TahawulTech.com
  • TahawulTech.com
  • Country/Region
    • UAE
      • Nokia drives cloud-native, AI-driven, secure networks for hyperconnected world
      • ruya unveils AI-generated brand film: “You’ve Got Better Things to Do” 
      • Dubai gaming expands with 350+ firms and $1Billion economic target under ‘DPG 2033’
      • Belkin unveils new gaming portfolio featuring power-packed charging accessories, gaming essentials
      • RLUSD approved by DFSA as recognised crypto token for use within DIFC
    • Saudi Arabia
      • Nokia drives cloud-native, AI-driven, secure networks for hyperconnected world
      • Belkin unveils new gaming portfolio featuring power-packed charging accessories, gaming essentials
      • Smart security adoption rises in Saudi homes with a digital-first approach
      • Cisco expands partnership with Saudi Arabia 
      • Sophos powers up cybersecurity in the UAE 
    • Oman
      • Microsoft AI Tour showcases groundbreaking AI innovations for Oman
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • KROHNE delivers insights to inspire the next generation of engineers in Oman
      • Oracle supports major project to accelerate Oman digital economy
      • Ooredoo accelerates cybersecurity in Oman with new deal
    • Bahrain
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • BDB launches “tijara” platform for SMEs
      • Bahrain achieves full nationwide 5G coverage
      • Batelco, SonicWall launch integrated security solutions for SMEs in Bahrain
      • Bahrain to offer COVID-19 test results on WhatsApp, Facebook Messenger
    • Kuwait
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Infopercept opens its first Middle East office in Kuwait
      • Microsoft Compliance Manager now available in Kuwait
      • Commercial Bank of Kuwait gets mobile payments moving with Thales Digital Solutions
      • Ooredoo chooses Fortinet to deliver secure SD-WAN managed services in Kuwait
    • Africa
      • Rise of Fearless unites 2,500+ gamers through African heritage, battle royale
      • Rise of Fearless launches $700K investment round to advance Web3 mobile gaming in Africa 
      • e& enterprise and RAIN Technology to revolutionise Operating Room efficiency in hospitals across MEA
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Looking for the best label solutions in South Africa? Go OKI!
    • Middle East
      • Belkin unveils new gaming portfolio featuring power-packed charging accessories, gaming essentials
      • TwitchCon 10th anniversary brings new products and language expansion
      • Dynatrace drives real-time AI governance, data sovereignty in enterprise landscape
      • UAE takes lead in AI-driven digital transformation with Dynatrace’s Observability vision
      • Qi Card powers digital leap beyond borders
    • Global
      • Apple boosts iPhone experience with iOS 26
      • iPadOS 26 introduces powerful features pushing capabilities and versatility
      • macOS Tahoe 26 makes Mac more capable, productive, and intelligent
      • visionOS 26 introduces powerful new spatial experiences for Apple Vision Pro
      • Apple TV brings redesign, enhanced entertainment experience to home
  • Industry
    • Education
      • e& marks milestone in AI Graduate Programme, empowering 284 Emirati tech leaders
      • DHA signs MoU to train leadership in AI
      • Dubai Future Foundation, University of Birmingham Dubai boost AI collaboration  
      • GDRFA – Dubai launches 8th ICEQ International Conference
      • Bybit partners with University of Wollongong in Dubai to host Demo Trading Challenge
    • Energy
      • Amazon enters nuclear energy partnership to power data centres
      • DOE inks agreement with Presight, AIQ for AI solutions and digital transformation 
      • Solis poised to transform Dubai’s skyline and deserts into beacons of sustainability
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Huawei launches ground-breaking solar inverter at World Future Energy Summit
    • Financial services
      • ruya unveils AI-generated brand film: “You’ve Got Better Things to Do” 
      • MENA Fintech Association launches Türkiye Chapter in collaboration with Insha Ventures
      • Hedera Hashgraph delivers scalable, secure, sustainable blockchain solutions for enterprises, governments
      • Blockchain for Good: ADI Foundation powers a trusted, tokenised future
      • “This has been one of our best years yet, even in the face of significant macroeconomic uncertainty.” – Yuanqing Yang, Lenovo CEO
    • Government
      • Malaysia and UAE’s Presight deepen digital ties with groundbreaking AI partnership 
      • GovTech Innovation Forum & Awards looks to a ‘reimagined future’
      • Lebanese Prime Minister tours Museum of the Future during official visit to UAE 
      • MENA Fintech Association launches Türkiye Chapter in collaboration with Insha Ventures
      • Hedera Hashgraph delivers scalable, secure, sustainable blockchain solutions for enterprises, governments
