{"id":1752,"date":"2025-04-24T20:41:53","date_gmt":"2025-04-24T20:41:53","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=1752"},"modified":"2025-04-24T20:41:53","modified_gmt":"2025-04-24T20:41:53","slug":"cybercrime-on-foremost-avenue-2025-sophos-information","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=1752","title":{"rendered":"Cybercrime on Foremost Avenue 2025 \u2013 Sophos Information"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Small companies are a main goal for cybercrime, as we highlighted in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/03\/12\/2024-sophos-threat-report\/\">our final annual report<\/a>. Lots of the felony threats we coated in that report remained a significant menace in 2024, together with ransomware\u2013which stays a main existential cyber risk to small and midsized organizations.<\/p>\n<p>Ransomware circumstances accounted for 70 % of Sophos Incident Response circumstances for small enterprise prospects in 2024\u2014and over 90 % for midsized organizations (from 500 to 5000 staff). Ransomware and knowledge theft makes an attempt accounted for practically 30 % of all Sophos Managed Detection and Response (MDR) tracked incidents (wherein malicious exercise of any type was detected) for small and midsized companies.<\/p>\n<p>Whereas ransomware assaults total have declined barely yr over yr, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/04\/30\/the-state-of-ransomware-2024\/\">the price of these assaults total has risen<\/a>, primarily based on knowledge from Sophos\u2019 State of Ransomware report. And although most of the threats noticed in 2024 had been acquainted in kind, different data-focused threats proceed to develop, and new ways and practices have emerged and developed:<\/p>\n<ul>\n<li>Compromised community edge gadgets\u2014firewalls, digital non-public community home equipment, and different entry gadgets\u2014account for 1 \/ 4 of the preliminary compromises of companies in circumstances that may very well be confirmed from telemetry, and is probably going a lot increased.<\/li>\n<li>Software program-as-a-service platforms, which had been extensively adopted by organizations in the course of the COVID pandemic to assist distant work and to enhance total safety posture, proceed to be abused in new methods for social engineering, preliminary compromise, and malware deployment.<\/li>\n<li>Enterprise e-mail compromise exercise is a rising proportion of the general preliminary compromises in cybersecurity incidents\u2014leveraged for malware supply, credential theft, and social engineering for a wide range of felony functions.<\/li>\n<li>One of many drivers of enterprise e-mail compromise is the phishing of credentials with adversary-in-the-middle multifactor authentication (MFA) token seize, a always evolving risk.<\/li>\n<li>Fraudulent purposes carrying malware, or tied to scams and social engineering via SMS and messaging purposes, result in cell threats for small and midsize companies.<\/li>\n<li>Different less-technical threats leveraging the community proceed to be a risk to small companies, once more with evolving patterns of scams.<\/li>\n<\/ul>\n<p>This report focuses on the tendencies seen in cybercriminal assault patterns confronted by small and midsized organizations. Particulars of malware and abused software program most continuously encountered in endpoint detections and incidents is supplied in an appendix to this report, which might be discovered <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2025\/04\/16\/the-sophos-annual-threat-report-appendix-most-frequently-encountered-malware-and-abused-software\/\">right here<\/a>.<\/p>\n<h2>Desk of Contents<\/h2>\n<h2><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600929\"\/>A phrase about our knowledge<\/h2>\n<p>The info utilized in our Annual Menace Report evaluation comes from the next sources:<\/p>\n<ul>\n<li>Buyer stories\u2014this consists of detection telemetry from Sophos endpoint software program working on prospects\u2019 networks, which supplies a broad view of threats encountered, and analyzed inside SophosLabs (on this report, known as endpoint detection knowledge)<\/li>\n<li>Incident knowledge\u2014this consists of each knowledge gathered in the midst of escalations pushed by detection of malicious exercise on MDR prospects\u2019 networks, knowledge gathered by MDR Incident Response \u00a0from buyer incidents, and knowledge gathered by Sophos Incident Response from incidents on buyer networks for organizations of 500 staff or fewer the place there was little or no managed detection and response safety in place. These datasets are handled as a mixed set of incident knowledge on this report.<\/li>\n<li>SecureWorks incident and detection knowledge shouldn&#8217;t be included on this report, because it was primarily based on pre-acquisition telemetry.<\/li>\n<li>All knowledge is from the 2024 calendar yr, until in any other case famous.<\/li>\n<\/ul>\n<p>Buyer report knowledge is a firehose of all detections from endpoints, which normally end in malware being blocked. Incident knowledge, then again, contains knowledge collected from any occasion the place malicious exercise was detected on an MDR buyer community or uncovered as a part of an Incident Response case, and provides a considerably deeper image in lots of circumstances of the intent of exercise and connections to different risk intelligence.<\/p>\n<p>This report focuses on knowledge particular to small and midsized organizations. Deeper dives on the info gathered from Sophos Incident Response and Sophos MDR Operations, together with knowledge on bigger organizations, might be present in our <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.sophos.com\/activeadversary\">Lively Adversary Report\u00a0(AAR<\/a>) collection.