TahawulTech.com
  • TahawulTech.com
  • Country/Region
    • UAE
      • Smart security adoption rises in Saudi homes with a digital-first approach
      • Cynalytica pioneers cybersecurity solutions for critical infrastructure protection 
      • Empowering HR for global growth on International HR Day
      • CrowdStrike highlights AI innovations shaping cyber defence at GISEC 2025
      • Kaspersky’s Cyber Immunity protects critical infrastructure, shapes the future of security 
    • Saudi Arabia
      • Smart security adoption rises in Saudi homes with a digital-first approach
      • Cisco expands partnership with Saudi Arabia 
      • Sophos powers up cybersecurity in the UAE 
      • Aster Pharmacy unveils largest regional store in Riyadh, pioneering digital healthcare integration
        Aster Pharmacy unveils largest regional store in Riyadh, pioneering digital healthcare integration
      • Cisco expands in Saudi Arabia with cloud data centers, AI talent development, and manufacturing plans
    • Oman
      • Microsoft AI Tour showcases groundbreaking AI innovations for Oman
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • KROHNE delivers insights to inspire the next generation of engineers in Oman
      • Oracle supports major project to accelerate Oman digital economy
      • Ooredoo accelerates cybersecurity in Oman with new deal
    • Bahrain
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • BDB launches “tijara” platform for SMEs
      • Bahrain achieves full nationwide 5G coverage
      • Batelco, SonicWall launch integrated security solutions for SMEs in Bahrain
      • Bahrain to offer COVID-19 test results on WhatsApp, Facebook Messenger
    • Kuwait
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Infopercept opens its first Middle East office in Kuwait
      • Microsoft Compliance Manager now available in Kuwait
      • Commercial Bank of Kuwait gets mobile payments moving with Thales Digital Solutions
      • Ooredoo chooses Fortinet to deliver secure SD-WAN managed services in Kuwait
    • Africa
      • Rise of Fearless launches $700K investment round to advance Web3 mobile gaming in Africa 
      • e& enterprise and RAIN Technology to revolutionise Operating Room efficiency in hospitals across MEA
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Looking for the best label solutions in South Africa? Go OKI!
      • OKI is only going bigger in the South African market!
    • Middle East
      • Cynalytica pioneers cybersecurity solutions for critical infrastructure protection 
      • Why Passwords still matter as a first line of cybersecurity in Middle East
      • Qlik expands cloud footprint with new AWS region in Middle East
      • ASUS unveils latest ExpertBook P1 models
      • e& UAE revolutionises telecom tower inspections with AI-powered drones
    • Global
      • Cynalytica pioneers cybersecurity solutions for critical infrastructure protection 
      • Samsung, e& UAE sign strategic MoU to advance AI-driven innovation, digital experiences at MWC
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Gender Lens investing vital to economic recovery
      • Virgin Hyperloop unveils location for Hyperloop certification centre
  • Industry
    • Education
      • DHA signs MoU to train leadership in AI
      • Dubai Future Foundation, University of Birmingham Dubai boost AI collaboration  
      • GDRFA – Dubai launches 8th ICEQ International Conference
      • Bybit partners with University of Wollongong in Dubai to host Demo Trading Challenge
      • National IT Academy and Microsoft launch the first Microsoft Datacentre Academy in the Region
    • Energy
      • Solis poised to transform Dubai’s skyline and deserts into beacons of sustainability
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Huawei launches ground-breaking solar inverter at World Future Energy Summit
      • Middle East Energy to further boost their sustainability agenda
      • EDF UK selects Dynatrace to keep the power flowing
    • Financial services
      • MENA Fintech Association announces new leadership for Digital Assets Working Group 
      • IHC, ADQ and FAB pioneer UAE Dirham-backed Stablecoin for digital economy
      • MENA Fintech Association, International Smart Card to shape future of digital finance
      • Emirates NBD’s collaboration with Kinexys to enhance cross-border payment security
      • Continental advances AI Integration to boost efficiency, protect client trust
    • Government
      • GDRFA–Dubai concludes ICEQ 2025 Conference; launches “Pioneering Scientific Research Award”
      • DFF, Google Cloud launch AI upskilling initiative for Dubai Chief AI Officers 
      • MBRHE and Beyond Limits AI MoU to enhance digital transformation
      • Dubai govt achieves major efficiency gains through AI, says 15 AI Use Cases report
      • 94% of Dubai govt employees express optimism over impact of generative AI
    • Healthcare
      • DHA to leverage AI-powered ‘Genesys’ system in contact centre services 
      • AI to lead Dubai’s healthcare transformation, says DHA head