    • Healthcare
      • Aster DM Healthcare recognised for Workplace quality
      • DHA to leverage AI-powered ‘Genesys’ system in contact centre services 
      • AI to lead Dubai’s healthcare transformation, says DHA head
      • BD hosts Healthcare Summit in Riyadh in line with Vision 2030
      • e& enterprise and RAIN Technology to revolutionise Operating Room efficiency in hospitals across MEA
    • Property
      • DLD boosts transparency with AI-enabled real estate advertising governance 
      • MBRHE and Beyond Limits AI MoU to enhance digital transformation
      • Huspy launches GCC’s first AI-powered mortgage chatbot to transform home financing  
      • DLD, VARA collaborate to boost leadership in realty and virtual assets regulation
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
    • Retail
      • Hushday enters UAE market with private luxury sales and steep discounts
      • Jacky’s Business Solutions unveils Agentic AI offering to accelerate GCC’s autonomous business future
      • Skills gap, data hurdles, and ethics key to unlocking AI in GCC retail, says Al-Futtaim
      • ASUS unveils latest ExpertBook P1 models
      • 75% of retailers say AI Agents will be essential to compete
    • Technology
      • Salesforce blocks AI rivals using data from Slack app
      • Threads to test direct messaging feature
      • Mistral launches Europe’s first AI reasoning model
      • Nokia drives cloud-native, AI-driven, secure networks for hyperconnected world
      • ruya unveils AI-generated brand film: “You’ve Got Better Things to Do” 
    • Transport & Logistics
      • RTA launches AI Strategy 2030 featuring 81 projects and initiatives 
      • Emirates Group co-locates to world’s largest solar-powered data centre
      • Uber School launches for students in Dubai in collaboration with RTA
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • HID transforms ticket validation and fare collection for mass transit
    • Travel & Hospitality
      • 8th Int’l Conference on Education Quality kicks off in Dubai; highlights AI innovations
      • Arabian Travel Market to gather global AI experts to explore new frontiers in travel
      • Smartphones, social media drive travel decisions for Indians, says travel report
      • Emirates Group co-locates to world’s largest solar-powered data centre
      • Emirates advances fleet availability with investment in Airbus Skywise S.FP+ and Core X3 digital predictive maintenance solution
  • Company
    • Enterprise
      • Google appoints new Chief AI Architect
      • Oracle anticipates strong demand for its cloud offerings 
      • Nvidia aims to build industrial AI platform in Germany 
      • Apple opens its AI to developers
      • NVIDIA CEO says UK needs more computing power to develop AI 
    • Corporate
      • Qlik expands cloud footprint with new AWS region in Middle East
      • PeopleStrong powers UAE’s talent shift, accelerates ME growth: Mrigank Tripathi
      • Microsoft names Samer Abu-Ltaif president for Europe, ME and Africa
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • YouGotaGift CEO says ‘product-centricity’ the key to their phenomenal success
    • SME
      • AI-powered solutions shape future of SMEs, says Zoftware founder 
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
      • Alaris expands information capture ecosystem for SMEs
    • Startup
      • AI without borders: Startups leading the next global leap 
      • Secure Domains brings cutting-edge DNS protection to MENA region 
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
    • Vendor
      • Amazon enters nuclear energy partnership to power data centres
      • Google appoints new Chief AI Architect
      • Oracle anticipates strong demand for its cloud offerings 
      • Nvidia aims to build industrial AI platform in Germany 
      • Salesforce blocks AI rivals using data from Slack app
    • Channel
      • Redington and Autodesk expand strategic partnership
      • Vertiv confirms strategic alignment with NVIDIA
      • WSO2 acquires Moesif in next step on strategic roadmap
      • Malaysia and UAE’s Presight deepen digital ties with groundbreaking AI partnership 
      • Sariya Information Technology partners with Keystrike to expand cybersecurity solutions
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
      • Amazon enters nuclear energy partnership to power data centres
      • Google appoints new Chief AI Architect
      • Oracle anticipates strong demand for its cloud offerings 
      • Nvidia aims to build industrial AI platform in Germany 
      • Vertiv appoints Mike Giresi as new Global CIO in bid to reinforce their ambitious AI strategy
    • Software
      • NVIDIA celebrates the launch of ‘DOOM: The Dark Ages’ with special launch event
      • Cisco innovates with Agentic AI
      • Fortinet expands FortiAI across its Security Fabric Platform
      • Dynatrace announces early access to its platform innovations