<\/p>\n<h2><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600930\"\/>Damaged Home windows (and gateways)<\/h2>\n<p>Whether or not merely misconfigured, utilizing weak credential insurance policies, or working on weak software program or firmware, techniques on the community edge are the preliminary level of compromise for over a 3rd of all incidents involving intrusion into smaller organizations. As <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/10\/31\/digital-detritus-the-engine-of-pacific-rim-and-a-call-to-the-industry-for-action\/\">Sophos CEO Joe Levy identified not too long ago<\/a>, out of date and unpatched {hardware} and software program constitutes an ever-growing supply of safety vulnerabilities, a phenomenon he known as \u201cdigital detritus.\u201d<\/p>\n<p>Whereas zero-day assaults on vulnerabilities are comparatively uncommon in cybercrime focusing on small and medium companies, printed vulnerabilities might be in a short time weaponized by entry brokers and different cybercriminals. This was the case when the backup software program supplier Veeam <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.veeam.com\/kb4649\">launched a safety bulletin<\/a> on CVE-2024-40711 in September 2024\u2014inside a month, cybercriminals had developed an exploit for the vulnerability, and paired it with gaining preliminary entry via VPNs.<\/p>\n<p>The Veeam vulnerability and related documented vulnerabilities that remained unpatched by prospects\u2014a few of them current, however some over a yr previous\u2014performed a job in practically 15 % of the circumstances Sophos MDR tracked involving malicious intrusions in 2024. In practically all circumstances, the vulnerabilities had been reported for weeks if not longer earlier than they had been exploited by attackers, continuously in connection to ransomware assaults. In different circumstances, they had been used to realize preliminary entry by cybercriminals for different functions\u2014together with getting access to probably promote to ransomware actors.<\/p>\n<p>High printed vulnerabilities as noticed in Sophos MDR \/ IR intrusion incidents<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"110\">CVE<\/td>\n<td width=\"348\">Description<\/td>\n<td width=\"75\">% of<br \/>intrusions<br \/>exploited<\/td>\n<td width=\"80\">Date of<br \/>CVE<br \/>publication*<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2024-1709<\/td>\n<td width=\"358\">ConnectWise ScreenConnect authentication bypass<\/td>\n<td>4.70%<\/td>\n<td>2024-02-21<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2023-4966<\/td>\n<td width=\"358\">Citrix NetScaler ADC and NetScaler Gateway buffer overflow<br \/>vulnerability<\/td>\n<td>2.78%<\/td>\n<td>2023-10-10<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2023-27532<\/td>\n<td width=\"358\">Veeam Backup &amp; Replication Cloud Join unauthenticated<br \/>entry to encrypted credentials saved within the configuration<br \/>database<\/td>\n<td>2.35%<\/td>\n<td>2023-03-10<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2024-3400<\/td>\n<td width=\"358\">Palo Alto Networks PAN-OS command injection vulnerability, permits an unauthenticated attacker to execute instructions with root<br \/>privileges on the firewall<\/td>\n<td>1.28%<\/td>\n<td>2024-04-12<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2024-37085<\/td>\n<td width=\"358\">VMware ESXi comprises an authentication bypass vulnerability<\/td>\n<td>0.85%<\/td>\n<td>2024-06-25<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2024-40711<\/td>\n<td width=\"358\">Veeam deserialization of information vulnerability, permits distant code<br \/>execution<\/td>\n<td>0.85%<\/td>\n<td>2024-09-07<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2023-48788<\/td>\n<td width=\"358\">Fortinet FortiClient EMS SQL injection vulnerability, permits an<br \/>unauthenticated attacker to execute instructions as SYSTEM<\/td>\n<td>0.64%<\/td>\n<td>2023-03-12<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2024-27198<\/td>\n<td width=\"358\">JetBrains TeamCity comprises an authentication bypass vulnerability that enables an attacker to carry out admin actions<\/td>\n<td>0.43%<\/td>\n<td>2024-03-04<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2024-21762<\/td>\n<td width=\"358\">Fortinet FortiOS out-of-bound write vulnerability, permits a distant<br \/>unauthenticated attacker to execute code or instructions through HTTP<br \/>requests<\/td>\n<td>0.43%<\/td>\n<td>2024-02-09<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">CVE-2021-34473<\/td>\n<td width=\"358\">Microsoft Alternate Server comprises an unspecified vulnerability that enables for distant code execution<\/td>\n<td>0.21%<\/td>\n<td>2021-07-14<\/td>\n<\/tr>\n<tr>\n<td width=\"110\">Whole<\/td>\n<td width=\"358\"\/>\n<td>14.53%<\/td>\n<td\/>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>* Vulnerability dates from cvedetails.com<\/p>\n<p><em>Determine 1: High printed vulnerabilities as noticed in Sophos MDR \/ IR intrusion incidents<\/em><\/p>\n<p>In some circumstances, even when patches have been deployed for identified vulnerabilities, gadgets might stay weak as a result of they&#8217;ve already been compromised. For instance, net shells or different strategies of post-exploit entry malware might have been deployed earlier than the vulnerability was patched. In different circumstances, the patching course of might haven&#8217;t been absolutely accomplished. In a single Sophos MDR\u00a0 case, a Citrix Netscaler gateway was used to ascertain preliminary entry by an attacker by exploiting periods that weren&#8217;t reset after the \u201cCitrix Bleed\u201d patch was deployed.