TahawulTech.com
  • TahawulTech.com
  • Region
    • UAE
      • ENEC, Presight co-develop ENECIQ platform to boost efficiency and knowledge sharing
      • BMC Helix empowers enterprises in Saudi with Agentic AI at Riyadh Roadshow
      • Empowering Change: Zeina Haggag builds trust, strategy, and inclusion in cybersecurity
      • “AI for All” initiative set to empower UAE with future-ready technology skills
      • Abu Dhabi, global tech leaders partner for major AI training initiative for public sector
    • Saudi Arabia
      • BMC Helix empowers enterprises in Saudi with Agentic AI at Riyadh Roadshow
      • PROVEN consolidates subsidiaries under “PROVEN Solution” brand
      • AI delivers early returns in Saudi Arabia, pushing enterprises to a tipping point
      • UiPath opens Riyadh office to support Vision 2030 via AI, skills development
      • ASUS highlights innovation for Government and Education Sectors at Riyadh Showcase
    • Oman
      • Microsoft AI Tour showcases groundbreaking AI innovations for Oman
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • KROHNE delivers insights to inspire the next generation of engineers in Oman
      • Oracle supports major project to accelerate Oman digital economy
      • Ooredoo accelerates cybersecurity in Oman with new deal
    • Bahrain
      • Bahrain sets global benchmark with GCC’s first stablecoin regulatory framework
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • BDB launches “tijara” platform for SMEs
      • Bahrain achieves full nationwide 5G coverage
      • Batelco, SonicWall launch integrated security solutions for SMEs in Bahrain
    • Kuwait
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Infopercept opens its first Middle East office in Kuwait
      • Microsoft Compliance Manager now available in Kuwait
      • Commercial Bank of Kuwait gets mobile payments moving with Thales Digital Solutions
      • Ooredoo chooses Fortinet to deliver secure SD-WAN managed services in Kuwait
    • Africa
      • ODC Africa and ME partners with Hedera Africa Hackathon to boost Web3 innovation
      • Dubai’s Omining unveils first African site in Kenya’s Special Economic Zone
      • Rise of Fearless unites 2,500+ gamers through African heritage, battle royale
      • Rise of Fearless launches $700K investment round to advance Web3 mobile gaming in Africa 
      • e& enterprise and RAIN Technology to revolutionise Operating Room efficiency in hospitals across MEA
    • Middle East
      • Nokia powers Mideast’s digital backbone with secure, open, and sustainable networks
      • BMC Helix empowers enterprises in Saudi with Agentic AI at Riyadh Roadshow
      • From Idea to App: Emergent’s Agentic AI ushers in post-coding era with innovation
      • Netscout extends visibility into Kubernetes containers with observability innovation
      • From solar parks to green hydrogen: The Middle East’s next big tech leap in offing
    • Global
      • Commvault unveils conversational AI, data rooms to advance cyber resilience in region
      • From data to dignity: SAS calls for human-centred AI shaping cities of tomorrow
      • Netscout extends visibility into Kubernetes containers with observability innovation
      • A potential breakthrough in US-China TikTok discussions
      • Japan records record smartphone growth in Q2 2025
  • Industry
    • Education
      • Bimser launches University Programme to drive innovation in higher education
      • Coursera’s Skills Tracks set new standard for workforce readiness, says top official
      • Kaspersky launches online course for universities to integrate cybersecurity knowledge in curriculums
      • Back-to-school season: The importance of using responsible artificial intelligence
      • UAE schools embrace AI for a knowledge first economy, says ASUS commercial head
    • Energy
      • Google invests in nuclear power for its data centres
      • Can U.S. power grids keep up with the data centre boom? 
      • Tesla applies for UK electricity supply license
      • Google invests heavily in hydroelectric energy
      • Amazon enters nuclear energy partnership to power data centres
    • Financial services
      • Future of Finance 2025 sets stage for transformative dialogue in Dubai
      • Rak Properties enables cryptocurrency payments via partnership with Hubpay
      • Zain powers Iraq’s digital future through customer-driven innovation, inclusion
      • American University of Sharjah, Ghaf Labs partner to boost student industry exposure 
      • American based insurance giant suffers cyber breach
    • Government
      • US soldier plans, executes autonomous Black Hawk Missions using MATRIX Technology at Northern Strike 25-2
      • “AI for All” initiative set to empower UAE with future-ready technology skills
      • Abu Dhabi, global tech leaders partner for major AI training initiative for public sector
      • Abu Dhabi set to unveil world’s first AI public servant at GITEX Global 2025 today
      • Cisco offers configuration options for EU data sovereignty