      • Kaspersky Research Sandbox 3.0: more power, less hardware
    • Hardware
      • Netherlands talks with Nvidia and AMB over supply for AI-facility
      • ASUS Evo lineup: Enhancing the online experience
      • ASUS A3402-Next level computing performance
      • The UAE ranks 8th globally for the readiness of markets for electric transportation
      • Hikvision Commercial Display and Malco Technologies host partner event
    • Networking
      • World Backup Day: Toshiba highlights the importance of data resilience
      • Optimizing IT infrastructure: How Perforator can cut costs and boost performance 
      • NO PAY NO PLAY: Chainalysis reports shows ransomware payments down by 35% as victims refuse to cough up
      • Aleph Alpha launch groundbreaking T-Free architecture for next-generation LLMs, collaborates with AMD, Schwarz Digits
      • Samsung Galaxy S25 series debuts with pioneering AI features and exclusive Snapdragon 8 Elite chipset
    • Security
      • Malicious packages are threatening software supply chains
      • Dynatrace drives real-time AI governance, data sovereignty in enterprise landscape
      • UAE takes lead in AI-driven digital transformation with Dynatrace’s Observability vision
      • “Our mission is to develop highly skilled cybersecurity professionals who can protect their nations’ digital sovereignty.” – Yuliya Danchina, Positive Technologies
      • Kaspersky uncovers sophisticated malware targeting online trading platforms
    • Channel
      • Redington and Autodesk expand strategic partnership
      • Vertiv confirms strategic alignment with NVIDIA
      • WSO2 acquires Moesif in next step on strategic roadmap
      • Malaysia and UAE’s Presight deepen digital ties with groundbreaking AI partnership 
      • Sariya Information Technology partners with Keystrike to expand cybersecurity solutions
    • Telecoms
      • Nokia drives cloud-native, AI-driven, secure networks for hyperconnected world
      • e& AGM approves 83 fils dividend per share for FY 2024
      • Mada & SALAM ink pact on Cutting-Edge Messaging Solutions 
      • NO PAY NO PLAY: Chainalysis reports shows ransomware payments down by 35% as victims refuse to cough up
      • Proofpoint named a leader in 2024 Gartner® Magic Quadrant™
    • Video
      • Catch up on the highlights from Bespin Global’s recent roundtable 
      • Relive all the thrills from the GovTech Innovation Forum and Awards 2025
      • Catch up on the highlights from Hitachi Vantara’s recent KSA roundtable
      • Seclore’s Saudi journey powers regional cybersecurity growth
      • Aster Hospital redefines healthcare with blockchain and AI-driven innovation
  • Features
    • Features
      • Strategy One delivers personalized AI experiences in the UAE
      • How AI is Revolutionising Warehousing Intralogistics
      • Catch up on the highlights from Bespin Global’s recent roundtable 
      • Threat Intel must adapt to disruptive adversarial GenAI
      • Relive all the thrills from the GovTech Innovation Forum and Awards 2025
    • CIO Spotlight
      • DMCC
        Rare commodity: DMCC IT director Abdalla Al Ali
      • HSBC MENAT CIO Ghinwa Baradhi
        The bigger picture: HSBC MENAT CIO Ghinwa Baradhi
      • Mubadala Investment Company CIO Mansour Al Ketbi
        Mansour Al Ketbi unites IT teams for $125 billion Mubadala Investment Company
      • Tariq Al Usaimi, head of digital strategy for the Central Bank of Kuwait
        The new breed: National Bank of Kuwait CDO Tariq Al-Usaimi
      • Al Masah Capital CIO Ashith Piriyattiath
        Ashith Piriyattiath’s diverse & transformative GCC career
    • Case Studies
      • Survey reveals misalignment between cybersecurity and business goals in the UAE and KSA
      • 3,200+ fake Meta profiles used in Facebook scam attempt
      • Edenred UAE: Transforming Customer Service Over WhatsApp with Conversations and Answers
      • Customer Story: Nissan Saudi Arabia
      • elseco
        DIFC prioritises digital transformation to enhance connectivity and accessibility with Wi-Fi 6
    • Partner Watch
      • Juniper Networks Expands Partner Ecosystem Leveraging AI-Native Networking Solutions
      • Commvault selects AlJammaz Technologies as key distributor in the Kingdom of Saudi Arabia
      • Kaspersky signs MoU with Zayed University
      • F5 Appoints Al Jammaz as a Value-Added Distribution Partner
      • The time is now for RNS Managed Security Services
    • Vendor focus
      • Dell Technologies To Establish New Merge & Logistics Fulfilment Hub in Riyadh
      • Dell Technologies study reveals innovation leaders better equipped for economic challenges
      • A10 Networks partners on a mission to ‘accelerate’
      • “The world is on the verge of a new intelligent era powered by Industry 5.0” – David Shi, Huawei
      • Huawei signs new partnership in effort to accelerate SMBs digital transformation
    • Analysis
      • Special Feature: Data Security in the Banking and Financial Sectors