<\/p>\n<p>Lots of the intrusions to which Sophos MDR and IR responded concerned different kinds of vulnerabilities not essentially coated by the Frequent Vulnerabilities and Exposures database: default configurations, misconfigurations, weak two-factor authentication (title and password), and different points with internet-facing gadgets that go away them weak to assault, in addition to vulnerabilities that will have been fastened in later updates by distributors however had been by no means assigned CVE identifiers. Others had been probably associated to a lot older vulnerabilities in unpatched or end-of-life\u2019d gadgets that had been left in service.<\/p>\n<p>Community edge gadgets specifically\u2014together with digital non-public community (VPN) home equipment, firewalls with VPN capabilities, and different remote-access home equipment\u2014are a significant contributor to cybercrime incidents. These gadgets collectively account for the most important single supply of preliminary compromise of networks in intrusion incidents tracked by Sophos MDR.<\/p>\n<figure id=\"attachment_960441\" aria-describedby=\"caption-attachment-960441\" style=\"width: 960px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide1.jpeg\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960441 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide1.jpeg\" alt=\"Figure 2: Relative frequency of initial compromise points by cybercriminals against small and medium businesses, based on all incident data. Initial compromise causes here overlap in some cases\" width=\"960\" height=\"540\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide1.jpeg 960w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide1.jpeg?resize=300,169 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide1.jpeg?resize=768,432 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\"\/><\/a><figcaption id=\"caption-attachment-960441\" class=\"wp-caption-text\"><em>Determine 2: Relative frequency of preliminary compromise factors by cybercriminals towards small and medium companies, primarily based on all incident knowledge. Preliminary compromise causes overlap in some circumstances<\/em><\/figcaption><\/figure>\n<figure id=\"attachment_960443\" aria-describedby=\"caption-attachment-960443\" style=\"width: 960px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960443 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide2.png\" alt=\"Figure 3: Relative frequency of initial compromise points specifically observed in \u00a0ransomware and data exfiltration\/extortion attacks by cybercriminals against small and medium businesses, based on Sophos MDR and Incident Response incident data\" width=\"960\" height=\"540\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide2.png 960w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide2.png?resize=300,169 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide2.png?resize=768,432 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\"\/><\/a><figcaption id=\"caption-attachment-960443\" class=\"wp-caption-text\"><em>Determine 3: Relative frequency of preliminary compromise factors particularly noticed in \u00a0ransomware and knowledge exfiltration\/extortion assaults by cybercriminals towards small and midsized companies, primarily based on Sophos MDR and Incident Response incident knowledge<\/em><\/figcaption><\/figure>\n<p>These figures don&#8217;t embody incidents the place ransomware execution or knowledge exfiltration by no means occurred due to blocking of C2 and different post-exploitation instruments.<\/p>\n<p>These statistics spotlight the necessity for even small organizations to deploy MFA for all person accounts, and particularly these with distant entry rights through a VPN or different means. In addition they present the need of auditing gadgets used for distant connection to networks and updating their software program or firmware recurrently\u2014and changing software program and working techniques that not obtain common safety replace assist.<\/p>\n<h2><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600931\"\/>STACs: Packaged playbooks, ways, instruments and procedures<\/h2>\n<p>Relatively than monitoring \u201crisk teams,\u201d Sophos MDR focuses on figuring out particular patterns of \u00a0habits to trace a set of actors throughout a number of incidents. These embody instruments, ways and procedures (TTPs), assist infrastructure, and different traits that mirror using a shared playbook or set of scripted instruments. We refer to those as Safety Menace Exercise Clusters (STACs) and monitor their exercise as campaigns.<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Sidebar-stacs.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-960461 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Sidebar-stacs.png\" alt=\"How Sophos names STACs STACs are assigned numeric identifiers that are generated based on the type of activity, with their first digit representing motivation: 1: State-sponsored 2: Hacktivist 3: Initial access brokers 4: Financially motivated cybercrime 5: Ransomware affiliates 6: Unknown\" width=\"310\" height=\"278\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Sidebar-stacs.png 310w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Sidebar-stacs.png?resize=300,269 300w\" sizes=\"auto, (max-width: 310px) 100vw, 310px\"\/><\/a><\/p>\n<p>STACs symbolize not only a single set of actors, however a shared playbook\u2014ways, instruments, and procedures (TTPs), together with assault scripts and related strategies for focusing on victims. These playbooks might have been packaged to be used by a number of associates of a ransomware group, offered on underground marketplaces, or outright stolen by people shifting from one felony exercise to a different.