TahawulTech.com
  • TahawulTech.com
  • Country/Region
    • UAE
      • MBZUAI’s MAILIS, AD Gaming to spotlight AI’s role in future of game development
      • Reimagining distribution: AI drives the dawn of autonomous, intelligent supply chains
      • Redington launches Software Solutions Group to power digital-first future
      • Drone deliveries to see trial use in Abu Dhabi
      • Transforming printing industry: Embracing sustainability for innovation and growth 
    • Saudi Arabia
      • MFTA launches Saudi Chapter, co-chaired by Mona Alsemayen and Sophie Guibaud 
      • Cluster 2 signs agreement to advance smart airport operations in Saudi Arabia
      • Nokia drives cloud-native, AI-driven, secure networks for hyperconnected world
      • Belkin unveils new gaming portfolio featuring power-packed charging accessories, gaming essentials
      • Smart security adoption rises in Saudi homes with a digital-first approach
    • Oman
      • Microsoft AI Tour showcases groundbreaking AI innovations for Oman
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • KROHNE delivers insights to inspire the next generation of engineers in Oman
      • Oracle supports major project to accelerate Oman digital economy
      • Ooredoo accelerates cybersecurity in Oman with new deal
    • Bahrain
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • BDB launches “tijara” platform for SMEs
      • Bahrain achieves full nationwide 5G coverage
      • Batelco, SonicWall launch integrated security solutions for SMEs in Bahrain
      • Bahrain to offer COVID-19 test results on WhatsApp, Facebook Messenger
    • Kuwait
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Infopercept opens its first Middle East office in Kuwait
      • Microsoft Compliance Manager now available in Kuwait
      • Commercial Bank of Kuwait gets mobile payments moving with Thales Digital Solutions
      • Ooredoo chooses Fortinet to deliver secure SD-WAN managed services in Kuwait
    • Africa
      • Dubai’s Omining unveils first African site in Kenya’s Special Economic Zone
      • Rise of Fearless unites 2,500+ gamers through African heritage, battle royale
      • Rise of Fearless launches $700K investment round to advance Web3 mobile gaming in Africa 
      • e& enterprise and RAIN Technology to revolutionise Operating Room efficiency in hospitals across MEA
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
    • Middle East
      • NTT DATA launches AI powered software defined infrastructure services for Cisco
      • Belkin unveils new gaming portfolio featuring power-packed charging accessories, gaming essentials
      • TwitchCon 10th anniversary brings new products and language expansion
      • Dynatrace drives real-time AI governance, data sovereignty in enterprise landscape
      • UAE takes lead in AI-driven digital transformation with Dynatrace’s Observability vision
    • Global
      • EU expresses interest in developing AI gigafactories 
      • UK operators seek to connect rural areas
      • U.S proposes ban on Chinese AI models
      • China responds to Taiwan’s tech blockade
      • U.S. on alert for Iranian cyberattacks
  • Industry
    • Education
      • MBZUAI’s MAILIS, AD Gaming to spotlight AI’s role in future of game development
      • ASUS examines the use of AI in Education at ‘The Tech Social’ Event
      • UAE sets pace in GenAI-powered upskilling and inclusive digital transformation
      • e& marks milestone in AI Graduate Programme, empowering 284 Emirati tech leaders
      • DHA signs MoU to train leadership in AI
    • Energy
      • Amazon enters nuclear energy partnership to power data centres
      • DOE inks agreement with Presight, AIQ for AI solutions and digital transformation 
      • Solis poised to transform Dubai’s skyline and deserts into beacons of sustainability
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Huawei launches ground-breaking solar inverter at World Future Energy Summit
    • Financial services
      • American based insurance giant suffers cyber breach
      • Qi, K2 Integrity join forces to align Iraq’s financial sector with global standards
      • ruya unveils AI-generated brand film: “You’ve Got Better Things to Do” 
      • MENA Fintech Association launches Türkiye Chapter in collaboration with Insha Ventures
      • Hedera Hashgraph delivers scalable, secure, sustainable blockchain solutions for enterprises, governments
    • Government
      • MBZUAI’s MAILIS, AD Gaming to spotlight AI’s role in future of game development
      • China introduces stricter online control with internet ID
      • OpenAI enters into lucrative deal with U.S. government 
      • Trump launches smartphone mobile service
      • Trump-Musk feud leads to reevaluation of SpaceX contracts 
    • Healthcare