      • Safeguarding Healthcare: Protecting Critical Data and Patient Privacy
      • Trend Micro Predictions Report Forecasts Cyber Fightback in 2022
      • Frost & Sullivan Names Tenable a Growth and Innovation Leader in the Global Vulnerability Management Market, 2021
      • Gartner Identifies the Top Trends Impacting Infrastructure and Operations for 2022
    • Video
      • Catch up on the highlights from Bespin Global’s recent roundtable 
      • Relive all the thrills from the GovTech Innovation Forum and Awards 2025
      • Catch up on the highlights from Hitachi Vantara’s recent KSA roundtable
      • Seclore’s Saudi journey powers regional cybersecurity growth
      • Aster Hospital redefines healthcare with blockchain and AI-driven innovation
    • Lifestyle
      • Apple Intelligence adds more powerfu new capabilities across Apple devices
      • Apple boosts iPhone experience with iOS 26
      • iPadOS 26 introduces powerful features pushing capabilities and versatility
      • macOS Tahoe 26 makes Mac more capable, productive, and intelligent
      • watchOS 26 delivers more personalised ways to stay active, healthy, and connected
    • Insight
      • Strategy One delivers personalized AI experiences in the UAE
      • How AI is Revolutionising Warehousing Intralogistics
      • GameStop revenue declines as online gaming rises
      • Skills shortage remains a huge problem as Cisco reveals results of its Cybersecurity Readiness Index 2025
      • Threat Intel must adapt to disruptive adversarial GenAI
    • Opinion
      • How AI is Revolutionising Warehousing Intralogistics
      • Threat Intel must adapt to disruptive adversarial GenAI
      • Kissflow outlines the link between digital transformation and app development
      • How Immersive Environments are Changing Hospitality, Retail, and Public Spaces
      • “Endava plays a critical role in helping organisations realise the full potential of Agentspace.” – Andrew Rossiter, Endava
    • Blogs
      • Why I joined Cloudflare: To build world-class partnerships in EMEA
      • Revolutionising fan engagement in football through data, gamification, and smart stadium experiences
      • How enterprises can raise their cyber security readiness by going through 3 stages of preparation
      • Maestro Blocks: Transferring passion into businesses!
      • Fighting glare: addressing urban light pollution from traffic cameras
  • News
    • Region
      • Amazon enters nuclear energy partnership to power data centres
      • Google appoints new Chief AI Architect
      • Oracle anticipates strong demand for its cloud offerings 
      • Nvidia aims to build industrial AI platform in Germany 
      • Salesforce blocks AI rivals using data from Slack app
  • Magazines
    • CNME
      • May 2025
      • April 2025
      • March 2025
      • February 2025
      • January 2025
    • Reseller ME
      • May 2025
      • April 2025
      • February 2025
      • January 2025
      • October 2024
    • Security Advisor ME
      • May 2025
      • April 2025
      • March 2025
      • February 2025
      • January 2025
    • 60 Minutes
      • 60mins Day 5 – PM (2024)
      • 60mins Day 5 – AM (2024)
      • 60mins Day 4 – PM (2024)
      • 60mins Day 4 – AM (2024)
      • 60mins Day 3 – PM (2024)
    • Supplements
      • GovTech – October 2024
      • GITEX Tech Vision 2024
      • LinkShadow Special Report October 2024
      • GovTech – May 2023
      • Pure Accelerate Riyadh Recap
  • Events
    • Awards
      • GovTech Awards 2025
      • Infosec & Cybersecurity Congress 2025
      • CIO Leadership Awards 2025
      • Reseller Middle East Partner Excellence Awards 2024
      • KSA Executive Summit on AI, Cybersecurity, and Emerging Technologies
    • Customer Events
      • Infosec & Cybersecurity Congress 2025
      • Infosec & Cybersecurity Congress 2024
      • Infosec & Cybersecurity Congress 2023
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
      • Expectations vs Investment
    • Forums
      • Women in Tech (Pride of Tech) Forum and Awards 2025
      • Infosec & Cybersecurity Congress 2025
      • Women in Tech (Pride of Tech) Forum and Awards 2024
      • Tahawultech Conference 2025
      • CISO 50 & Future Security Awards 2024
    • Your Voice
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
      • Expectations vs Investment
      • Rise of e-commerce
      • Combating credit crunch
    • Webinars
      • Freshworks virtual webinar highlights increasing role of IT industry in accelerating digital transformation
      • Mimecast virtual webinar highlights importance of brand protection
      • Huawei and IDC collaborate on Autonomous Network white paper
      • WEBINAR: Experience the Intelligent HPE Hyperconverged and Composable Infrastructure
      • WEBINAR: How Alpha Data and Veritas Enable Enterprises to Win the War Against Ransomware
  • GISEC 2025
  • LEAP 2025
Don’t show this ad again.
D-Link
Bahwan CyberTek
Fortinet
Enterprise, Features, News

