be even greater, requiring caution.
Han Chang-kyu, Head of AhnLab’s Security Response Center (ASEC), stated, “In line with the recent acceleration of digital transformation, the destructive power of cyber attacks is also gradually increasing,” adding, “We will further strengthen our efforts to develop security solutions and services to respond to threats in the hyper-connected era.”
Diversification of Targeted Ransomware and Mobile Cyber Attacks Expected
AhnLab announced the cyber security threats expected in 2020 to respond to the acceleration of digital transformation.
The five major anticipated security threats are: the full-scale launch of targeted ransomware attacks, the emergence of cloud security threats, increased security threats to special purpose systems and OT, the sophistication of information gathering and theft attacks, and the diversification of mobile cyber attack methods.

AhnLab announced the cyber security threats expected in 2020.
Targeted ransomware attacks intensify
In 2019, ransomware attacks targeting companies and organizations became increasingly frequent around the world, and in Korea as well, Clop ransomware caused damage to numerous companies and organizations.
In 2020, ransomware in the form of Advanced Persistent Threats (APTs) that continuously attack specific targets is expected to continue.
Enterprise-targeted ransomware is expanding its reach into various industrial sectors, and it appears likely to launch indiscriminate attacks on companies and individuals through 'fileless attacks,' which utilize advanced social engineering techniques and system vulnerabilities to directly execute malicious code on a computer without a file.
>
Cloud Security Threats Emerge
In line with the recent trend of many companies migrating their business infrastructure to the cloud to reduce costs and improve operational efficiency, attackers are also expected to focus their attention on cloud environments.
In 2019, there was already a case where customer information stored on cloud servers was leaked at a U.S. financial firm. In 2020, it is expected that security incidents will increase not only due to external attacks on cloud infrastructure but also due to technical flaws in the cloud system itself or user configuration errors.
Increased Security Threats to Special Purpose Systems and OT
In 2020, hacking attacks targeting POS (Point of Sales) devices, ATM (Automated Teller Machine), and OT (Operational Technology) environments in industrial facilities are expected to increase.
Reflecting the growing trend toward a cashless society involving card payments and fund transfers in Korea and around the world, attacks on points where direct financial transactions occur, such as POS systems and ATMs, are expected to increase.
Considering that there were attacks on social infrastructure such as factories and power plants around the world in 2019, it is predicted that as smart factories expand due to the acceleration of the ICT-based Fourth Industrial Revolution, cyber attacks on Industrial Control Systems (ICS) of power plants and industrial facilities will also increase.
Advanced intelligence gathering and extermination attacks
Traditional cyber attacks that infiltrate systems to collect and steal critical information from users or organizations are expected to continue. The scope of information targeted by attackers is expanding beyond IDs and passwords to include personal information and internal corporate data.
As the environment in which most information is transmitted and received within IT infrastructure expands, it appears that all possible information within the IT infrastructure domain will be attacked in 2020. Accordingly, traditional forms of information gathering and theft attacks are expected to remain a major pillar of security threats this year.
Diversification of mobile cyber attack methods
Mobile cyber attacks are expected to diversify from methods that deceive users for financial gain to forms that target the app supply chain itself.
Recently, attackers have been creating and distributing malicious SDKs (Software Development Kits) that are difficult for even mobile app developers to detect. The intention is to ensure that if a mobile app developer uses such an SDK, they end up creating and distributing malicious apps regardless of their original intent.
Through this, attackers can create an environment to distribute apps that perform malicious activities without engaging in direct attacks. Since there is a possibility that such malicious apps could be distributed through legitimate app stores like Google Play, the scale of damage could be even greater, requiring caution.
Han Chang-kyu, Head of AhnLab’s Security Response Center (ASEC), stated, “In line with the recent acceleration of digital transformation, the destructive power of cyber attacks is also gradually increasing,” adding, “We will further strengthen our efforts to develop security solutions and services to respond to threats in the hyper-connected era.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.