      • Genomics company fined over data breach
      • SandboxAQ improves drug discovery with data creation
      • Aster DM Healthcare recognised for Workplace quality
      • DHA to leverage AI-powered ‘Genesys’ system in contact centre services 
      • AI to lead Dubai’s healthcare transformation, says DHA head
    • Property
      • DLD boosts transparency with AI-enabled real estate advertising governance 
      • MBRHE and Beyond Limits AI MoU to enhance digital transformation
      • Huspy launches GCC’s first AI-powered mortgage chatbot to transform home financing  
      • DLD, VARA collaborate to boost leadership in realty and virtual assets regulation
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
    • Retail
      • Global second-hand smartphone market sees annual drop
      • Hushday enters UAE market with private luxury sales and steep discounts
      • Jacky’s Business Solutions unveils Agentic AI offering to accelerate GCC’s autonomous business future
      • Skills gap, data hurdles, and ethics key to unlocking AI in GCC retail, says Al-Futtaim
      • ASUS unveils latest ExpertBook P1 models
    • Technology
      • OpenAI to rent gigawatts of capacity from Oracle
      • Tech companies explore the role of robots in farming
      • Google launches Veo 3 on Gemini in MENA
      • MBZUAI’s MAILIS, AD Gaming to spotlight AI’s role in future of game development
      • Pure Storage delivers performance at any scale with new products
    • Transport & Logistics
      • EV maker Telsa sees collapse in sales
      • Cybercriminals set their sights on U.S. airlines
      • Tesla robotaxis draw concerns from U.S. regulators 
      • Small fleet of Tesla Robotaxi launches in Texas  
      • UK to explore ‘clean’ air travel
    • Travel & Hospitality
      • Cluster 2 signs agreement to advance smart airport operations in Saudi Arabia
      • 8th Int’l Conference on Education Quality kicks off in Dubai; highlights AI innovations
      • Arabian Travel Market to gather global AI experts to explore new frontiers in travel
      • Smartphones, social media drive travel decisions for Indians, says travel report
      • Emirates Group co-locates to world’s largest solar-powered data centre
  • Company
    • Enterprise
      • Apple looks to appease EU over App Store fines
      • AVEVA recognised at annual Data + AI Summit
      • Intel makes new appointments in bid to be more engineering-focused 
      • SandboxAQ improves drug discovery with data creation
      • Amazon’s workforce looks to shrink in the face of AI
    • Corporate
      • Qlik expands cloud footprint with new AWS region in Middle East
      • PeopleStrong powers UAE’s talent shift, accelerates ME growth: Mrigank Tripathi
      • Microsoft names Samer Abu-Ltaif president for Europe, ME and Africa
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • YouGotaGift CEO says ‘product-centricity’ the key to their phenomenal success
    • SME
      • AI-powered solutions shape future of SMEs, says Zoftware founder 
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
      • Alaris expands information capture ecosystem for SMEs
    • Startup
      • AI without borders: Startups leading the next global leap 
      • Secure Domains brings cutting-edge DNS protection to MENA region 
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
    • Vendor
      • HPE buys Juniper Networks for $14 billion
      • Pure Storage delivers performance at any scale with new products
      • Bybit helped contain crypto crisis after a hefty hack
      • Zscaler invests in data centers for the KSA
      • Salesforce introduces Agentforce for Net Zero Cloud to assist sustainability teams 
    • Channel
      • OpenAI to rent gigawatts of capacity from Oracle
      • HPE buys Juniper Networks for $14 billion
      • TP-Link MEA powers into 2025 with Wi-Fi 7, AI, and Scalable Security
      • Rakuten Symphony finds the ‘IDEAL’ value-added distributor for MEA expansion
      • Reimagining distribution: AI drives the dawn of autonomous, intelligent supply chains
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
      • OpenAI to rent gigawatts of capacity from Oracle
      • EV maker Telsa sees collapse in sales
      • HPE buys Juniper Networks for $14 billion
      • Tech companies explore the role of robots in farming
      • MBZUAI’s MAILIS, AD Gaming to spotlight AI’s role in future of game development
    • Software
      • U.S. Senate votes on state-level AI regulation 
      • Redington launches Software Solutions Group to power digital-first future
      • Fortinet upgrades CNAPP, expands solution availability via AWS Marketplace
      • NVIDIA celebrates the launch of ‘DOOM: The Dark Ages’ with special launch event
      • Cisco innovates with Agentic AI
    • Hardware
      • Apple weighs the value of AI-designed hardware