<\/p>\n<p>For instance, whereas looking for threats leveraging the Veeam vulnerability CVE-2024-40711, Sophos MDR Menace Intelligence recognized a selected risk exercise cluster utilizing it, together with VPN exploitation, and practically equivalent TTPs. The cluster is tracked as STAC5881. On this marketing campaign, the Veeam vulnerability was used to create identically named administrator accounts (named \u201clevel\u201d). Nevertheless, the ransomware deployed in these circumstances different: Akira, Fog, and a brand new ransomware named Frag.<\/p>\n<figure id=\"attachment_960463\" aria-describedby=\"caption-attachment-960463\" style=\"width: 1986px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/frag-ransom.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960463 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/frag-ransom.png\" alt=\"Figure 4: Frag Ransomware note associated with a STAC5881 attack\" width=\"1986\" height=\"796\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/frag-ransom.png 1986w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/frag-ransom.png?resize=300,120 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/frag-ransom.png?resize=768,308 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/frag-ransom.png?resize=1024,410 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/frag-ransom.png?resize=1536,616 1536w\" sizes=\"auto, (max-width: 1986px) 100vw, 1986px\"\/><\/a><figcaption id=\"caption-attachment-960463\" class=\"wp-caption-text\"><em>Determine 4: Frag Ransomware word related to a STAC5881 assault<\/em><\/figcaption><\/figure>\n<p>Frag seems to be <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/04\/17\/junk-gun-ransomware-peashooters-can-still-pack-a-punch\/\">a \u201cjunk gun\u201d ransomware<\/a>\u2014crudely coded, low cost ransomware produced as a substitute for ransomware-as-a-service, and both developed by the cybercriminals themselves or obtained from an underground market at a mean value of $375.<\/p>\n<p>Probably the most lively STAC campaigns tracked by Sophos MDR in 2024 had been ransomware-related in all however one case\u2014and that marketing campaign was the long-running malware-as-a-service platform DanaBot, which is usually a precursor to ransomware assaults.<\/p>\n<p>Most lively safety risk exercise clusters in 2024<\/p>\n<table width=\"549\">\n<tbody>\n<tr>\n<td width=\"106\">STAC4265<\/td>\n<td width=\"443\">DanaBot marketing campaign utilizing Fb social engineering, with hyperlinks to \u201cunclaimed cash\u201d websites that<br \/>redirect to ship malware that makes an attempt to steal browser knowledge and exfiltrate it through the Tor<br \/>anonymizing community<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC4529<\/td>\n<td width=\"443\">Authentication bypass utilizing RCE of ConnectWise Display screen Join previous to 23.9.8<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC4556<\/td>\n<td width=\"443\">Crytox ransomware deployed, uTox messenger software dropped, use of a deployed weak<br \/>kernel driver to disable EDR software program. The attackers within the cluster additionally used respectable \u201ctwin use\u201d<br \/>instruments: Superior Port Scanner for community discovery, and Mimikatz and Lazagne instruments for credential discovery and dumping<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC6451<\/td>\n<td width=\"443\">Mimic ransomware associates, utilizing Cloudflare to masks command and management domains, exploiting<br \/>Microsoft SQL Server for unauthorized entry, and deploying Impacket for backdoor creation with<br \/>widespread credentials. In addition they exhibit proficiency in community evasion by redirecting probing<br \/>domains to respectable websites and exfiltrating knowledge through well-known file switch companies.<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC5881<\/td>\n<td width=\"443\">A cluster leveraging Akira, Fog, and Frag ransomware assaults, exploiting VPNs and CVE-2024-4071 (described above)<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC5464<\/td>\n<td width=\"443\">A ransomware-related cluster linked to Hunters Worldwide, utilizing the identical SFTP exfiltration<br \/>server throughout incidents in addition to NTDS credential dumping and use of community proxying via<br \/>Plink, SystemBC malware, and different instruments<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC5397<\/td>\n<td width=\"443\">A risk actor or set of actors related to Akira and Fog ransomware. Creates backdoor<br \/>accounts with a standard password. The cluster has been noticed deploying \u201ctwin use\u201d respectable instruments:\u00a0 AnyDesk for execution and lateral motion, and Rclone and FileZilla for knowledge exfiltration.<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC4663<\/td>\n<td width=\"443\">A ransomware-related cluster that makes use of customized, obfuscated malware to carry out intrusions. The group usually makes use of CVE-2023-3519 to use Citrix NetScaler home equipment for preliminary entry, and makes use of<br \/>the respectable OpenSSH library for community site visitors tunneling in sufferer environments.