Mandiant’s M-Trends 2023 report reveals frontline threat intelligence

by Veronica Martin
May 2, 2023, 9:15 amMay 2, 2023

The results of the M-Trends 2023 report by Mandiant Inc., now a part of Google Cloud, have been announced and offer up-to-date information and knowledgeable analysis on the constantly changing threat landscape based on frontline Mandiant investigations and remediations of high-impact cyber attacks globally.

The new report reveals the progress organizations globally have made in strengthening defenses against increasingly sophisticated adversaries.

“M-Trends 2023 makes it clear that, while our industry is getting better at cyber security, we are combating ever evolving and increasingly sophisticated adversaries. Several trends we saw in 2021 continued in 2022, such as an increasing number of new malware families as well as rising cyber espionage from nation-state-backed actors. As a result, organizations must remain diligent and continue to enhance their cyber security posture with modern cyber defense capabilities. Ongoing validation of cyber resilience against these latest threats and testing of overall response capabilities are equally critical.” – Jurgen Kutscher, VP, Mandiant Consulting at Google Cloud

Global Median Dwell Time Declines to Just Over Two Weeks

According to the M-Trends 2023 report, the global median dwell time – which is calculated as the median number of days an attacker is present in a target’s environment before being detected – continues to drop year-over-year down to 16 days in 2022. This is the shortest median global dwell time from all M-Trends reporting periods, with a median dwell time of 21 days in 2021.