    • Healthcare
      • myAster app expands reach, impacts over five million lives in three years, says CEO
      • BD drives healthcare innovation at Global Health Saudi 2025
      • Aster DM Healthcare ranked 2nd largest healthcare provider in UAE, 15th in EMEA
      • AI stethoscopes could revolutionise heart health
      • Mecomed unveils digital health whitepaper to boost value-based healthcare in MEA 
    • Property
      • Siemens supplies digital technology for factory-built housing
      • DLD boosts transparency with AI-enabled real estate advertising governance 
      • MBRHE and Beyond Limits AI MoU to enhance digital transformation
      • Huspy launches GCC’s first AI-powered mortgage chatbot to transform home financing  
      • DLD, VARA collaborate to boost leadership in realty and virtual assets regulation
    • Retail
      • The microsecond economy: AI rewrites customer engagement rules in MENA
      • Line Investments, Sheikh Al Nuaimi and Mulk Int’l to deliver Mirkaaz Mall by LuLu
      • Blue Ocean Global shifts to E-Commerce as digital transaction value exceed $60b in UAE
      • Ariston celebrates retail partners at annual retail event
      • myAster expands to Abu Dhabi, RAK, Ajman and Sharjah through 24×7 Express delivery
    • Technology
      • Commvault unveils conversational AI, data rooms to advance cyber resilience in region
      • Nokia powers Mideast’s digital backbone with secure, open, and sustainable networks
      • From data to dignity: SAS calls for human-centred AI shaping cities of tomorrow
      • Informatica announces further details surrounding its new Fall 2025 release
      • ASUS brings “Design You Can Feel” to Dubai Design Week 2025
    • Transport & Logistics
      • US soldier plans, executes autonomous Black Hawk Missions using MATRIX Technology at Northern Strike 25-2
      • UK airport suffers cyber-attack disruption
      • Chinese flying cars crash at air show rehearsal
      • StarLink looking to collaborate with Saudi Arabia’s main airline
      • Tesla found partly liable for fatal 2019 Autopilot crash
    • Travel & Hospitality
      • Sojern and PubMatic join forces to power next-gen travel advertising solutions
      • Cluster 2 signs agreement to advance smart airport operations in Saudi Arabia
      • 8th Int’l Conference on Education Quality kicks off in Dubai; highlights AI innovations
      • Arabian Travel Market to gather global AI experts to explore new frontiers in travel
      • Smartphones, social media drive travel decisions for Indians, says travel report
  • Company
    • Enterprise
      • ASUS brings “Design You Can Feel” to Dubai Design Week 2025
      • NVIDIA CEO outlines future roadmap at recent keynote
      • AVEVA highlights the role of Industrial Intelligence in Net-Zero Energy at ADIPEC 2025
      • BD drives healthcare innovation at Global Health Saudi 2025
      • PROVEN consolidates subsidiaries under “PROVEN Solution” brand
    • Corporate
      • Qlik expands cloud footprint with new AWS region in Middle East
      • PeopleStrong powers UAE’s talent shift, accelerates ME growth: Mrigank Tripathi
      • Microsoft names Samer Abu-Ltaif president for Europe, ME and Africa
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • YouGotaGift CEO says ‘product-centricity’ the key to their phenomenal success
    • SME
      • AI-powered solutions shape future of SMEs, says Zoftware founder 
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
      • Alaris expands information capture ecosystem for SMEs
    • Startup
      • AI without borders: Startups leading the next global leap 
      • Secure Domains brings cutting-edge DNS protection to MENA region 
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
    • Vendor
      • Mastercard and Yandex Qazaqstan join forces to advance digital services in Kazakhstan
      • Informatica announces further details surrounding its new Fall 2025 release
      • Samsung Electronics forecasts a strong 2026
      • Meta Platforms faces hefty tax charge
      • Nvidia invests $1 billion in Nokia with a focus on AI-native infrastructure
    • Channel
      • Mastercard and Yandex Qazaqstan join forces to advance digital services in Kazakhstan
      • Nvidia invests $1 billion in Nokia with a focus on AI-native infrastructure
      • Keystrike and Bulwark Technologies partner to bring advanced cybersecurity to the Middle East
      • Ericsson and Nokia look to the future of 6G deployments
      • VAD Technologies partners with NetApp to accelerate data-driven transformation in the Middle East
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
      • Commvault unveils conversational AI, data rooms to advance cyber resilience in region
      • Kaspersky finds security flaws that put vehicle safety at risk
      • Smart cities must be human cities: Why data needs a heartbeat
      • Mastercard and Yandex Qazaqstan join forces to advance digital services in Kazakhstan
      • ENEC, Presight co-develop ENECIQ platform to boost efficiency and knowledge sharing