      • Netherlands talks with Nvidia and AMB over supply for AI-facility
      • ASUS Evo lineup: Enhancing the online experience
      • ASUS A3402-Next level computing performance
      • The UAE ranks 8th globally for the readiness of markets for electric transportation
    • Networking
      • Reimagining distribution: AI drives the dawn of autonomous, intelligent supply chains
      • Fortinet upgrades CNAPP, expands solution availability via AWS Marketplace
      • World Backup Day: Toshiba highlights the importance of data resilience
      • Optimizing IT infrastructure: How Perforator can cut costs and boost performance 
      • NO PAY NO PLAY: Chainalysis reports shows ransomware payments down by 35% as victims refuse to cough up
    • Security
      • Orange Business announces new cyberdefense initiative 
      • Cybercriminals set their sights on U.S. airlines
      • U.S. on alert for Iranian cyberattacks
      • Protect your login credentials with these tips from Kaspersky
      • American based insurance giant suffers cyber breach
    • Channel
      • OpenAI to rent gigawatts of capacity from Oracle
      • HPE buys Juniper Networks for $14 billion
      • TP-Link MEA powers into 2025 with Wi-Fi 7, AI, and Scalable Security
      • Rakuten Symphony finds the ‘IDEAL’ value-added distributor for MEA expansion
      • Reimagining distribution: AI drives the dawn of autonomous, intelligent supply chains
    • Telecoms
      • UK operators seek to connect rural areas
      • Nedaa participates in CCW 2025 to boost partnerships in critical communications
      • Nokia drives cloud-native, AI-driven, secure networks for hyperconnected world
      • e& AGM approves 83 fils dividend per share for FY 2024
      • Mada & SALAM ink pact on Cutting-Edge Messaging Solutions 
    • Video
      • Catch up on the highlights from Bespin Global’s recent roundtable 
      • Relive all the thrills from the GovTech Innovation Forum and Awards 2025
      • Catch up on the highlights from Hitachi Vantara’s recent KSA roundtable
      • Seclore’s Saudi journey powers regional cybersecurity growth
      • Aster Hospital redefines healthcare with blockchain and AI-driven innovation
  • Features
    • Features
      • Zebra’s 5G-enabled devices are empowering port operators
      • Lebanon 3.0: From Elon Musk’s call to a National Reboot powered by Code, Collaboration, and Confidence
      • Opinion: Telecom Operators need a talent strategy to develop solution visionaries
      • The home of the future is here… and it knows what you need before you do
      • Sirius is building next-gen ecosystems for future digital nations
    • CIO Spotlight
      • DMCC
        Rare commodity: DMCC IT director Abdalla Al Ali
      • HSBC MENAT CIO Ghinwa Baradhi
        The bigger picture: HSBC MENAT CIO Ghinwa Baradhi
      • Mubadala Investment Company CIO Mansour Al Ketbi
        Mansour Al Ketbi unites IT teams for $125 billion Mubadala Investment Company
      • Tariq Al Usaimi, head of digital strategy for the Central Bank of Kuwait
        The new breed: National Bank of Kuwait CDO Tariq Al-Usaimi
      • Al Masah Capital CIO Ashith Piriyattiath
        Ashith Piriyattiath’s diverse & transformative GCC career
    • Case Studies
      • Survey reveals misalignment between cybersecurity and business goals in the UAE and KSA
      • 3,200+ fake Meta profiles used in Facebook scam attempt
      • Edenred UAE: Transforming Customer Service Over WhatsApp with Conversations and Answers
      • Customer Story: Nissan Saudi Arabia
      • elseco
        DIFC prioritises digital transformation to enhance connectivity and accessibility with Wi-Fi 6
    • Partner Watch
      • Juniper Networks Expands Partner Ecosystem Leveraging AI-Native Networking Solutions
      • Commvault selects AlJammaz Technologies as key distributor in the Kingdom of Saudi Arabia
      • Kaspersky signs MoU with Zayed University
      • F5 Appoints Al Jammaz as a Value-Added Distribution Partner
      • The time is now for RNS Managed Security Services
    • Vendor focus
      • Dell Technologies To Establish New Merge & Logistics Fulfilment Hub in Riyadh
      • Dell Technologies study reveals innovation leaders better equipped for economic challenges
      • A10 Networks partners on a mission to ‘accelerate’
      • “The world is on the verge of a new intelligent era powered by Industry 5.0” – David Shi, Huawei
      • Huawei signs new partnership in effort to accelerate SMBs digital transformation
    • Analysis
      • Special Feature: Data Security in the Banking and Financial Sectors
      • Safeguarding Healthcare: Protecting Critical Data and Patient Privacy
      • Trend Micro Predictions Report Forecasts Cyber Fightback in 2022