When comparing how threats were detected, Mandiant observed a general increase in the number of organizations that were alerted by an external entity of historic or ongoing compromise. Organizations headquartered in the Americas were notified by an external entity in 55% of incidents, compared to 40% of incidents last year. This is the highest percentage of external notifications the Americas has seen over the past six years. Similarly, organizations in Europe, the Middle East and Africa (EMEA) were alerted of an intrusion by an external entity in 74% of investigations in 2022 compared to 62% in 2021.

Mandiant experts noted a decrease in the percentage of their global investigations involving ransomware between 2021 and 2022. In 2022, 18% of investigations involved ransomware compared to 23% in 2021. This represents the smallest percentage of Mandiant investigations related to ransomware since prior to 2020.

“While we don’t have data that suggests there is a single cause for the slight drop in ransomware-related attacks that we observed, there have been multiple shifts in the operating environment that have likely contributed to these lower figures. These factors include, but are not limited to: ongoing government and law enforcement disruption efforts targeting ransomware services and individuals, which at minimum require actors to retool or develop new partnerships; the conflict in Ukraine; actors needing to adjust their initial access operations to a world where macros may often be disabled by default, as well as organizations potentially getting better at detecting and preventing or recovering from ransomware events at faster rates.” – Sandra Joyce, VP, Mandiant Intelligence at Google Cloud.

Stuart McKenzie, Head of Mandiant Consulting EMEA at Google Cloud, said: “Our latest M-Trends report shows dwell time has decreased for another consecutive year. We look at the median number of days an attacker sits in a target’s environment before being detected – in EMEA this is now less than three weeks, compared to 48 days in the previous year, so an improvement of 58% year-on-year.”

“While this shows clear progress in cyber security capabilities on the part of defenders, we’re also seeing threat actors being increasingly brazen. It’s important that defences aren’t static and organisations are running continuous testing programmes to maintain a strong security posture. As ever, practice makes perfect – one of the best ways to stay prepared is to keep defending against cyber-attacks simulated by a red team. By continuously testing defences against likely, real-world scenarios, an organisation can quickly uncover vulnerabilities and focus on the right things to work on,” concluded Stuart.

Cyber Espionage, Malware Families Increase Globally 

Mandiant identified extensive cyber espionage and information operations leading up to and since Russia’s invasion of Ukraine on February 24, 2022. Most notably, Mandiant saw activity by UNC2589 and APT28 prior to the invasion of Ukraine, and observed more destructive cyber attacks in Ukraine during the first four months of 2022 than in the previous eight years.

In 2022, Mandiant began tracking 588 new malware families, revealing how adversaries are continuing to expand their toolsets. Of the newly tracked malware families, the top five categories consisted of backdoors (34%), downloaders (14%), droppers (11%), ransomware (7%) and launchers (5%). These categories of malware remain consistent over the years and backdoors continue to represent a little over one third of the newly tracked malware families.

In line with previous years, the most common malware family identified by Mandiant in investigations was BEACON, a multi-function backdoor. In 2022, BEACON was identified in 15% of all intrusions investigated by Mandiant and remains by far the most seen in investigations across regions. It has been used by a wide variety of threat groups tracked by Mandiant including nation state-backed threat groups attributed to China, Russia and Iran, as well as financial threat groups and over 700 UNC groups. This ubiquity is likely due to the common availability of BEACON combined with the malware’s high customizability and ease of use, according to the report.

“Mandiant has investigated several intrusions carried out by newer adversaries that are becoming increasingly savvy and effective. They leverage data from underground cybercrime markets, conduct convincing social engineering schemes over voice calls and text messages, and even attempt to bribe employees to obtain access to networks. These groups pose a significant risk to organizations, even those with robust security programs, as these techniques are challenging to defend against. As organizations continue to build their security teams, infrastructure, and capabilities, protecting against these threat actors should be part of their design goals.” – Charles Carmakal, CTO, Mandiant Consulting at Google Cloud

Actioning Intelligence

The goal of M-Trends is to arm security professionals with insights on the latest attacker activity as seen directly on the frontlines, backed by actionable intelligence to improve organizations’ security postures within an evolving threat landscape. To meet this objective, Mandiant provides insight into some of the most prolific threat actors and their expanding tactics, techniques and procedures.