      • BD hosts Healthcare Summit in Riyadh in line with Vision 2030
      • e& enterprise and RAIN Technology to revolutionise Operating Room efficiency in hospitals across MEA
      • How will Agentic AI ease healthcare’s workforce crisis?
    • Property
      • DLD boosts transparency with AI-enabled real estate advertising governance 
      • MBRHE and Beyond Limits AI MoU to enhance digital transformation
      • Huspy launches GCC’s first AI-powered mortgage chatbot to transform home financing  
      • DLD, VARA collaborate to boost leadership in realty and virtual assets regulation
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
    • Retail
      • Jacky’s Business Solutions unveils Agentic AI offering to accelerate GCC’s autonomous business future
      • Skills gap, data hurdles, and ethics key to unlocking AI in GCC retail, says Al-Futtaim
      • ASUS unveils latest ExpertBook P1 models
      • 75% of retailers say AI Agents will be essential to compete
      • New data: Gen Z embraces AI for social media spending
    • Technology
      • Smart security adoption rises in Saudi homes with a digital-first approach
      • Cynalytica pioneers cybersecurity solutions for critical infrastructure protection 
      • BeamSec launches MailX at GISEC 2025
      • NTT DATA Unveils Smart AI AgentTM Ecosystem
      • CrowdStrike highlights AI innovations shaping cyber defence at GISEC 2025
    • Transport & Logistics
      • RTA launches AI Strategy 2030 featuring 81 projects and initiatives 
      • Emirates Group co-locates to world’s largest solar-powered data centre
      • Uber School launches for students in Dubai in collaboration with RTA
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • HID transforms ticket validation and fare collection for mass transit
    • Travel & Hospitality
      • 8th Int’l Conference on Education Quality kicks off in Dubai; highlights AI innovations
      • Arabian Travel Market to gather global AI experts to explore new frontiers in travel
      • Smartphones, social media drive travel decisions for Indians, says travel report
      • Emirates Group co-locates to world’s largest solar-powered data centre
      • Emirates advances fleet availability with investment in Airbus Skywise S.FP+ and Core X3 digital predictive maintenance solution
  • Company
    • Enterprise
      • Tenable appoints Eric Doerr as Chief Product Officer
      • Qlik launches new Open Lakehouse
      • AI takes centre stage at Customer Experience Live Show Middle East 2025
      • Vertiv to supply Polar’s data centre in Norway
      • Bybit surpasses 70 million users 
    • Corporate
      • Qlik expands cloud footprint with new AWS region in Middle East
      • PeopleStrong powers UAE’s talent shift, accelerates ME growth: Mrigank Tripathi
      • Microsoft names Samer Abu-Ltaif president for Europe, ME and Africa
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • YouGotaGift CEO says ‘product-centricity’ the key to their phenomenal success
    • SME
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
      • Alaris expands information capture ecosystem for SMEs
      • “Innovation is a focal point in Abu Dhabi’s plans,” says DED chair
    • Startup
      • AI without borders: Startups leading the next global leap 
      • Secure Domains brings cutting-edge DNS protection to MENA region 
      • Open Innovation AI collaborates with Intel to revolutionize AI orchestration with Gaudi
      • Kaspersky exposes new scam targeting SMBs
      • Thriwe: Enhancing the Omni-channel experience
    • Vendor
      • Tenable appoints Eric Doerr as Chief Product Officer
      • BeamSec launches MailX at GISEC 2025
      • Qlik launches new Open Lakehouse
      • Qualys selects Teksalah to join mROC Partner Alliance 
      • NTT DATA Unveils Smart AI AgentTM Ecosystem
    • Channel
      • Qualys selects Teksalah to join mROC Partner Alliance 
      • Proofpoint signs agreement to acquire HornetSecurity
      • StarLink empowers the channel through growth and innovation
      • Bybit and Ghaf Labs announce strategic partnership
      • VAST Data becomes core to Google Cloud’s Infrastructure 
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
      • Smart security adoption rises in Saudi homes with a digital-first approach
      • Pure Storage technologies help The Saudi Investment Bank to modernise and transform customer experiences
      • G42 partners with Italian company to deploy Europe’s largest AI compute cluster
      • Cynalytica pioneers cybersecurity solutions for critical infrastructure protection 
      • IBM partners with University of Sharjah on new app designed to promote sustainable agriculture
    • Software
      • Cisco innovates with Agentic AI
      • Fortinet expands FortiAI across its Security Fabric Platform
      • Dynatrace announces early access to its platform innovations
      • Kaspersky Research Sandbox 3.0: more power, less hardware
      • World Backup Day: Toshiba highlights the importance of data resilience
    • Hardware
      • Netherlands talks with Nvidia and AMB over supply for AI-facility