      • Frost & Sullivan Names Tenable a Growth and Innovation Leader in the Global Vulnerability Management Market, 2021
      • Gartner Identifies the Top Trends Impacting Infrastructure and Operations for 2022
    • Video
      • Catch up on the highlights from Bespin Global’s recent roundtable 
      • Relive all the thrills from the GovTech Innovation Forum and Awards 2025
      • Catch up on the highlights from Hitachi Vantara’s recent KSA roundtable
      • Seclore’s Saudi journey powers regional cybersecurity growth
      • Aster Hospital redefines healthcare with blockchain and AI-driven innovation
    • Lifestyle
      • MBZUAI’s MAILIS, AD Gaming to spotlight AI’s role in future of game development
      • e& puts online safety first with new parental control service for families
      • The home of the future is here… and it knows what you need before you do
      • Apple Intelligence adds more powerfu new capabilities across Apple devices
      • Apple boosts iPhone experience with iOS 26
    • Insight
      • Bybit helped contain crypto crisis after a hefty hack
      • Zebra’s 5G-enabled devices are empowering port operators
      • Lebanon 3.0: From Elon Musk’s call to a National Reboot powered by Code, Collaboration, and Confidence
      • Opinion: Telecom Operators need a talent strategy to develop solution visionaries
      • Transforming printing industry: Embracing sustainability for innovation and growth 
    • Opinion
      • Lebanon 3.0: From Elon Musk’s call to a National Reboot powered by Code, Collaboration, and Confidence
      • Opinion: Telecom Operators need a talent strategy to develop solution visionaries
      • Transforming printing industry: Embracing sustainability for innovation and growth 
      • “We believe that technology should not only drive performance but also empower people.” – Peter Oganesean, HP
      • The home of the future is here… and it knows what you need before you do
    • Blogs
      • Opinion: TeKnowledge CTO on the Enterprise AI Execution Gap
      • Why I joined Cloudflare: To build world-class partnerships in EMEA
      • Revolutionising fan engagement in football through data, gamification, and smart stadium experiences
      • How enterprises can raise their cyber security readiness by going through 3 stages of preparation
      • Maestro Blocks: Transferring passion into businesses!
  • News
    • Region
      • OpenAI to rent gigawatts of capacity from Oracle
      • EV maker Telsa sees collapse in sales
      • HPE buys Juniper Networks for $14 billion
      • Tech companies explore the role of robots in farming
      • Google launches Veo 3 on Gemini in MENA
  • Magazines
    • CNME
      • May 2025
      • April 2025
      • March 2025
      • February 2025
      • January 2025
    • Reseller ME
      • May 2025
      • April 2025
      • February 2025
      • January 2025
      • October 2024
    • Security Advisor ME
      • June 2025
      • May 2025
      • April 2025
      • March 2025
      • February 2025
    • 60 Minutes
      • 60mins Day 5 – PM (2024)
      • 60mins Day 5 – AM (2024)
      • 60mins Day 4 – PM (2024)
      • 60mins Day 4 – AM (2024)
      • 60mins Day 3 – PM (2024)
    • Supplements
      • GISEC 2025 – Special Report
      • GovTech – October 2024
      • GITEX Tech Vision 2024
      • LinkShadow Special Report October 2024
      • GovTech – May 2023
  • Events
    • Awards
      • Infosec & Cybersecurity Congress 2025
      • The Channel Leaders Forum & Awards 2025
      • The Future of Finance Conference
      • The Future Enterprise Awards
      • CISO 50 & Future Security Awards 2025
    • Customer Events
      • Infosec & Cybersecurity Congress 2025
      • Infosec & Cybersecurity Congress 2024
      • Infosec & Cybersecurity Congress 2023
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
      • Combating credit crunch
    • Forums
      • Infosec & Cybersecurity Congress 2025
      • The Channel Leaders Forum & Awards 2025
      • The Future of Finance Conference
      • Women in Tech (Pride of Tech) Forum and Awards 2025
      • Tahawultech Conference 2025
    • Your Voice
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
      • Combating credit crunch
      • Rise of e-commerce
      • Expectations vs Investment
    • Webinars
      • Freshworks virtual webinar highlights increasing role of IT industry in accelerating digital transformation
      • Mimecast virtual webinar highlights importance of brand protection
      • Huawei and IDC collaborate on Autonomous Network white paper
      • WEBINAR: Experience the Intelligent HPE Hyperconverged and Composable Infrastructure
      • WEBINAR: How Alpha Data and Veritas Enable Enterprises to Win the War Against Ransomware
  • GISEC 2025
  • LEAP 2025
Don’t show this ad again.
D-Link
Bahwan CyberTek
Fortinet
Enterprise, Features, News

