This page was machine-translated and may differ from the original. View original
Top 5 Cyber Security Threats of 2023, "No Single Master Key to Security"

▲ 2023 Top 5 Cyber Security Threat Forecasts (Image - AhnLab)
AhnLab Announces Forecasts for Top 5 Cyber Security Threats
Major security threats for next year are projected to include: ransomware organizations pursuing a 'Quantity to Quality' strategy; 'parasitic' attacks that leak a company's core information over a long period becoming the norm; continued discovery and exploitation of high-impact 'jackpot' vulnerabilities; expansion of supply chain attacks into mobile environments; and intensification of attacks targeting individuals' virtual asset wallets.
AhnLab (CEO Kang Seok-kyun) announced the '2023 Top 5 Cyber Security Threat Forecasts' on the 24th, summarizing the outlook for cyber security threats expected in 2023.
Kim Gun-woo, Head of AhnLab’s Security Response Center (ASEC), stated, “Due to digitalization across society, security is no longer an issue for specific entities only.” “Attackers will continue to utilize every attack point to maximize effectiveness,” he said, adding, “It is a time when a multifaceted approach by organizations and users is needed rather than looking for a single master key to security.”
■ Ransomware Organizations Pursue 'Quantity to Quality' Strategy
With the recent emergence of new ransomware slowing down, ransomware attack groups are expected to pursue a "quality over quantity" strategy going forward, aiming for maximum profit and impact with minimal attacks.
To this end, attack groups are expected to first seize control of the organization's core infrastructure and then relentlessly target a single objective through a 'multiple threat' that combines data leakage, ransomware infection, and DDoS attacks.
Furthermore, as investigations and arrests of ransomware organizations continue globally, there is a possibility that pressured cybercriminals may launch large-scale attacks and then retire. Therefore, in addition to establishing basic security systems, organizations must utilize Threat Intelligence (TI) to identify the latest attack trends and vulnerability information.
■ 'Parasitic' attacks that leak core organizational information over long periods are becoming the norm
This year, attacks targeting virtual asset exchanges, large corporations, and public institutions possessing key assets such as technology or personal information continued, and some attack groups even disclosed their achievements externally. Since attackers also place importance on 'return on investment,' attempts to steal core technologies and assets from major institutions and companies are expected to continue next year, but the methods are likely to become more covert and sophisticated.
In particular, rather than "show-off" attacks that destroyed or exposed systems as in the past, parasitic attacks that steal core technologies or sensitive information over an extended period after seizing control of infrastructure are expected to be dominant. As attack methods could expand extensively to include not only the collection of account information but also screen capturing, video recording, and audio recording, organizations must establish an integrated security system capable of responding across all areas of the system.
■ Continued discovery and exploitation of high-impact 'jackpot' vulnerabilities
This year, the 'BYOVD (Bring Your Own Vulnerable Driver)' attack method was discovered, which exploits drivers that have vulnerabilities but can normally access key system privileges. Next year as well, attackers are expected to seek out and exploit high-impact jackpot vulnerabilities for attacks, regardless of whether the environment ranges from PCs to mobile, cloud, and OT (Operational Technology).
In particular, attackers can exploit software with discontinued security patch support or unpatched vulnerabilities by discovering them themselves or purchasing them on the dark web to carry out data leaks or ransomware attacks. Therefore, organizational security personnel and members must periodically apply security patches and delete unused programs.
■ Supply Chain Attacks Expand to Mobile Environments
With financial transactions and the use of personal information becoming increasingly active on mobile devices recently, supply chain attacks, which have previously centered on PC software, could expand into the mobile sector next year. Attackers appear likely to attempt infiltration from the early stages of app development by hacking developers or development tools that allow apps to be registered on legitimate app markets, rather than using the existing method of creating and distributing malicious apps (malicious code).
In addition, malicious code injection may be attempted during the distribution or update phases of mobile apps, or certificates from legitimate apps may be stolen and utilized to create and distribute malicious apps. Therefore, mobile service providers must consider security during the development and distribution processes and establish threat detection and response systems for their key assets.
■ Attacks Targeting Individual Virtual Asset Wallets Intensify
With recent hacking attacks on major cryptocurrency exchanges and key blockchain services, an increasing number of users are transferring virtual assets, such as coins and NFTs, to personal wallets. Consequently, attack attempts targeting individual virtual asset wallets are also expected to rise next year.
For example, many users cannot memorize the seed phrases or 12- (or 24-word) mnemonic keys used for account ownership verification and wallet recovery, so they record them in photos, emails, or mobile phone memos. Attackers are expected to expand the distribution of data-stealing malware and phishing websites and apps impersonating well-known cryptocurrency wallets to steal this mnemonic key information and wallet account details. Personal wallet users must store their seed phrases or mnemonic keys in a safe place and use wallets that are secure against the risk of losing their keys. You must also carefully check for any criminal involvement of the wallet you intend to transfer money to.
To prevent such security threats, organizations must establish preventive measures, such as frequent security checks and patching of PCs, operating systems, software, and websites within the organization, utilizing security solutions and services and conducting security training for internal employees, monitoring authentication history for administrator accounts, and introducing Multi-Factor Authentication.
In addition, individuals must adhere to security guidelines, such as refraining from opening attachments or URLs in emails from unknown sources, using official channels for downloading content and software, applying the latest security patches to software, operating systems, and internet browsers, using two-factor authentication in addition to a password when logging in, and maintaining the latest version of antivirus software and enabling real-time monitoring.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