    • Software
      • Grok gets agentic coding upgrade
      • Trump Administration threatens a U.S. TikTok ban 
      • X accused of breaching advertising rules 
      • WeTransfer clarifies stance on training AI
      • U.S. Senate votes on state-level AI regulation 
    • Hardware
      • HOT Systems to showcase hardware powered by PNY at GITEX 2025
      • Apple weighs the value of AI-designed hardware
      • Netherlands talks with Nvidia and AMB over supply for AI-facility
      • ASUS Evo lineup: Enhancing the online experience
      • ASUS A3402-Next level computing performance
    • Networking
      • Who is in the running for the US TikTok takeover?
      • TikTok employees concerned about app’s mental health impact
      • T-Mobile’s U.S satellite service makes a nationwide debut
      • Nokia lowers 2025 profit outlook
      • X accused of breaching advertising rules 
    • Security
      • Commvault unveils conversational AI, data rooms to advance cyber resilience in region
      • Kaspersky finds security flaws that put vehicle safety at risk
      • Kaspersky spots new HackingTeam spyware in the wild after years of silence
      • Kaspersky: new Demon Slayer movie ignites scam campaigns worldwide
      • Netscout extends visibility into Kubernetes containers with observability innovation
    • Channel
      • Mastercard and Yandex Qazaqstan join forces to advance digital services in Kazakhstan
      • Nvidia invests $1 billion in Nokia with a focus on AI-native infrastructure
      • Keystrike and Bulwark Technologies partner to bring advanced cybersecurity to the Middle East
      • Ericsson and Nokia look to the future of 6G deployments
      • VAD Technologies partners with NetApp to accelerate data-driven transformation in the Middle East
    • Telecoms
      • Japan records record smartphone growth in Q2 2025
      • AST SpaceMobile outlines 2026 satellite deployment plans 
      • EE introduces new child-safe smartphone plan
      • e&’s Monitoring-as-a-Service offers UAE businesses real-time infrastructure visibility
      • SK Telecom sees massive customer drop after data breach 
    • Video
      • ASUS is on a mission to help transform the education sector in Middle East 
      • Resecurity empowers the UAE’s cyber resilience with AI-driven intelligence
      • Genesys unveils Arabic AI Studio and governance-driven CX innovation at GITEX 2025
      • Pure Storage and VAD Technologies spotlight enterprise data cloud to power AI innovation
      • SearchInform DLP system offers comprehensive protection through real-time monitoring
  • Features
    • Features
      • Driving change, seen and unseen: LLMs in the Middle East’s cybersecurity arena
      • The power of superintelligence in healthcare
      • How secure, modern networks can make AI work for you
      • Mitigating the risks of using open source in KasperskyOS
      • From solar parks to green hydrogen: The Middle East’s next big tech leap in offing
    • CIO Spotlight
      • DMCC
        Rare commodity: DMCC IT director Abdalla Al Ali
      • HSBC MENAT CIO Ghinwa Baradhi
        The bigger picture: HSBC MENAT CIO Ghinwa Baradhi
      • Mubadala Investment Company CIO Mansour Al Ketbi
        Mansour Al Ketbi unites IT teams for $125 billion Mubadala Investment Company
      • Tariq Al Usaimi, head of digital strategy for the Central Bank of Kuwait
        The new breed: National Bank of Kuwait CDO Tariq Al-Usaimi
      • Al Masah Capital CIO Ashith Piriyattiath
        Ashith Piriyattiath’s diverse & transformative GCC career
    • Case Studies
      • Survey reveals misalignment between cybersecurity and business goals in the UAE and KSA
      • 3,200+ fake Meta profiles used in Facebook scam attempt
      • Edenred UAE: Transforming Customer Service Over WhatsApp with Conversations and Answers
      • Customer Story: Nissan Saudi Arabia
      • elseco
        DIFC prioritises digital transformation to enhance connectivity and accessibility with Wi-Fi 6
    • Partner Watch
      • Juniper Networks Expands Partner Ecosystem Leveraging AI-Native Networking Solutions
      • Commvault selects AlJammaz Technologies as key distributor in the Kingdom of Saudi Arabia
      • Kaspersky signs MoU with Zayed University
      • F5 Appoints Al Jammaz as a Value-Added Distribution Partner
      • The time is now for RNS Managed Security Services
    • Vendor focus
      • Dell Technologies To Establish New Merge & Logistics Fulfilment Hub in Riyadh
      • Dell Technologies study reveals innovation leaders better equipped for economic challenges
      • A10 Networks partners on a mission to ‘accelerate’
      • “The world is on the verge of a new intelligent era powered by Industry 5.0” – David Shi, Huawei
      • Huawei signs new partnership in effort to accelerate SMBs digital transformation
    • Analysis
      • Gartner 2026 technology trends include AI supercomputing, preemptive cybersecurity
      • Emirati entrepreneurs learn, sell, and grow in a digital world, says new GoDaddy data 