Mandiant’s M-Trends 2023 report reveals frontline threat intelligence

by Veronica Martin
May 2, 2023, 9:15 amMay 2, 2023

The results of the M-Trends 2023 report by Mandiant Inc., now a part of Google Cloud, have been announced and offer up-to-date information and knowledgeable analysis on the constantly changing threat landscape based on frontline Mandiant investigations and remediations of high-impact cyber attacks globally.

The new report reveals the progress organizations globally have made in strengthening defenses against increasingly sophisticated adversaries.

“M-Trends 2023 makes it clear that, while our industry is getting better at cyber security, we are combating ever evolving and increasingly sophisticated adversaries. Several trends we saw in 2021 continued in 2022, such as an increasing number of new malware families as well as rising cyber espionage from nation-state-backed actors. As a result, organizations must remain diligent and continue to enhance their cyber security posture with modern cyber defense capabilities. Ongoing validation of cyber resilience against these latest threats and testing of overall response capabilities are equally critical.” – Jurgen Kutscher, VP, Mandiant Consulting at Google Cloud

Global Median Dwell Time Declines to Just Over Two Weeks

According to the M-Trends 2023 report, the global median dwell time – which is calculated as the median number of days an attacker is present in a target’s environment before being detected – continues to drop year-over-year down to 16 days in 2022. This is the shortest median global dwell time from all M-Trends reporting periods, with a median dwell time of 21 days in 2021.

