• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cyber threat intelligence: illuminating the deep, dark cybercriminal underground

Cyber Threat Intelligence: Illuminating the Deep, Dark Cybercriminal Underground

You are here: Home / General Cyber Security News / Cyber Threat Intelligence: Illuminating the Deep, Dark Cybercriminal Underground
July 30, 2024

Learn about critical threats that can impact your organization and the bad actors behind them from Cybersixgill’s threat experts. Each story shines a light on underground activities, the threat actors involved, and why you should care, along with what you can do to mitigate risk.

The deep and dark web, otherwise known as the cybercriminal underground, is where malicious actors gather to exchange plans, sell goods or services, and recruit others to help in their illicit activities. Grasping how it functions and the intelligence it offers is crucial for proactively safeguarding your environment against attacks, as it is in these spaces that threat actors frequently reveal their intentions prior to launching an attack.

The State of the Underground 2024

Our annual State of the Underground 2024 is a detailed report that sheds light on the evolving underworld of cybercrime, exploring trends and behaviors observed within the deep, dark web during 2023. This comprehensive analysis, compiled by Cybersixgill’s cyber threat intelligence experts, provides valuable insights into the tactics, techniques, and technologies employed by threat actors worldwide. Topics addressed in the report include:

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


  • Compromised credit card trends
  • Physical products on the underground
  • Messaging platforms and underground forums
  • Initial access trends
  • Malware and ransomware trends

The report completes its analysis with a look back at Cybersixgill’s 2023 predictions, assessing whether those predictions came true (or not) and the impact they had on the cybersecurity landscape.

Click here to learn more

Take a guided tour of the underground

Because the dark web is a hub for cybercriminals to exchange tools, information, and services, dark web threat intelligence is crucial for companies, as it offers an uncensored view into the current cybercrime landscape and trends. Accessing deep and dark web sources is challenging since they are not indexed and require exact URLs. These underground sites constantly post data, from credit card information and data dumps to compromised endpoints, malicious programs, and narcotics. Join Cybersixgill’s Cyber Threat Intelligence Analyst Michael-Angelo Zummo as he demonstrates how to access the dark web and provides a tour of this hidden world.

Click here to watch

Inside the mind of a hacker

If you’ve ever wondered what life as a threat actor on the cybercriminal underground is like, you’ll want to watch this webinar. In it, our experts provide a rare glimpse into the mind of a hacker and the tools they use to undertake malicious activities. Using the Cyber Kill Chain framework to map the stages of successful cyber attacks, the discussion delves into how hackers think, their methods for infiltrating and exploiting networks, and their motivations for doing so.

Discover more here

Wholesale Access Markets: a feeding ground for ransomware

The first stage of an active cyberattack is gaining initial access to establish a foothold within a network. This step is challenging, so many aspiring attackers buy network access from skilled threat actors. There are two main types of access-as-a-service available on the underground: initial access brokers (IABs) and wholesale access markets (WAMs). IABs auction access to companies for hundreds to thousands of dollars, while WAMs sell access to compromised endpoints for about $10.

WAMs are like flea markets with low prices, a vast inventory, and poor quality (since listings could belong to random individual users or enterprise endpoints). Still, they can play a big role in how threat actors launch ransomware attacks. Our research provides an analysis of SaaS logins in WAM listings and describes how threat actors might attribute the listing to an enterprise. In other words, WAM posts often list the resources into which the compromised endpoint is connected, which can reveal a major vulnerability for enterprises. For-sale systems that are logged onto enterprise software (for example, Slack or Jira) presumably belong to the organization whose name is often mentioned in the URL.

Read more here

To learn more about Cybersixgill’s deep, dark web cyber threat intelligence, contact us to schedule a demo.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «new sidewinder cyber attacks target maritime facilities in multiple countries New SideWinder Cyber Attacks Target Maritime Facilities in Multiple Countries
Next Post: Cybercriminals Target Polish Businesses with Agent Tesla and Formbook Malware cybercriminals target polish businesses with agent tesla and formbook malware»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.