      • ASUS Evo lineup: Enhancing the online experience
      • ASUS A3402-Next level computing performance
      • The UAE ranks 8th globally for the readiness of markets for electric transportation
      • Hikvision Commercial Display and Malco Technologies host partner event
    • Networking
      • World Backup Day: Toshiba highlights the importance of data resilience
      • Optimizing IT infrastructure: How Perforator can cut costs and boost performance 
      • NO PAY NO PLAY: Chainalysis reports shows ransomware payments down by 35% as victims refuse to cough up
      • Aleph Alpha launch groundbreaking T-Free architecture for next-generation LLMs, collaborates with AMD, Schwarz Digits
      • Samsung Galaxy S25 series debuts with pioneering AI features and exclusive Snapdragon 8 Elite chipset
    • Security
      • Smart security adoption rises in Saudi homes with a digital-first approach
      • Cynalytica pioneers cybersecurity solutions for critical infrastructure protection 
      • CrowdStrike highlights AI innovations shaping cyber defence at GISEC 2025
      • Kaspersky’s Cyber Immunity protects critical infrastructure, shapes the future of security 
      • SentinelOne’s AI-driven solutions transform cybersecurity operations at GISEC 2025
    • Channel
      • Qualys selects Teksalah to join mROC Partner Alliance 
      • Proofpoint signs agreement to acquire HornetSecurity
      • StarLink empowers the channel through growth and innovation
      • Bybit and Ghaf Labs announce strategic partnership
      • VAST Data becomes core to Google Cloud’s Infrastructure 
    • Telecoms
      • e& AGM approves 83 fils dividend per share for FY 2024
      • Mada & SALAM ink pact on Cutting-Edge Messaging Solutions 
      • NO PAY NO PLAY: Chainalysis reports shows ransomware payments down by 35% as victims refuse to cough up
      • Proofpoint named a leader in 2024 Gartner® Magic Quadrant™
      • Samsung Galaxy S25 series debuts with pioneering AI features and exclusive Snapdragon 8 Elite chipset
    • Video
      • Relive all the excitement from the Infosec and Cybersecurity Congress 2025
      • SANS Institute unveils key strategies for securing AI technologies in 2025
      • Seclore showcases data-centric security innovations at GISEC Global 2025
      • Cyble’s AI-driven cybersecurity vision takes centre stage at GISEC Global 2025
      • Finesse bolsters cybersecurity with AI-powered SOC and advanced penetration testing
  • Features
    • Features
      • How Immersive Environments are Changing Hospitality, Retail, and Public Spaces
      • CrowdStrike highlights AI innovations shaping cyber defence at GISEC 2025
      • ManageEngine unveils AI-powered unified cybersecurity solutions at GISEC Global 2025
      • Tenable champions proactive cybersecurity with business-aligned exposure management
      • Nozomi Networks enhances critical infrastructure security amid evolving cyber threats
    • CIO Spotlight
      • DMCC
        Rare commodity: DMCC IT director Abdalla Al Ali
      • HSBC MENAT CIO Ghinwa Baradhi
        The bigger picture: HSBC MENAT CIO Ghinwa Baradhi
      • Mubadala Investment Company CIO Mansour Al Ketbi
        Mansour Al Ketbi unites IT teams for $125 billion Mubadala Investment Company
      • Tariq Al Usaimi, head of digital strategy for the Central Bank of Kuwait
        The new breed: National Bank of Kuwait CDO Tariq Al-Usaimi
      • Al Masah Capital CIO Ashith Piriyattiath
        Ashith Piriyattiath’s diverse & transformative GCC career
    • Case Studies
      • Survey reveals misalignment between cybersecurity and business goals in the UAE and KSA
      • 3,200+ fake Meta profiles used in Facebook scam attempt
      • Edenred UAE: Transforming Customer Service Over WhatsApp with Conversations and Answers
      • Customer Story: Nissan Saudi Arabia
      • elseco
        DIFC prioritises digital transformation to enhance connectivity and accessibility with Wi-Fi 6
    • Partner Watch
      • Juniper Networks Expands Partner Ecosystem Leveraging AI-Native Networking Solutions
      • Commvault selects AlJammaz Technologies as key distributor in the Kingdom of Saudi Arabia
      • Kaspersky signs MoU with Zayed University
      • F5 Appoints Al Jammaz as a Value-Added Distribution Partner
      • The time is now for RNS Managed Security Services
    • Vendor focus
      • Dell Technologies To Establish New Merge & Logistics Fulfilment Hub in Riyadh
      • Dell Technologies study reveals innovation leaders better equipped for economic challenges
      • A10 Networks partners on a mission to ‘accelerate’
      • “The world is on the verge of a new intelligent era powered by Industry 5.0” – David Shi, Huawei
      • Huawei signs new partnership in effort to accelerate SMBs digital transformation
    • Analysis
      • Special Feature: Data Security in the Banking and Financial Sectors
      • Safeguarding Healthcare: Protecting Critical Data and Patient Privacy
      • Trend Micro Predictions Report Forecasts Cyber Fightback in 2022