      • Special Feature: Data Security in the Banking and Financial Sectors
      • Safeguarding Healthcare: Protecting Critical Data and Patient Privacy
      • Trend Micro Predictions Report Forecasts Cyber Fightback in 2022
    • Video
      • ASUS is on a mission to help transform the education sector in Middle East 
      • Resecurity empowers the UAE’s cyber resilience with AI-driven intelligence
      • Genesys unveils Arabic AI Studio and governance-driven CX innovation at GITEX 2025
      • Pure Storage and VAD Technologies spotlight enterprise data cloud to power AI innovation
      • SearchInform DLP system offers comprehensive protection through real-time monitoring
    • Lifestyle
      • ChatGPT aims to better investigate signs of mental health emergencies in users
      • German audio specialist Neumann expands KH monitor line with advanced subwoofers
      • Predator Helios Neo 16S AI showcases cutting-edge portable gaming power
      • Mecomed unveils digital health whitepaper to boost value-based healthcare in MEA 
      • myAster expands to Abu Dhabi, RAK, Ajman and Sharjah through 24×7 Express delivery
    • Insight
      • Kaspersky finds security flaws that put vehicle safety at risk
      • Driving change, seen and unseen: LLMs in the Middle East’s cybersecurity arena
      • Smart cities must be human cities: Why data needs a heartbeat
      • From data to dignity: SAS calls for human-centred AI shaping cities of tomorrow
      • The power of superintelligence in healthcare
    • Opinion
      • Driving change, seen and unseen: LLMs in the Middle East’s cybersecurity arena
      • From data to dignity: SAS calls for human-centred AI shaping cities of tomorrow
      • The power of superintelligence in healthcare
      • How secure, modern networks can make AI work for you
      • UAE businesses must up defences against AI-driven misinformation and disinformation
    • Blogs
      • Opinion: TeKnowledge CTO on the Enterprise AI Execution Gap
      • Why I joined Cloudflare: To build world-class partnerships in EMEA
      • Revolutionising fan engagement in football through data, gamification, and smart stadium experiences
      • How enterprises can raise their cyber security readiness by going through 3 stages of preparation
      • Maestro Blocks: Transferring passion into businesses!
  • News
    • Region
      • Commvault unveils conversational AI, data rooms to advance cyber resilience in region
      • Nokia powers Mideast’s digital backbone with secure, open, and sustainable networks
      • Smart cities must be human cities: Why data needs a heartbeat
      • Mastercard and Yandex Qazaqstan join forces to advance digital services in Kazakhstan
      • From data to dignity: SAS calls for human-centred AI shaping cities of tomorrow
  • Magazines
    • CNME
      • October 2025 – Citrix
      • October 2025 – Core42
      • September 2025
      • July 2025
      • May 2025
    • Reseller ME
      • October 2025
      • September 2025
      • August 2025
      • July 2025
      • May 2025
    • Security Advisor ME
      • October 2025
      • September 2025
      • August 2025
      • June 2025
      • May 2025
    • GITEX 60 Minutes
      • 60mins Day 5 – PM (2025)
      • 60mins Day 5 – AM (2025)
      • 60mins Day 4 – PM (2025)
      • 60mins Day 4 – AM (2025)
      • 60mins Day 3 – PM (2025)
    • LEAP 60 Minutes
    • Supplements
      • GITEX Tech Vision 2025
      • GISEC 2025 – Special Report
      • GovTech – October 2024
      • GITEX Tech Vision 2024
      • LinkShadow Special Report October 2024
  • Events & Conferences
    • Awards
      • KSA Future Enterprise Awards 2025
      • AI Conference & Awards 2025
      • Reseller Middle East Partner Excellence Awards 2025
      • CIO Leadership Awards 2026
      • CISO 50 & Future Security Awards 2025
    • Customer Events
      • Planview Middle East Launch
      • Infosec & Cybersecurity Congress 2025 – Abu Dhabi
      • Infosec & Cybersecurity Congress 2024
      • Infosec & Cybersecurity Congress 2023
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
    • Forums
      • AI Conference & Awards 2025
      • Planview Middle East Launch
      • The Channel Leaders Forum & Awards 2025
      • Infosec & Cybersecurity Congress 2025 – Abu Dhabi
      • The Future of Finance Conference
    • Your Voice
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
      • Combating credit crunch
      • Rise of e-commerce
      • Expectations vs Investment
    • Webinars
      • Freshworks virtual webinar highlights increasing role of IT industry in accelerating digital transformation
      • Mimecast virtual webinar highlights importance of brand protection
      • Huawei and IDC collaborate on Autonomous Network white paper
      • WEBINAR: Experience the Intelligent HPE Hyperconverged and Composable Infrastructure
      • WEBINAR: How Alpha Data and Veritas Enable Enterprises to Win the War Against Ransomware
  • GITEX 2025
  • Black Hat
Don’t show this ad again.
D-Link
Bespin Global
Fortinet
Enterprise, Features, News

