216.73.216.6

2024 Malicious Infrastructure Insights: Key Trends and Threats

· Published 28/02/2025 18:30 · Modified 05/03/2025 19:07

Export JSON

Essential information

Published
28/02/2025 18:30
Modified
05/03/2025 19:07
Tags
2025-02-28 asyncrat botnets brute ratel c4 cobalt strike command-and-control servers cybercrime dcrat gobrat hook infostealers latrodectus lummac2 malicious infrastructure mobile malware mozi botnet offensive security tools plugx quasarrat remote access trojans solarmarker rat state-sponsored groups traffic distribution systems
Related entities
20 techniques (mitre), 18 malware, 8 others

Description

The report highlights significant trends in for 2024, including the rise of malware-as-a-service , continued dominance of among , and increased use of legitimate services by threat actors. Key findings include 's dominance in , and Quasar RAT remaining top remote access tools, and Android being the primary target for . The US and China were the top malicious hosting locations, while enhanced efficiency. Chinese expanded their use of relay networks, and Russian groups increasingly relied on legitimate services to evade detection. The report suggests defenders should prioritize top malware and infrastructure techniques, enhance network monitoring, and balance blocking high-risk services based on criticality and risk level.

External references