      • Frost & Sullivan Names Tenable a Growth and Innovation Leader in the Global Vulnerability Management Market, 2021
      • Gartner Identifies the Top Trends Impacting Infrastructure and Operations for 2022
    • Video
      • Relive all the excitement from the Infosec and Cybersecurity Congress 2025
      • SANS Institute unveils key strategies for securing AI technologies in 2025
      • Seclore showcases data-centric security innovations at GISEC Global 2025
      • Cyble’s AI-driven cybersecurity vision takes centre stage at GISEC Global 2025
      • Finesse bolsters cybersecurity with AI-powered SOC and advanced penetration testing
    • Lifestyle
      • DHA signs MoU to train leadership in AI
      • AI to lead Dubai’s healthcare transformation, says DHA head
      • Arabian Travel Market to gather global AI experts to explore new frontiers in travel
      • Smartphones, social media drive travel decisions for Indians, says travel report
      • Emirates Group co-locates to world’s largest solar-powered data centre
    • Insight
      • How Immersive Environments are Changing Hospitality, Retail, and Public Spaces
      • AI takes centre stage at Customer Experience Live Show Middle East 2025
      • ManageEngine unveils AI-powered unified cybersecurity solutions at GISEC Global 2025
      • “Endava plays a critical role in helping organisations realise the full potential of Agentspace.” – Andrew Rossiter, Endava
      • Tenable champions proactive cybersecurity with business-aligned exposure management
    • Opinion
      • How Immersive Environments are Changing Hospitality, Retail, and Public Spaces
      • “Endava plays a critical role in helping organisations realise the full potential of Agentspace.” – Andrew Rossiter, Endava
      • The DNA of a brand message that ‘no one’ can steal
      • Endava executive outlines how enterprises can tread that elusive path of AI adoption and modernisation
      • “Sovereign AI is more than just technology – it’s a commitment to governance, ethics and citizen empowerment.” – Mohammed Amin, Dell Technologies
    • Blogs
      • Why I joined Cloudflare: To build world-class partnerships in EMEA
      • Revolutionising fan engagement in football through data, gamification, and smart stadium experiences
      • How enterprises can raise their cyber security readiness by going through 3 stages of preparation
      • Maestro Blocks: Transferring passion into businesses!
      • Fighting glare: addressing urban light pollution from traffic cameras
  • News
    • Region
      • Smart security adoption rises in Saudi homes with a digital-first approach
      • Cynalytica pioneers cybersecurity solutions for critical infrastructure protection 
      • Tenable appoints Eric Doerr as Chief Product Officer
      • BeamSec launches MailX at GISEC 2025
      • Qlik launches new Open Lakehouse
  • Magazines
    • CNME
      • May 2025
      • April 2025
      • March 2025
      • February 2025
      • January 2025
    • Reseller ME
      • May 2025
      • April 2025
      • February 2025
      • January 2025
      • October 2024
    • Security Advisor ME
      • May 2025
      • April 2025
      • March 2025
      • February 2025
      • January 2025
    • 60 Minutes
      • 60mins Day 5 – PM (2024)
      • 60mins Day 5 – AM (2024)
      • 60mins Day 4 – PM (2024)
      • 60mins Day 4 – AM (2024)
      • 60mins Day 3 – PM (2024)
    • Supplements
      • GovTech – October 2024
      • GITEX Tech Vision 2024
      • LinkShadow Special Report October 2024
      • GovTech – May 2023
      • Pure Accelerate Riyadh Recap
  • Events
    • Awards
      • GovTech Awards 2025
      • Infosec & Cybersecurity Congress 2025
      • CIO Leadership Awards 2025
      • Reseller Middle East Partner Excellence Awards 2024
      • KSA Executive Summit on AI, Cybersecurity, and Emerging Technologies
    • Customer Events
      • Infosec & Cybersecurity Congress 2025
      • Infosec & Cybersecurity Congress 2024
      • Infosec & Cybersecurity Congress 2023
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
      • Expectations vs Investment
    • Forums
      • Women in Tech (Pride of Tech) Forum and Awards 2025
      • Infosec & Cybersecurity Congress 2025
      • Women in Tech (Pride of Tech) Forum and Awards 2024
      • Tahawultech Conference 2025
      • CISO 50 & Future Security Awards 2024
    • Your Voice
      • Race to innovate | Your Voice | Tahawul Tech
        Race to Innovate
      • Expectations vs Investment
      • Rise of e-commerce
      • Combating credit crunch
    • Webinars
      • Freshworks virtual webinar highlights increasing role of IT industry in accelerating digital transformation
      • Mimecast virtual webinar highlights importance of brand protection
      • Huawei and IDC collaborate on Autonomous Network white paper
      • WEBINAR: Experience the Intelligent HPE Hyperconverged and Composable Infrastructure
      • WEBINAR: How Alpha Data and Veritas Enable Enterprises to Win the War Against Ransomware
  • GISEC 2025
  • LEAP 2025
Don’t show this ad again.
D-Link
Bahwan CyberTek
Fortinet
Enterprise, Features, News