Mandiant’s M-Trends 2023 report reveals frontline threat intelligence

by Veronica Martin
May 2, 2023, 9:15 amMay 2, 2023

The results of the M-Trends 2023 report by Mandiant Inc., now a part of Google Cloud, have been announced and offer up-to-date information and knowledgeable analysis on the constantly changing threat landscape based on frontline Mandiant investigations and remediations of high-impact cyber attacks globally.

The new report reveals the progress organizations globally have made in strengthening defenses against increasingly sophisticated adversaries.

“M-Trends 2023 makes it clear that, while our industry is getting better at cyber security, we are combating ever evolving and increasingly sophisticated adversaries. Several trends we saw in 2021 continued in 2022, such as an increasing number of new malware families as well as rising cyber espionage from nation-state-backed actors. As a result, organizations must remain diligent and continue to enhance their cyber security posture with modern cyber defense capabilities. Ongoing validation of cyber resilience against these latest threats and testing of overall response capabilities are equally critical.” – Jurgen Kutscher, VP, Mandiant Consulting at Google Cloud

Global Median Dwell Time Declines to Just Over Two Weeks

According to the M-Trends 2023 report, the global median dwell time – which is calculated as the median number of days an attacker is present in a target’s environment before being detected – continues to drop year-over-year down to 16 days in 2022. This is the shortest median global dwell time from all M-Trends reporting periods, with a median dwell time of 21 days in 2021.