<\/td>\n<\/tr>\n<tr>\n<td width=\"106\">STAC5304<\/td>\n<td width=\"443\">A RansomHub ransomware affiliate first recognized in summer time 2024 that has reused exfiltration IP<br \/>addresses throughout a number of incidents, leveraging respectable instruments (Atera Agent distant machine<br \/>administration software program, FileZilla for knowledge exfiltration) and a script named HideAtera.bat for protection<br \/>evasion<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><em>Determine 5: Most lively safety risk exercise clusters in 2024 ordered by variety of incidents<\/em><\/p>\n<h2><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600932\"\/>Developments in cybercrime strategies, ways and practices<\/h2>\n<h3><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600933\"\/>Distant ransomware continues to develop<\/h3>\n<p>Whereas the general variety of incidents in 2024 was barely down\u2014partly due to higher defenses and the disruption of some main ransomware-as-a-service operators\u2014ransomware-related crime shouldn&#8217;t be fading away. If something, the ways of ransomware actors are evolving to be quicker on the assault and extra keen to extort the sufferer over stolen knowledge once they fail to encrypt sufferer\u2019s information. Generally the attackers don\u2019t even hassle making an attempt to encrypt the information.<\/p>\n<p>When attackers do run ransomware, it\u2019s usually finished from exterior of the detection vary of endpoint safety software program\u2014that&#8217;s, from an unmanaged machine both remotely or straight linked to the focused community. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2023\/12\/20\/cryptoguard-an-asymmetric-approach-to-the-ransomware-battle\/\">These \u201cdistant\u201d ransomware assaults<\/a> use community file-sharing connections to entry and encrypt information on different machines, so the ransomware by no means executes on them straight. This may conceal the encryption course of from malware scans, behavioral detection, and different defenses.<\/p>\n<p>Sophos X-Ops present in an examination of telemetry that use of distant ransomware elevated 50 % in 2024 over final yr, and 141 % since 2022.<\/p>\n<figure id=\"attachment_960466\" aria-describedby=\"caption-attachment-960466\" style=\"width: 960px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/ATR-2025-figure-6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960466 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/ATR-2025-figure-6.png\" alt=\"Figure 6: Remote ransomware attacks from 2022 to 2024 by quarter\" width=\"960\" height=\"540\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/ATR-2025-figure-6.png 960w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/ATR-2025-figure-6.png?resize=300,169 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/ATR-2025-figure-6.png?resize=768,432 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\"\/><\/a><figcaption id=\"caption-attachment-960466\" class=\"wp-caption-text\"><em>Determine 6: Distant ransomware assaults from 2022 to 2024 by quarter<\/em><\/figcaption><\/figure>\n<p>\u00a0<\/p>\n<h3><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600934\"\/>Social engineering through Groups vishing<\/h3>\n<p>Within the second half of 2024, and significantly within the fourth quarter, we noticed the adoption of a mixture of technical and social engineering assaults utilized by risk actors to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2025\/01\/21\/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing\/\">goal organizations utilizing Microsoft 365<\/a>\u00a0 (previously Workplace 365). One in every of these assaults was profitable in knowledge exfiltration however did not progress to ransomware execution. A number of others had been blocked throughout makes an attempt to assemble credentials and transfer additional into the focused organizations\u2019 community (and probably, into their software-as-a-service occasion and its knowledge).<\/p>\n<p>These assaults by two completely different risk teams used \u201ce-mail bombing\u201d\u2014the sending of a giant quantity of emails to focused individuals throughout the organizations they attacked\u2014adopted by a faux technical assist name over Microsoft Groups to these individuals, utilizing their very own 365 account to ship Groups messages and make Groups voice and video calls into the focused organizations.<\/p>\n<h3><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600935\"\/>MFA phishing<\/h3>\n<p>Criminals have additionally adjusted their deception strategies for gathering person credentials. MFA has made it harder to transform usernames and passwords into entry. The cybercriminal market has responded with new methods to seize each credentials and multifactor tokens in actual time to beat that impediment.<\/p>\n<p>MFA phishing depends on an \u201cadversary-in-the-middle\u201d strategy, the place the phishing platform acts as a proxy to precise authentication course of for the multifactor-protected service. The platform then passes captured credentials and the session cookie returned from the login to the cybercriminal over a separate channel, which in flip permits them to cross the credentials and token to the goal\u2019s respectable service web site and achieve entry.<\/p>\n<p>An MFA phishing platform known as Dadsec emerged within the fall of 2023, and would later be linked to campaigns in 2024 by a phishing-for-hire platform generally known as Tycoon. However Tycoon was not the one phishing ring utilizing Dadsec-derived instruments. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/12\/19\/phishing-platform-rockstar-2fa-trips-and-flowerstorm-picks-up-the-pieces\/\">Rockstar 2FA and FlowerStorm<\/a> each look like primarily based on up to date variations of the Dadsec platform, utilizing Telegram as a command-and-control channel. Rockstar 2FA was extremely lively in the midst of 2024 and appeared to undergo from technical failures in November, however was shortly supplanted by FlowerStorm.