Mandiant’s M-Trends 2023 report reveals frontline threat intelligence

by Veronica Martin
May 2, 2023, 9:15 amMay 2, 2023

The results of the M-Trends 2023 report by Mandiant Inc., now a part of Google Cloud, have been announced and offer up-to-date information and knowledgeable analysis on the constantly changing threat landscape based on frontline Mandiant investigations and remediations of high-impact cyber attacks globally.

The new report reveals the progress organizations globally have made in strengthening defenses against increasingly sophisticated adversaries.

“M-Trends 2023 makes it clear that, while our industry is getting better at cyber security, we are combating ever evolving and increasingly sophisticated adversaries. Several trends we saw in 2021 continued in 2022, such as an increasing number of new malware families as well as rising cyber espionage from nation-state-backed actors. As a result, organizations must remain diligent and continue to enhance their cyber security posture with modern cyber defense capabilities. Ongoing validation of cyber resilience against these latest threats and testing of overall response capabilities are equally critical.” – Jurgen Kutscher, VP, Mandiant Consulting at Google Cloud

Global Median Dwell Time Declines to Just Over Two Weeks

According to the M-Trends 2023 report, the global median dwell time – which is calculated as the median number of days an attacker is present in a target’s environment before being detected – continues to drop year-over-year down to 16 days in 2022. This is the shortest median global dwell time from all M-Trends reporting periods, with a median dwell time of 21 days in 2021.