When comparing how threats were detected, Mandiant observed a general increase in the number of organizations that were alerted by an external entity of historic or ongoing compromise. Organizations headquartered in the Americas were notified by an external entity in 55% of incidents, compared to 40% of incidents last year. This is the highest percentage of external notifications the Americas has seen over the past six years. Similarly, organizations in Europe, the Middle East and Africa (EMEA) were alerted of an intrusion by an external entity in 74% of investigations in 2022 compared to 62% in 2021.

Mandiant experts noted a decrease in the percentage of their global investigations involving ransomware between 2021 and 2022. In 2022, 18% of investigations involved ransomware compared to 23% in 2021. This represents the smallest percentage of Mandiant investigations related to ransomware since prior to 2020.

“While we don’t have data that suggests there is a single cause for the slight drop in ransomware-related attacks that we observed, there have been multiple shifts in the operating environment that have likely contributed to these lower figures. These factors include, but are not limited to: ongoing government and law enforcement disruption efforts targeting ransomware services and individuals, which at minimum require actors to retool or develop new partnerships; the conflict in Ukraine; actors needing to adjust their initial access operations to a world where macros may often be disabled by default, as well as organizations potentially getting better at detecting and preventing or recovering from ransomware events at faster rates.” – Sandra Joyce, VP, Mandiant Intelligence at Google Cloud.

Stuart McKenzie, Head of Mandiant Consulting EMEA at Google Cloud, said: “Our latest M-Trends report shows dwell time has decreased for another consecutive year. We look at the median number of days an attacker sits in a target’s environment before being detected – in EMEA this is now less than three weeks, compared to 48 days in the previous year, so an improvement of 58% year-on-year.”

“While this shows clear progress in cyber security capabilities on the part of defenders, we’re also seeing threat actors being increasingly brazen. It’s important that defences aren’t static and organisations are running continuous testing programmes to maintain a strong security posture. As ever, practice makes perfect – one of the best ways to stay prepared is to keep defending against cyber-attacks simulated by a red team. By continuously testing defences against likely, real-world scenarios, an organisation can quickly uncover vulnerabilities and focus on the right things to work on,” concluded Stuart.

Cyber Espionage, Malware Families Increase Globally 

Mandiant identified extensive cyber espionage and information operations leading up to and since Russia’s invasion of Ukraine on February 24, 2022. Most notably, Mandiant saw activity by UNC2589 and APT28 prior to the invasion of Ukraine, and observed more destructive cyber attacks in Ukraine during the first four months of 2022 than in the previous eight years.

In 2022, Mandiant began tracking 588 new malware families, revealing how adversaries are continuing to expand their toolsets. Of the newly tracked malware families, the top five categories consisted of backdoors (34%), downloaders (14%), droppers (11%), ransomware (7%) and launchers (5%). These categories of malware remain consistent over the years and backdoors continue to represent a little over one third of the newly tracked malware families.

In line with previous years, the most common malware family identified by Mandiant in investigations was BEACON, a multi-function backdoor. In 2022, BEACON was identified in 15% of all intrusions investigated by Mandiant and remains by far the most seen in investigations across regions. It has been used by a wide variety of threat groups tracked by Mandiant including nation state-backed threat groups attributed to China, Russia and Iran, as well as financial threat groups and over 700 UNC groups. This ubiquity is likely due to the common availability of BEACON combined with the malware’s high customizability and ease of use, according to the report.