When comparing how threats were detected, Mandiant observed a general increase in the number of organizations that were alerted by an external entity of historic or ongoing compromise. Organizations headquartered in the Americas were notified by an external entity in 55% of incidents, compared to 40% of incidents last year. This is the highest percentage of external notifications the Americas has seen over the past six years. Similarly, organizations in Europe, the Middle East and Africa (EMEA) were alerted of an intrusion by an external entity in 74% of investigations in 2022 compared to 62% in 2021.

Mandiant experts noted a decrease in the percentage of their global investigations involving ransomware between 2021 and 2022. In 2022, 18% of investigations involved ransomware compared to 23% in 2021. This represents the smallest percentage of Mandiant investigations related to ransomware since prior to 2020.

“While we don’t have data that suggests there is a single cause for the slight drop in ransomware-related attacks that we observed, there have been multiple shifts in the operating environment that have likely contributed to these lower figures. These factors include, but are not limited to: ongoing government and law enforcement disruption efforts targeting ransomware services and individuals, which at minimum require actors to retool or develop new partnerships; the conflict in Ukraine; actors needing to adjust their initial access operations to a world where macros may often be disabled by default, as well as organizations potentially getting better at detecting and preventing or recovering from ransomware events at faster rates.” – Sandra Joyce, VP, Mandiant Intelligence at Google Cloud.

Stuart McKenzie, Head of Mandiant Consulting EMEA at Google Cloud, said: “Our latest M-Trends report shows dwell time has decreased for another consecutive year. We look at the median number of days an attacker sits in a target’s environment before being detected – in EMEA this is now less than three weeks, compared to 48 days in the previous year, so an improvement of 58% year-on-year.”

“While this shows clear progress in cyber security capabilities on the part of defenders, we’re also seeing threat actors being increasingly brazen. It’s important that defences aren’t static and organisations are running continuous testing programmes to maintain a strong security posture. As ever, practice makes perfect – one of the best ways to stay prepared is to keep defending against cyber-attacks simulated by a red team. By continuously testing defences against likely, real-world scenarios, an organisation can quickly uncover vulnerabilities and focus on the right things to work on,” concluded Stuart.

Cyber Espionage, Malware Families Increase Globally 

Mandiant identified extensive cyber espionage and information operations leading up to and since Russia’s invasion of Ukraine on February 24, 2022. Most notably, Mandiant saw activity by UNC2589 and APT28 prior to the invasion of Ukraine, and observed more destructive cyber attacks in Ukraine during the first four months of 2022 than in the previous eight years.

In 2022, Mandiant began tracking 588 new malware families, revealing how adversaries are continuing to expand their toolsets. Of the newly tracked malware families, the top five categories consisted of backdoors (34%), downloaders (14%), droppers (11%), ransomware (7%) and launchers (5%). These categories of malware remain consistent over the years and backdoors continue to represent a little over one third of the newly tracked malware families.

In line with previous years, the most common malware family identified by Mandiant in investigations was BEACON, a multi-function backdoor. In 2022, BEACON was identified in 15% of all intrusions investigated by Mandiant and remains by far the most seen in investigations across regions. It has been used by a wide variety of threat groups tracked by Mandiant including nation state-backed threat groups attributed to China, Russia and Iran, as well as financial threat groups and over 700 UNC groups. This ubiquity is likely due to the common availability of BEACON combined with the malware’s high customizability and ease of use, according to the report.