When comparing how threats were detected, Mandiant observed a general increase in the number of organizations that were alerted by an external entity of historic or ongoing compromise. Organizations headquartered in the Americas were notified by an external entity in 55% of incidents, compared to 40% of incidents last year. This is the highest percentage of external notifications the Americas has seen over the past six years. Similarly, organizations in Europe, the Middle East and Africa (EMEA) were alerted of an intrusion by an external entity in 74% of investigations in 2022 compared to 62% in 2021.

Mandiant experts noted a decrease in the percentage of their global investigations involving ransomware between 2021 and 2022. In 2022, 18% of investigations involved ransomware compared to 23% in 2021. This represents the smallest percentage of Mandiant investigations related to ransomware since prior to 2020.

“While we don’t have data that suggests there is a single cause for the slight drop in ransomware-related attacks that we observed, there have been multiple shifts in the operating environment that have likely contributed to these lower figures. These factors include, but are not limited to: ongoing government and law enforcement disruption efforts targeting ransomware services and individuals, which at minimum require actors to retool or develop new partnerships; the conflict in Ukraine; actors needing to adjust their initial access operations to a world where macros may often be disabled by default, as well as organizations potentially getting better at detecting and preventing or recovering from ransomware events at faster rates.” – Sandra Joyce, VP, Mandiant Intelligence at Google Cloud.

Stuart McKenzie, Head of Mandiant Consulting EMEA at Google Cloud, said: “Our latest M-Trends report shows dwell time has decreased for another consecutive year. We look at the median number of days an attacker sits in a target’s environment before being detected – in EMEA this is now less than three weeks, compared to 48 days in the previous year, so an improvement of 58% year-on-year.”

“While this shows clear progress in cyber security capabilities on the part of defenders, we’re also seeing threat actors being increasingly brazen. It’s important that defences aren’t static and organisations are running continuous testing programmes to maintain a strong security posture. As ever, practice makes perfect – one of the best ways to stay prepared is to keep defending against cyber-attacks simulated by a red team. By continuously testing defences against likely, real-world scenarios, an organisation can quickly uncover vulnerabilities and focus on the right things to work on,” concluded Stuart.

Cyber Espionage, Malware Families Increase Globally 

Mandiant identified extensive cyber espionage and information operations leading up to and since Russia’s invasion of Ukraine on February 24, 2022. Most notably, Mandiant saw activity by UNC2589 and APT28 prior to the invasion of Ukraine, and observed more destructive cyber attacks in Ukraine during the first four months of 2022 than in the previous eight years.

In 2022, Mandiant began tracking 588 new malware families, revealing how adversaries are continuing to expand their toolsets. Of the newly tracked malware families, the top five categories consisted of backdoors (34%), downloaders (14%), droppers (11%), ransomware (7%) and launchers (5%). These categories of malware remain consistent over the years and backdoors continue to represent a little over one third of the newly tracked malware families.

In line with previous years, the most common malware family identified by Mandiant in investigations was BEACON, a multi-function backdoor. In 2022, BEACON was identified in 15% of all intrusions investigated by Mandiant and remains by far the most seen in investigations across regions. It has been used by a wide variety of threat groups tracked by Mandiant including nation state-backed threat groups attributed to China, Russia and Iran, as well as financial threat groups and over 700 UNC groups. This ubiquity is likely due to the common availability of BEACON combined with the malware’s high customizability and ease of use, according to the report.

“Mandiant has investigated several intrusions carried out by newer adversaries that are becoming increasingly savvy and effective. They leverage data from underground cybercrime markets, conduct convincing social engineering schemes over voice calls and text messages, and even attempt to bribe employees to obtain access to networks. These groups pose a significant risk to organizations, even those with robust security programs, as these techniques are challenging to defend against. As organizations continue to build their security teams, infrastructure, and capabilities, protecting against these threat actors should be part of their design goals.” – Charles Carmakal, CTO, Mandiant Consulting at Google Cloud

Actioning Intelligence

The goal of M-Trends is to arm security professionals with insights on the latest attacker activity as seen directly on the frontlines, backed by actionable intelligence to improve organizations’ security postures within an evolving threat landscape. To meet this objective, Mandiant provides insight into some of the most prolific threat actors and their expanding tactics, techniques and procedures.