<\/p>\n<p>Intelligence collected from each platforms revealed a big quantity of compromised accounts, but it surely was unclear what number of had really been used for entry by cybercriminals.<\/p>\n<figure id=\"attachment_960471\" aria-describedby=\"caption-attachment-960471\" style=\"width: 2447px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960471 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png\" alt=\"Figure 7: A developer browser view of a FlowerStorm phishing page\" width=\"2447\" height=\"1573\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png 2447w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png?resize=300,193 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png?resize=768,494 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png?resize=1024,658 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png?resize=1536,987 1536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/figure7MFAphish.png?resize=2048,1317 2048w\" sizes=\"auto, (max-width: 2447px) 100vw, 2447px\"\/><\/a><figcaption id=\"caption-attachment-960471\" class=\"wp-caption-text\"><em>Determine 7: A developer browser view of a FlowerStorm phishing web page<\/em><\/figcaption><\/figure>\n<p>\u00a0<\/p>\n<h3><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600936\"\/>Adversarial AI utilization<\/h3>\n<p>Cybercriminals engaged in intrusion-style assaults have made restricted use of synthetic intelligence. Most of using generative AI by cybercriminals has centered on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/02\/02\/cryptocurrency-scams-metastasize-into-new-forms\/\">social engineering duties<\/a>: creating photos, movies and textual content for faux profiles, and to be used in communication with targets to masks language fluency points and id. In addition they use it to make their very own instruments look extra skilled\u2014as RaccoonStealer builders did for a graphic for his or her portal login web page.<\/p>\n<figure id=\"attachment_960473\" aria-describedby=\"caption-attachment-960473\" style=\"width: 1018px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure8ATR-Raccoon_stealer.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960473 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure8ATR-Raccoon_stealer.png\" alt=\"A login screen with a picture of a raccoon with a human body dressed in futuristic gunslinger garb.\" width=\"1018\" height=\"764\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure8ATR-Raccoon_stealer.png 1018w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure8ATR-Raccoon_stealer.png?resize=300,225 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure8ATR-Raccoon_stealer.png?resize=768,576 768w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\"\/><\/a><figcaption id=\"caption-attachment-960473\" class=\"wp-caption-text\"><em>Determine 8: The login display screen for a RaccoonStealer Office365-focused credential theft portal<\/em><\/figcaption><\/figure>\n<figure id=\"attachment_960474\" aria-describedby=\"caption-attachment-960474\" style=\"width: 1646px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-9-ATR-Raccoon-AI-gen.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960474 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-9-ATR-Raccoon-AI-gen.png\" alt=\"A screenshot of the same raccoon from figure 8 from a generative AI website.\" width=\"1646\" height=\"922\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-9-ATR-Raccoon-AI-gen.png 1646w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-9-ATR-Raccoon-AI-gen.png?resize=300,168 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-9-ATR-Raccoon-AI-gen.png?resize=768,430 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-9-ATR-Raccoon-AI-gen.png?resize=1024,574 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-9-ATR-Raccoon-AI-gen.png?resize=1536,860 1536w\" sizes=\"auto, (max-width: 1646px) 100vw, 1646px\"\/><\/a><figcaption id=\"caption-attachment-960474\" class=\"wp-caption-text\"><em>Determine 9: The supply of the picture, on the generative AI web site OpenArt<\/em><\/figcaption><\/figure>\n<p>One space the place there was emergent use of generative AI is in phishing emails. Giant Language Fashions (LLMs) comparable to ChatGPT can be utilized to create grammatically right content material in a format that varies from goal to focus on\u2014defeating content material filters that establish signatures in spam and phishing emails. SophosAI <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/10\/02\/political-manipulation-with-massive-ai-model-driven-misinformation-and-microtargeting\/\">demonstrated that a whole marketing campaign of focused emails may very well be created<\/a> utilizing AI-orchestrated processes primarily based on info gathered from focused people\u2019 social media profiles, utilizing current instruments.<\/p>\n<p>Sophos X-Ops expects use of those capabilities by cybercriminals to develop sooner or later. At present, (primarily based on our analysis into discussions of LLMs on felony boards, together with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2023\/11\/28\/cybercriminals-cant-agree-on-gpts\/\">an preliminary investigation in late 2023<\/a>, adopted by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2025\/01\/28\/update-cybercriminals-still-not-fully-on-board-the-ai-train-yet\/\">an replace in early 2025<\/a>), there stays a substantial quantity of skepticism amongst some risk actor communities. Some are experimenting and utilizing AI for routine duties, however malicious purposes stay largely theoretical\u2014although in our most up-to-date replace we famous {that a} handful of risk actors are starting to include generative AI into spamming companies and related instruments.