“Mandiant has investigated several intrusions carried out by newer adversaries that are becoming increasingly savvy and effective. They leverage data from underground cybercrime markets, conduct convincing social engineering schemes over voice calls and text messages, and even attempt to bribe employees to obtain access to networks. These groups pose a significant risk to organizations, even those with robust security programs, as these techniques are challenging to defend against. As organizations continue to build their security teams, infrastructure, and capabilities, protecting against these threat actors should be part of their design goals.” – Charles Carmakal, CTO, Mandiant Consulting at Google Cloud

Actioning Intelligence

The goal of M-Trends is to arm security professionals with insights on the latest attacker activity as seen directly on the frontlines, backed by actionable intelligence to improve organizations’ security postures within an evolving threat landscape. To meet this objective, Mandiant provides insight into some of the most prolific threat actors and their expanding tactics, techniques and procedures.

To further support this objective, Mandiant mapped an additional 150 Mandiant techniques to the updated MITRE ATT&CK® framework, bringing the total to 2,300+ Mandiant techniques and subsequent findings associated with the ATT&CK framework. Organizations should prioritize which security measures to implement based on the likelihood of a specific technique being used during an intrusion.

Additional takeaways from M-Trends 2023 Report include:

  • Infection vector: For the third year in a row, exploits remained the most leveraged initial infection vector used by adversaries at 32%. While this was a decrease from the 37% of intrusions identified in 2021, exploits remained a critical tool for adversaries to use against their targets. Phishing returned as the second most utilized vector, representing 22% of intrusions as compared to 12% in 2021.
  • Target industries impacted: Response efforts for government-related organizations captured 25% of all investigations, compared to 9% in 2021. This primarily reflects Mandiant’s investigative support of cyber threat activity which targeted Ukraine. The next four most targeted industries from 2022 are consistent with what Mandiant experts observed in 2021, with business & professional services, financial, high tech, and healthcare industries being favored by adversaries. These industries remain attractive targets for both financially and espionage motivated actors.
  • Credential theft: Mandiant investigations uncovered an increased prevalence in both the use of widespread information stealer malware and credential purchasing in 2022 when compared to previous years. In many cases, investigations identified that credentials were likely stolen outside of the organization’s environment and then used against the organization, potentially due to reused passwords or use of personal accounts on corporate devices.
  • Data theft: Mandiant experts identified that in 40% of intrusions in 2022, adversaries prioritized data theft. Mandiant defenders have observed threat actors attempting to steal, or successfully completing data theft operations more often in 2022 compared to previous years.
  • North Korea’s Use of Crypto: Alongside traditional intelligence collection missions and disruptive attacks, in 2022, Democratic People’s Republic of Korea operators showed more interest in stealing—and using—cryptocurrency. These operations have been highly lucrative and will likely continue unabated throughout 2023. For more on how North Korean threat actors are using cybercrime as a way to fund their espionage operations, check out Mandiant’s APT43 report.

M-Trends 2023 Methodology:

The metrics reported in M-Trends 2023 are based on Mandiant Consulting Investigations of targeted attack activity between January 1, 2022 and December 31, 2022. The intelligence gleaned has been sanitized to protect the identities of targets and their data.

Resources:

M-Trends 2023 Report: www.mandiant.com/m-trends

Related Articles

  • Aster DM Healthcare launches myAster in Saudi Arabia
  • API supergroup unveils its first CEO and new name
  • Interview: AI-Powered Security
[easy-social-share buttons="facebook,twitter,google,linkedin,stumbleupon,pinterest" counters=0 hide_names="force" fixedwidth="yes" fixedwidth_px="111"]
constantly changing threat landscape Google Cloud high-impact cyber attacks investigations Mandiant's M-Trends 2023 report ransomware

Previous ArticleHuawei announces 2023 Q1 business resultsNext ArticleMindware signs master distribution rights for Genesys in MEA

Related Articles

  • Help AG Unveils Top Digital Threats and Trends in Cybersecurity
  • Google Cloud recognises Oredata as MENAT Region Partner of the Year
  • Google Cloud announce appointment of Ziad Jammal as UAE Country Manager
tahawultech tahawultech.com @tahawultech ·
16h