To further support this objective, Mandiant mapped an additional 150 Mandiant techniques to the updated MITRE ATT&CK® framework, bringing the total to 2,300+ Mandiant techniques and subsequent findings associated with the ATT&CK framework. Organizations should prioritize which security measures to implement based on the likelihood of a specific technique being used during an intrusion.

Additional takeaways from M-Trends 2023 Report include:

  • Infection vector: For the third year in a row, exploits remained the most leveraged initial infection vector used by adversaries at 32%. While this was a decrease from the 37% of intrusions identified in 2021, exploits remained a critical tool for adversaries to use against their targets. Phishing returned as the second most utilized vector, representing 22% of intrusions as compared to 12% in 2021.
  • Target industries impacted: Response efforts for government-related organizations captured 25% of all investigations, compared to 9% in 2021. This primarily reflects Mandiant’s investigative support of cyber threat activity which targeted Ukraine. The next four most targeted industries from 2022 are consistent with what Mandiant experts observed in 2021, with business & professional services, financial, high tech, and healthcare industries being favored by adversaries. These industries remain attractive targets for both financially and espionage motivated actors.
  • Credential theft: Mandiant investigations uncovered an increased prevalence in both the use of widespread information stealer malware and credential purchasing in 2022 when compared to previous years. In many cases, investigations identified that credentials were likely stolen outside of the organization’s environment and then used against the organization, potentially due to reused passwords or use of personal accounts on corporate devices.
  • Data theft: Mandiant experts identified that in 40% of intrusions in 2022, adversaries prioritized data theft. Mandiant defenders have observed threat actors attempting to steal, or successfully completing data theft operations more often in 2022 compared to previous years.
  • North Korea’s Use of Crypto: Alongside traditional intelligence collection missions and disruptive attacks, in 2022, Democratic People’s Republic of Korea operators showed more interest in stealing—and using—cryptocurrency. These operations have been highly lucrative and will likely continue unabated throughout 2023. For more on how North Korean threat actors are using cybercrime as a way to fund their espionage operations, check out Mandiant’s APT43 report.

M-Trends 2023 Methodology:

The metrics reported in M-Trends 2023 are based on Mandiant Consulting Investigations of targeted attack activity between January 1, 2022 and December 31, 2022. The intelligence gleaned has been sanitized to protect the identities of targets and their data.

Resources:

M-Trends 2023 Report: www.mandiant.com/m-trends

Related Articles

  • Aster DM Healthcare launches myAster in Saudi Arabia
  • API supergroup unveils its first CEO and new name
  • Interview: AI-Powered Security
[easy-social-share buttons="facebook,twitter,google,linkedin,stumbleupon,pinterest" counters=0 hide_names="force" fixedwidth="yes" fixedwidth_px="111"]
constantly changing threat landscape Google Cloud high-impact cyber attacks investigations Mandiant's M-Trends 2023 report ransomware

Previous ArticleHuawei announces 2023 Q1 business resultsNext ArticleMindware signs master distribution rights for Genesys in MEA

Related Articles

  • Help AG Unveils Top Digital Threats and Trends in Cybersecurity
  • Google Cloud recognises Oredata as MENAT Region Partner of the Year
  • Google Cloud announce appointment of Ziad Jammal as UAE Country Manager

Most Read in Enterprise

Qlik launches new Open Lakehouse

2 days agoMay 20, 2025

Tenable appoints Eric Doerr as Chief Product Officer

2 days agoMay 20, 2025
tahawultech tahawultech.com @tahawultech ·
20 May

"I’m thrilled to be part of a team that’s building the future of cybersecurity".
Learn more about @TenableSecurity's new CPO below.
https://www.tahawultech.com/enterprise/tenable-appoints-eric-doerr-as-chief-product-officer/
#Tenable #tahawultech

Reply on Twitter 1924757336431984693 Retweet on Twitter 1924757336431984693 Like on Twitter 1924757336431984693 Twitter 1924757336431984693
tahawultech tahawultech.com @tahawultech ·
20 May

