Skip to main content

TrendAI™ Deep Research

spark

Featured Articles

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure
Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

TrendAI™ Research
Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoT & smart devicesASM ASRM
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data

China-aligned operational relay box (ORB) infrastructure is harvesting open sensor data at scale, and most defenders can't see it. Our report dives into how these ORBs can use open telemetry for data collection and other purposes.

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
HacktivismRansomware & extortion
Mapping the Criminal Economy Targeting Critical Infrastructure

TrendAI™ Research went inside the forums, marketplaces, and Telegram channels where access to factories, utilities, and energy firms is bought, sold, and weaponized. Combing through two years’ worth of data revealed an underground where financially motivated brokers and ransomware crews now operate alongside state-aligned hacktivists, sharing the same entry vectors, the same pirated training, and in some cases, the same personnel.

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
IPFS: A New Data Frontier or a New Cybercriminal Hideout?

In this article, we briefly detail what IPFS is and how it works at the user level, before providing up to date statistics about the current usage of IPFS by cybercriminals, especially for hosting phishing content. We will also discuss emerging new cybercrime activities abusing the IPFS protocol and detail how cybercriminals already consider IPFS for their deeds.

Read Article
Ransomware & extortionExploits & Zero-Days
Ransomware Spotlight: Royal

Backed by threat actors from Conti, Royal ransomware is poised to wreak havoc in the threat landscape, starting strong by taking a spot among the most prolific ransomware groups within three months since it was first reported. Combining new and old techniques and quick evolution, it is likely to remain a big player in the threat landscape in the future.

Read Article
Cybercriminal underground
The Gender-Equal Cybercriminal Underground

A look into the cybercriminal gender gap, the status and perceptions on gender profiles in the underground, and the role assumptions have for law enforcement.

Read Article
Ransomware & extortion
Ransomware Spotlight: Magniber

The Magniber ransomware initially targeted only Asian countries when it was first detected in 2017. However, it resurfaced in 2021 and continues to operate today with expanded targets around the globe. Magniber remains a significant player in the threat landscape, with malicious attackers likely to continue using the ransomware in future.

Read Article
Ransomware & extortionCyber crime
The Future of Ransomware

Our research looks at the potential evolutions and revolutions in the current ransomware landscape based on significant triggers and catalysts. We highlight the specific developments (triggers) that could cause gradual changes (evolutions) before sparking more drastic transformations (revolutions).

Read Article
Ransomware & extortion
Ransomware Spotlight: Cuba

Cuba ransomware emerged on the scene with a spate of high-profile attacks in late 2021. Armed with an expansive infrastructure, impressive tools, and associated malware, Cuba ransomware is considered a significant player in the threat landscape, and is likely to remain so in the future through its continued evolution.

Read Article
By The NumbersRansomware & extortion
LockBit and Black Basta Are the Most Active RaaS Groups as Victim Count Rises: Ransomware in Q2 and Q3 2022

We discuss key trends in the ransomware threat landscape from April to September 2022. Data from RaaS and extortion groups’ leak sites, open-source intelligence (OSINT) research, and the Trend Micro™ Smart Protection Network™ points to LockBit, BlackCat, Black Basta, and Karakurt as the most active groups with the most victims.

Read Article
Zero trust
Zero Trust: Enforcing Business Risk Reduction Through Security Risk Reduction

Unlike traditional legacy trust models where security is not always present in all cases, Zero Trust revolves around an ”always-on everywhere” approach.

Read Article
Ransomware & extortionExploits & Zero-Days
Ransomware Spotlight: BlackCat

Known for its unconventional methods and use of advanced extortion techniques, BlackCat has quickly risen to prominence in the cybercrime community. As this ransomware group forges its way to gain more clout, we examine its operations and discuss how organizations can shore up their defenses against it.

Read Article
OT & critical infrastructure
Uncovering Security Weak Spots in Industry 4.0 CNC Machines

The technological leaps of the Fourth Industrial Revolution may have made production machinery more efficient, but these have also put manufacturers in the crosshairs of cybercriminals. Our research tackles the risks that computer numerical control (CNC) machines now face as they’re integrated into today’s networked factories.

Read Article