“Mandiant has investigated several intrusions carried out by newer adversaries that are becoming increasingly savvy and effective. They leverage data from underground cybercrime markets, conduct convincing social engineering schemes over voice calls and text messages, and even attempt to bribe employees to obtain access to networks. These groups pose a significant risk to organizations, even those with robust security programs, as these techniques are challenging to defend against. As organizations continue to build their security teams, infrastructure, and capabilities, protecting against these threat actors should be part of their design goals.” – Charles Carmakal, CTO, Mandiant Consulting at Google Cloud

Actioning Intelligence

The goal of M-Trends is to arm security professionals with insights on the latest attacker activity as seen directly on the frontlines, backed by actionable intelligence to improve organizations’ security postures within an evolving threat landscape. To meet this objective, Mandiant provides insight into some of the most prolific threat actors and their expanding tactics, techniques and procedures.

To further support this objective, Mandiant mapped an additional 150 Mandiant techniques to the updated MITRE ATT&CK® framework, bringing the total to 2,300+ Mandiant techniques and subsequent findings associated with the ATT&CK framework. Organizations should prioritize which security measures to implement based on the likelihood of a specific technique being used during an intrusion.

Additional takeaways from M-Trends 2023 Report include:

  • Infection vector: For the third year in a row, exploits remained the most leveraged initial infection vector used by adversaries at 32%. While this was a decrease from the 37% of intrusions identified in 2021, exploits remained a critical tool for adversaries to use against their targets. Phishing returned as the second most utilized vector, representing 22% of intrusions as compared to 12% in 2021.
  • Target industries impacted: Response efforts for government-related organizations captured 25% of all investigations, compared to 9% in 2021. This primarily reflects Mandiant’s investigative support of cyber threat activity which targeted Ukraine. The next four most targeted industries from 2022 are consistent with what Mandiant experts observed in 2021, with business & professional services, financial, high tech, and healthcare industries being favored by adversaries. These industries remain attractive targets for both financially and espionage motivated actors.
  • Credential theft: Mandiant investigations uncovered an increased prevalence in both the use of widespread information stealer malware and credential purchasing in 2022 when compared to previous years. In many cases, investigations identified that credentials were likely stolen outside of the organization’s environment and then used against the organization, potentially due to reused passwords or use of personal accounts on corporate devices.
  • Data theft: Mandiant experts identified that in 40% of intrusions in 2022, adversaries prioritized data theft. Mandiant defenders have observed threat actors attempting to steal, or successfully completing data theft operations more often in 2022 compared to previous years.
  • North Korea’s Use of Crypto: Alongside traditional intelligence collection missions and disruptive attacks, in 2022, Democratic People’s Republic of Korea operators showed more interest in stealing—and using—cryptocurrency. These operations have been highly lucrative and will likely continue unabated throughout 2023. For more on how North Korean threat actors are using cybercrime as a way to fund their espionage operations, check out Mandiant’s APT43 report.

M-Trends 2023 Methodology:

The metrics reported in M-Trends 2023 are based on Mandiant Consulting Investigations of targeted attack activity between January 1, 2022 and December 31, 2022. The intelligence gleaned has been sanitized to protect the identities of targets and their data.

Resources:

M-Trends 2023 Report: www.mandiant.com/m-trends

Related Articles

  • Aster DM Healthcare launches myAster in Saudi Arabia
  • API supergroup unveils its first CEO and new name
  • Interview: AI-Powered Security
[easy-social-share buttons="facebook,twitter,google,linkedin,stumbleupon,pinterest" counters=0 hide_names="force" fixedwidth="yes" fixedwidth_px="111"]
constantly changing threat landscape Google Cloud high-impact cyber attacks investigations Mandiant's M-Trends 2023 report ransomware

Previous ArticleHuawei announces 2023 Q1 business resultsNext ArticleMindware signs master distribution rights for Genesys in MEA

Related Articles

  • Help AG Unveils Top Digital Threats and Trends in Cybersecurity
  • Google Cloud recognises Oredata as MENAT Region Partner of the Year
  • Google Cloud announce appointment of Ziad Jammal as UAE Country Manager