"@BeamSec’s AI-first approach represents more than just innovation—it’s a necessary evolution in how organisations prepare, respond, and stay ahead".
Learn more about this GISEC showcase below.
https://www.tahawultech.com/industry/technology/beamsec-launches-mailx-at-gisec-2025/
#BeamSec #tahawultech #GISEC2025

Reply on Twitter 1924751779260203484 Retweet on Twitter 1924751779260203484 Like on Twitter 1924751779260203484 Twitter 1924751779260203484
tahawultech tahawultech.com @tahawultech ·
20 May

Bahir Omar, Virtuwall, explores how projection technology, digital art, and interactive media are enhancing engagement and storytelling.
Read the full op-ed below.
https://www.tahawultech.com/features/how-immersive-environments-are-changing-hospitality-retail-and-public-spaces/
#Virtuwall #tahawultech

Reply on Twitter 1924738363632058603 Retweet on Twitter 1924738363632058603 Like on Twitter 1924738363632058603 Twitter 1924738363632058603
Load More

RECOMMENDED FOR YOU

  • Opinion: Role of AI in cybersecurity
  • Mindware partners up to promote regional growth
  • Exclusive Interview: Aloysius Cheang, Chief Security Officer, Huawei Middle East and Central Asia
  • Qualys’ 2023 TruRisk report: more than 2.3 billion vulnerabilities detected worldwide in 2022

GET TAHAWULTECH.COM IN YOUR INBOX

The free newsletter covering the top industry headlines

CPI Media Group
TahawulTech.com is the definitive platform in the Middle East for IT content. Covering stories across enterprise technology, cybersecurity and the region’s IT channel industry, TahawulTech.com brings business leaders and technology decision makers together to share their stories of transformation.

OTHER LINKS

  • Events
  • Media Pack
  • Resource Centre
  • Subscription

 

  • Advertise
  • Contact Us
  • Privacy Policy

Contact Us

Office:
Office 1307, Dubai Studio City
Dubai, United Arab Emirates, PO Box 13700
Tel: +971 4 568 2993
Email: info@tahawultech.com
© 2025 All Rights Reserved. Product of CPI
Menu
  • Country/Region
    • UAE
    • Saudi Arabia
    • Oman
    • Bahrain
    • Kuwait
    • Africa
    • Middle East
    • Global
  • Industry
    • Education
    • Energy
    • Financial services
    • Government
    • Healthcare
    • Property
    • Retail
    • Technology
    • Transport & Logistics
    • Travel & Hospitality
  • Company
    • Enterprise
    • Corporate
    • SME
    • Startup
    • Vendor
    • Channel
  • Trending
    • Digital Transformation
      • Internet of Things
      • Big Data
      • Blockchain
      • Smart City
      • Cloud Computing
    • Artificial Intelligence
      • Data Centre
      • Machine Learning
      • Virtual Reality
      • Robotics
      • Systems Integrator
      • E-commerce
    • 3D Printing
      • Self-driving Cars
      • Drones
      • Automation
      • Smartphones
      • Wearables
      • Virtualisation
    • Fintech
      • Storage
      • Mobile Payment
      • Startups
      • Applications
      • Security
  • News
    • All News
    • Software
    • Hardware
    • Networking
    • Security
    • Channel
    • Telecoms
    • Video
  • Features
    • Features
    • CIO Spotlight
    • Case Studies
    • Partner Watch
    • Vendor focus
    • Analysis
    • Video
    • Lifestyle
    • Insight
    • Opinion
    • Blogs
  • News
    • Region
  • Magazines
    • CNME
    • Reseller ME
    • Security Advisor ME
    • 60 Minutes
    • Supplements
  • Events
    • Awards
    • Customer Events
    • Forums
    • Your Voice
    • Webinars
  • GISEC 2025
  • LEAP 2025
  • Bitz News
    • Business News
    • Financial News
  • Example Column Title
    • Bitz News Group Websites:
    • Insider Journal
    • Business Day
    • Weekly Selection
    • Tech News
    • Cool Stories
    • Geek Reviews
 

Loading Comments...
 

    tahawultech.com Intro