<\/p>\n<h3><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600937\"\/>Quishing<\/h3>\n<p>Across the similar time that RockStar was peaking, Sophos X-Ops found a \u201cquishing\u201d marketing campaign focusing on Sophos staff (none of whom fell for the lure). Emails with QR codes alleged to offer safe entry to a doc had been embedded in a PDF attachment; the QR code in reality contained a hyperlink to a fraudulent document-sharing web site that was, in reality, an adversary-in-the-middle phishing occasion, with traits similar to Rockstar 2FA and FlowerStorm.<\/p>\n<figure id=\"attachment_960475\" aria-describedby=\"caption-attachment-960475\" style=\"width: 768px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure10-quishing-email.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960475 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure10-quishing-email.png\" alt=\"Figure 10: A phishing email with a QR code targeting Sophos employees\" width=\"768\" height=\"686\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure10-quishing-email.png 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure10-quishing-email.png?resize=300,268 300w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\"\/><\/a><figcaption id=\"caption-attachment-960475\" class=\"wp-caption-text\"><em>Determine 10: A phishing e-mail with a QR code focusing on Sophos staff<\/em><\/figcaption><\/figure>\n<p>\u00a0<\/p>\n<figure id=\"attachment_960476\" aria-describedby=\"caption-attachment-960476\" style=\"width: 784px\" class=\"wp-caption alignnone\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-11-phishing-fake-security-check.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-960476 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-11-phishing-fake-security-check.png\" alt=\"Figure 11: The fake authentication window for the phishing site the QR code directed targets to, with a Cloudflare security check to validate the target\" width=\"784\" height=\"376\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-11-phishing-fake-security-check.png 784w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-11-phishing-fake-security-check.png?resize=300,144 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Figure-11-phishing-fake-security-check.png?resize=768,368 768w\" sizes=\"auto, (max-width: 784px) 100vw, 784px\"\/><\/a><figcaption id=\"caption-attachment-960476\" class=\"wp-caption-text\"><em>Determine 11: The faux authentication window for the phishing web site the QR code directed targets to, with a Cloudflare safety test to validate the goal<\/em><\/figcaption><\/figure>\n<h3><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192065387\"\/><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192065769\"\/><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600938\"\/>Malvertising and search engine optimization poisoning<\/h3>\n<p>Malvertising is using malicious net ads, together with paid listings on search outcomes. It continues to be a popular technique of distributing malware. Lengthy utilized by droppers comparable to ChromeLoader, malvertising has turn into the distribution technique of alternative for information-stealing malware, however Sophos MDR has noticed different malware injection mechanisms leveraging malvertising as properly.<\/p>\n<p>A malvertisment can both hyperlink to a malicious net web page or on to a malicious script that&#8217;s downloaded and launched by the sufferer, ensuing within the set up of malware or different instruments giving the attacker persistence on the sufferer\u2019s laptop. \u00a0For instance, within the second half of 2024, Sophos X-Ops noticed a browser hijacking marketing campaign related to Google search malvertising leveraging key phrases that focused customers looking for a PDF instrument obtain. The ads led to downloads of malicious Microsoft installer (.MSI) information which put in what seemed to be an precise functioning PDF instrument\u2014but additionally created a system process, a startup merchandise, and registry keys to ascertain persistence for malware that hijacks browsers, redirecting targets\u2019 net searches to websites managed by the malware\u2019s operators.<\/p>\n<p>Malvertising has been noticed by Sophos MDR in circumstances related to among the different most lively malware campaigns of 2024: DanaBot, Lumma Stealer, and GootLoader. Different assault vectors had been additionally noticed utilizing malvertising, together with backdoors and distant administration trojans (together with SectopRat), the Cobalt Strike assault instrument set, and abused respectable distant entry software program comparable to AnyDesk.<\/p>\n<h3><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600939\"\/>EDR killers<\/h3>\n<p>Sophos X-Ops has noticed a wide range of malicious software program instruments developed for the felony market over the previous two years known as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/tag\/edr-killer\/\">\u201cEDR killers.\u201d<\/a> These instruments are meant to use kernel drivers to realize privileged entry to the working system and kill focused protected processes\u2014particularly, endpoint safety software program\u2014in order that ransomware or different malware might be deployed unimpeded. More and more, we have now seen the builders of those instruments depend on a group of respectable however weak drivers to energy them, in what are generally known as \u201cdeliver your personal weak driver\u201d (BYOVD) assaults.<\/p>\n<p>Sophos X-Ops noticed a wide range of would-be EDR killers utilized by ransomware actors in 2024. Probably the most continuously seen of those was EDRSandBlast, a instrument utilized by a number of actors. Seen in each MDR and Incident Response circumstances, EDRSandBlast variants had been detected in waves of tried ransomware assaults all year long, together with a dramatic peak across the US Thanksgiving vacation in November.