To further support this objective, Mandiant mapped an additional 150 Mandiant techniques to the updated MITRE ATT&CK® framework, bringing the total to 2,300+ Mandiant techniques and subsequent findings associated with the ATT&CK framework. Organizations should prioritize which security measures to implement based on the likelihood of a specific technique being used during an intrusion.

Additional takeaways from M-Trends 2023 Report include:

  • Infection vector: For the third year in a row, exploits remained the most leveraged initial infection vector used by adversaries at 32%. While this was a decrease from the 37% of intrusions identified in 2021, exploits remained a critical tool for adversaries to use against their targets. Phishing returned as the second most utilized vector, representing 22% of intrusions as compared to 12% in 2021.
  • Target industries impacted: Response efforts for government-related organizations captured 25% of all investigations, compared to 9% in 2021. This primarily reflects Mandiant’s investigative support of cyber threat activity which targeted Ukraine. The next four most targeted industries from 2022 are consistent with what Mandiant experts observed in 2021, with business & professional services, financial, high tech, and healthcare industries being favored by adversaries. These industries remain attractive targets for both financially and espionage motivated actors.
  • Credential theft: Mandiant investigations uncovered an increased prevalence in both the use of widespread information stealer malware and credential purchasing in 2022 when compared to previous years. In many cases, investigations identified that credentials were likely stolen outside of the organization’s environment and then used against the organization, potentially due to reused passwords or use of personal accounts on corporate devices.
  • Data theft: Mandiant experts identified that in 40% of intrusions in 2022, adversaries prioritized data theft. Mandiant defenders have observed threat actors attempting to steal, or successfully completing data theft operations more often in 2022 compared to previous years.
  • North Korea’s Use of Crypto: Alongside traditional intelligence collection missions and disruptive attacks, in 2022, Democratic People’s Republic of Korea operators showed more interest in stealing—and using—cryptocurrency. These operations have been highly lucrative and will likely continue unabated throughout 2023. For more on how North Korean threat actors are using cybercrime as a way to fund their espionage operations, check out Mandiant’s APT43 report.

M-Trends 2023 Methodology:

The metrics reported in M-Trends 2023 are based on Mandiant Consulting Investigations of targeted attack activity between January 1, 2022 and December 31, 2022. The intelligence gleaned has been sanitized to protect the identities of targets and their data.

Resources:

M-Trends 2023 Report: www.mandiant.com/m-trends

Related Articles

  • Aster DM Healthcare launches myAster in Saudi Arabia
  • API supergroup unveils its first CEO and new name
  • Interview: AI-Powered Security
[easy-social-share buttons="facebook,twitter,google,linkedin,stumbleupon,pinterest" counters=0 hide_names="force" fixedwidth="yes" fixedwidth_px="111"]
constantly changing threat landscape Google Cloud high-impact cyber attacks investigations Mandiant's M-Trends 2023 report ransomware

Previous ArticleHuawei announces 2023 Q1 business resultsNext ArticleMindware signs master distribution rights for Genesys in MEA

Related Articles

  • Help AG Unveils Top Digital Threats and Trends in Cybersecurity
  • Google Cloud recognises Oredata as MENAT Region Partner of the Year
  • Google Cloud announce appointment of Ziad Jammal as UAE Country Manager

Most Read in Enterprise

OpenAI’s annualized revenue hits $10 billion

2 days agoJune 11, 2025

Catch up on the highlights from Bespin Global’s recent roundtable 

2 days agoJune 10, 2025

NVIDIA CEO says UK needs more computing power to develop AI 

2 days agoJune 11, 2025

Apple opens its AI to developers

2 days agoJune 11, 2025
tahawultech tahawultech.com @tahawultech ·
22h

"There is a disconnect between the understanding of the threats posed by AI, and what it takes to secure organisations against those threats".
Read the full interview with @Cisco's Fady Younes below.
https://www.tahawultech.com/interviews/cisco-committed-to-addressing-cybersecurity-skills-gap-through-its-networking-academy/
#Cisco #tahawultech