Most Read in Enterprise

ASUS brings “Design You Can Feel” to Dubai Design Week 2025

2 days agoOctober 31, 2025
tahawultech tahawultech.com @tahawultech ·
31 Oct

Organisations are beginning to realise that their historical data is more than just insurance, it’s a powerful, untapped strategic asset, says Pranay Ahlawat, Chief Technology and AI Officer at Commvault.
https://ow.ly/b0LV50XkUal

Reply on Twitter 1984243708959564245 Retweet on Twitter 1984243708959564245 Like on Twitter 1984243708959564245 Twitter 1984243708959564245
tahawultech tahawultech.com @tahawultech ·
31 Oct

Roque Lozano, SVP of Network Infrastructure, MEA at Nokia, shares how the company is driving sovereign, AI-ready infrastructure, advancing quantum-safe security, and shaping the region’s digital future.
https://ow.ly/Looa50XkTHR

Reply on Twitter 1984241023157928339 Retweet on Twitter 1984241023157928339 Like on Twitter 1984241023157928339 Twitter 1984241023157928339
tahawultech tahawultech.com @tahawultech ·
31 Oct

ENECIQ sets a benchmark in innovation for sovereign agentic AI deployment within critical national infrastructure, representing one of the most advanced corporate-wide implementations, says Thomas Pramotedham, Chief Executive Officer of Presight.
https://ow.ly/EYk250XkRmf

Reply on Twitter 1984222683349864724 Retweet on Twitter 1984222683349864724 Like on Twitter 1984222683349864724 Twitter 1984222683349864724
Load More

RECOMMENDED FOR YOU

  • Opinion: Role of AI in cybersecurity
  • Mindware partners up to promote regional growth
  • Exclusive Interview: Aloysius Cheang, Chief Security Officer, Huawei Middle East and Central Asia
  • Qualys’ 2023 TruRisk report: more than 2.3 billion vulnerabilities detected worldwide in 2022

GET TAHAWULTECH.COM IN YOUR INBOX

The free newsletter covering the top industry headlines

CPI Media Group
TahawulTech.com is the definitive platform in the Middle East for IT content. Covering stories across enterprise technology, cybersecurity and the region’s IT channel industry, TahawulTech.com brings business leaders and technology decision makers together to share their stories of transformation.

OTHER LINKS

  • Events and Conferences
  • Media Pack
  • Resource Centre
  • Subscription

 

  • Advertise
  • Contact Us
  • Privacy Policy

Contact Us

Office:
Office 1307, Dubai Studio City
Dubai, United Arab Emirates, PO Box 13700
Tel: +971 4 568 2993
Email: info@tahawultech.com
© 2025 All Rights Reserved. Product of CPI
Menu
  • Region
    • UAE
    • Saudi Arabia
    • Oman
    • Bahrain
    • Kuwait
    • Africa
    • Middle East
    • Global
  • Industry
    • Education
    • Energy
    • Financial services
    • Government
    • Healthcare
    • Property
    • Retail
    • Technology
    • Transport & Logistics
    • Travel & Hospitality
  • Company
    • Enterprise
    • Corporate
    • SME
    • Startup
    • Vendor
    • Channel
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
    • Software
    • Hardware
    • Networking
    • Security
    • Channel
    • Telecoms
    • Video
  • Features
    • Features
    • CIO Spotlight
    • Case Studies
    • Partner Watch
    • Vendor focus
    • Analysis
    • Video
    • Lifestyle
    • Insight
    • Opinion
    • Blogs
  • News
    • Region
  • Magazines
    • CNME
    • Reseller ME
    • Security Advisor ME
    • GITEX 60 Minutes
    • LEAP 60 Minutes
    • Supplements
  • Events & Conferences
    • Awards
    • Customer Events
    • Forums
    • Your Voice
    • Webinars
  • GITEX 2025
  • Black Hat
  • Bitz News
    • Business News
    • Financial News
  • Example Column Title
    • Bitz News Group Websites:
    • Insider Journal
    • Business Day
    • Weekly Selection
    • Tech News
    • Cool Stories
    • Geek Reviews
 

Loading Comments...
 

    tahawultech.com Intro