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide18.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-960457 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/04\/Slide16.png\" alt=\"Top 10 EDR killers\" width=\"960\" height=\"540\"\/><\/a><\/p>\n<p><em>Determine 12: High 10 EDR-killer malware detected by Sophos endpoint safety<\/em><\/p>\n<p>Sophos tamper safety, behavioral detection, and particular detections of malicious use of kernel drivers for disabling defenses assist stop these instruments from making ransomware assaults extra damaging. However the fixed evolution of those instruments places much more strain on defenders to detect and cease attackers earlier than they will deploy them.<\/p>\n<h2><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192065882\"\/><a rel=\"nofollow\" target=\"_blank\" name=\"_Toc192600940\"\/>Conclusion<\/h2>\n<p>The risk panorama for small and midsized companies stays extremely dynamic, with criminals always adapting their ways to new defensive measures and exploiting vulnerabilities new and previous alike as alternatives emerge. Responding to this atmosphere is greater than most small organizations can deal with with out exterior assist and is a pressure even on organizations with devoted IT groups.<\/p>\n<p>Lifecyle administration of all techniques, together with Web routers, firewalls, VPN home equipment, and Web-facing purposes and servers, is an important a part of deterring a major proportion of assaults. Units left in service with out patches or after the top of their assist by distributors can act as a beacon for entry brokers and ransomware actors who carry out broad community scans of the Web for weak techniques to assault.<\/p>\n<p>This yr\u2019s knowledge reveals that criminals are more and more attacking the place we aren\u2019t wanting.<\/p>\n<ul>\n<li>Sophos MDR is more and more seeing the exploitation of vulnerabilities and misconfigurations of community edge gadgets, that are used to acquire and disguise felony entry to networks.<\/li>\n<li>If there&#8217;s a danger of their ransomware encryption instrument being detected by your endpoint safety safety, attackers merely use \u201cdistant ransomware\u201d strategies from under-defended property.<\/li>\n<li>If they will discover a technique to elevate their privileges, they carry alongside a weak machine driver with the purpose of blinding your safety instruments from their malicious intent.<\/li>\n<\/ul>\n<p>Whether or not stealing MFA codes, utilizing QR codes to trick customers into visiting malicious logins from their telephones, or convincing customers to ask them in via e-mail bombing and vishing assaults, cybercriminals regularly adapt and evolve to our defenses.<\/p>\n<p>When taken as a complete, the info and tendencies on this report illustrate the necessity to take a defense-in-depth strategy to defending any measurement group. Many of those don\u2019t require a deeper funding in safety, as a lot as a change in mindset to match the evolving risk. Small and midsized organizations can cut back their danger profile with these steps:<\/p>\n<ul>\n<li>Migrate from passwords to passkeys for account credentials. Passkeys are saved digital keys assigned to particular gadgets and might\u2019t be intercepted by adversary-in-the-middle phishing kits.<\/li>\n<li>For accounts that may\u2019t be secured with passkeys, use multifactor authentication, and migrate to passkey safety when potential.<\/li>\n<li>If accounts can&#8217;t be secured by both technique, intently monitor them via an id risk detection and response technique\u2014both internally or with a managed service supplier.<\/li>\n<li>Prioritize patching edge gadgets comparable to firewalls and VPN gadgets, and following via on all required steps for patching (together with machine resets).<\/li>\n<li>Be sure endpoint safety software program is deployed throughout all of your property in order that unmanaged gadgets can\u2019t be leveraged by attackers.<\/li>\n<li>Enlist exterior assist to audit and monitor your exterior assault surfaces recurrently to make sure you don\u2019t have exploitable entry factors for attackers scanning for targets.<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<h4>Acknowledgements<\/h4>\n<p>Sophos X-Ops thanks Anna Szalay, Colin Cowie and Morgan Demboski of Sophos MDR Menace Intelligence and Chester Wisniewski, Director, International Area CISO for his or her assist within the manufacturing of this report.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Small companies are a main goal for cybercrime, as we highlighted in our final annual report. Lots of the felony threats we coated in that report remained a significant menace in 2024, together with ransomware\u2013which stays a main existential cyber risk to small and midsized organizations. Ransomware circumstances accounted for 70 % of Sophos Incident [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1754,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1574,1474,121,120,1714],"class_list":["post-1752","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybercrime","tag-main","tag-news","tag-sophos","tag-street"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1752"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1752\/revisions"}],"predecessor-version":[{"id":1753,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1752\/revisions\/1753"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/1754"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:23:48 UTC -->