"@Oracle will build multiple data centres across the US with its partners to meet the additional demand from @OpenAI".
Learn more about this investment below.
https://www.tahawultech.com/channel/openai-to-rent-gigawatts-of-capacity-from-oracle/
#OracleCloud #OpenAI #tahawultech

Reply on Twitter 1941053059339374872 Retweet on Twitter 1941053059339374872 Like on Twitter 1941053059339374872 Twitter 1941053059339374872
tahawultech tahawultech.com @tahawultech ·
18h

"Musk's controversial role in the Trump administration has also been blamed for the plummeting numbers".
Learn more about these developments for @Tesla below.
https://www.tahawultech.com/home-slide/ev-maker-telsa-sees-collapse-in-sales/
#Tesla #tahawultech

Reply on Twitter 1941030099828330502 Retweet on Twitter 1941030099828330502 Like on Twitter 1941030099828330502 Twitter 1941030099828330502
tahawultech tahawultech.com @tahawultech ·
18h

"The @JuniperNetworks team will be integrated inside the @HPE corporate structure”.
Learn more about this recent acquisition below.
https://www.tahawultech.com/channel/hpe-buys-juniper-networks-for-14-billion/
#HPE #JuniperNetworks #tahawultech

Reply on Twitter 1941023645125771392 Retweet on Twitter 1941023645125771392 Like on Twitter 1941023645125771392 Twitter 1941023645125771392
Load More

RECOMMENDED FOR YOU

  • Opinion: Role of AI in cybersecurity
  • Mindware partners up to promote regional growth
  • Exclusive Interview: Aloysius Cheang, Chief Security Officer, Huawei Middle East and Central Asia
  • Qualys’ 2023 TruRisk report: more than 2.3 billion vulnerabilities detected worldwide in 2022

GET TAHAWULTECH.COM IN YOUR INBOX

The free newsletter covering the top industry headlines

CPI Media Group
TahawulTech.com is the definitive platform in the Middle East for IT content. Covering stories across enterprise technology, cybersecurity and the region’s IT channel industry, TahawulTech.com brings business leaders and technology decision makers together to share their stories of transformation.

OTHER LINKS

  • Events
  • Media Pack
  • Resource Centre
  • Subscription

 

  • Advertise
  • Contact Us
  • Privacy Policy

Contact Us

Office:
Office 1307, Dubai Studio City
Dubai, United Arab Emirates, PO Box 13700
Tel: +971 4 568 2993
Email: info@tahawultech.com
© 2025 All Rights Reserved. Product of CPI
Menu
  • Country/Region
    • UAE
    • Saudi Arabia
    • Oman
    • Bahrain
    • Kuwait
    • Africa
    • Middle East
    • Global
  • Industry
    • Education
    • Energy
    • Financial services
    • Government
    • Healthcare
    • Property
    • Retail
    • Technology
    • Transport & Logistics
    • Travel & Hospitality
  • Company
    • Enterprise
    • Corporate
    • SME
    • Startup
    • Vendor
    • Channel
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
    • Software
    • Hardware
    • Networking
    • Security
    • Channel
    • Telecoms
    • Video
  • Features
    • Features
    • CIO Spotlight
    • Case Studies
    • Partner Watch
    • Vendor focus
    • Analysis
    • Video
    • Lifestyle
    • Insight
    • Opinion
    • Blogs
  • News
    • Region
  • Magazines
    • CNME
    • Reseller ME
    • Security Advisor ME
    • 60 Minutes
    • Supplements
  • Events
    • Awards
    • Customer Events
    • Forums
    • Your Voice
    • Webinars
  • GISEC 2025
  • LEAP 2025
  • Bitz News
    • Business News
    • Financial News
  • Example Column Title
    • Bitz News Group Websites:
    • Insider Journal
    • Business Day
    • Weekly Selection
    • Tech News
    • Cool Stories
    • Geek Reviews
 

Loading Comments...
 

    tahawultech.com Intro