Reply on Twitter 1932784243194872148 Retweet on Twitter 1932784243194872148 Like on Twitter 1932784243194872148 Twitter 1932784243194872148
tahawultech tahawultech.com @tahawultech ·
23h

"We’re committed to delivering AI and data services in a way that’s thoughtful and transparent".
Learn more about @salesforce's recent update below.
https://www.tahawultech.com/industry/technology/salesforce-blocks-ai-rivals-using-data-from-slack-app/
#Salesforce #tahawultech

Reply on Twitter 1932778285148295354 Retweet on Twitter 1932778285148295354 Like on Twitter 1932778285148295354 Twitter 1932778285148295354
tahawultech tahawultech.com @tahawultech ·
11 Jun

"Users in select markets will get a dedicated inbox for direct messages on the app as part of the test".
Learn more about Threads' new feature below.
https://www.tahawultech.com/industry/technology/threads-to-test-direct-messaging-feature/
#ThreadsApp #tahawultech

Reply on Twitter 1932751368600629595 Retweet on Twitter 1932751368600629595 Like on Twitter 1932751368600629595 Twitter 1932751368600629595
Load More

RECOMMENDED FOR YOU

  • Opinion: Role of AI in cybersecurity
  • Mindware partners up to promote regional growth
  • Exclusive Interview: Aloysius Cheang, Chief Security Officer, Huawei Middle East and Central Asia
  • Qualys’ 2023 TruRisk report: more than 2.3 billion vulnerabilities detected worldwide in 2022

GET TAHAWULTECH.COM IN YOUR INBOX

The free newsletter covering the top industry headlines

CPI Media Group
TahawulTech.com is the definitive platform in the Middle East for IT content. Covering stories across enterprise technology, cybersecurity and the region’s IT channel industry, TahawulTech.com brings business leaders and technology decision makers together to share their stories of transformation.

OTHER LINKS

  • Events
  • Media Pack
  • Resource Centre
  • Subscription

 

  • Advertise
  • Contact Us
  • Privacy Policy

Contact Us

Office:
Office 1307, Dubai Studio City
Dubai, United Arab Emirates, PO Box 13700
Tel: +971 4 568 2993
Email: info@tahawultech.com
© 2025 All Rights Reserved. Product of CPI
Menu
  • Country/Region
    • UAE
    • Saudi Arabia
    • Oman
    • Bahrain
    • Kuwait
    • Africa
    • Middle East
    • Global
  • Industry
    • Education
    • Energy
    • Financial services
    • Government
    • Healthcare
    • Property
    • Retail
    • Technology
    • Transport & Logistics
    • Travel & Hospitality
  • Company
    • Enterprise
    • Corporate
    • SME
    • Startup
    • Vendor
    • Channel
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
    • Software
    • Hardware
    • Networking
    • Security
    • Channel
    • Telecoms
    • Video
  • Features
    • Features
    • CIO Spotlight
    • Case Studies
    • Partner Watch
    • Vendor focus
    • Analysis
    • Video
    • Lifestyle
    • Insight
    • Opinion
    • Blogs
  • News
    • Region
  • Magazines
    • CNME
    • Reseller ME
    • Security Advisor ME
    • 60 Minutes
    • Supplements
  • Events
    • Awards
    • Customer Events
    • Forums
    • Your Voice
    • Webinars
  • GISEC 2025
  • LEAP 2025
  • Bitz News
    • Business News
    • Financial News
  • Example Column Title
    • Bitz News Group Websites:
    • Insider Journal
    • Business Day
    • Weekly Selection
    • Tech News
    • Cool Stories
    • Geek Reviews
 

Loading Comments...
 

    tahawultech.com Intro