Connect with us

E-Business

Cyber Attackers Getting More Undetected in Target Networks – Sophos Report

Published

on

Senior-Security-Advisor-at-Sophos-John-Shier
John-Shier, Senior-Security-Advisor-at-Sophos
Kindly share this post

New report released by Sophos has revealed that Cyber attackers are not only becoming sophisticated now, they are even getting more time undetected in target networks.

John-Shier, Senior-Security-Advisor-at-Sophos

Sophos, a global leader in next-generation cybersecurity, which released the “Active Adversary Playbook 2021,” detailing attacker behaviors and the tools, techniques and procedures (TTPs) that  Sophos’ frontline threat hunters and incident responders saw in the wild in 2020.

The TTP detection data also covers early 2021. The findings show that the median attacker dwell time before detection was 11 days – or 264 hours – with the longest undetected intrusion lasting 15 months.

Ransomware featured in 81% of incidents and 69% of attacks involved the use of the remote desktop protocol (RDP) for lateral movement inside the network.

The playbook is based on Sophos telemetry as well as 81 incident investigations and insight from the Sophos Managed Threat Response (MTR) team of threat hunters and analysts and the Sophos Rapid Response team of incident responders.

The aim is to help security teams understand what adversaries do during attacks and how to spot and defend against malicious activity on their network.

Advertisement

Key findings in the playbook include:

  • The median attacker dwell time before detection was 11 days – To put this in context, 11 days potentially provide attackers with 264 hours for malicious activity, such as lateral movement, reconnaissance, credential dumping, data exfiltration, and more.

Considering that some of these activities can take just minutes or a few hours to implement – often taking place at night or outside standard working hours – 11 days offers attackers plenty of time to cause damage in an organization’s network.

It is also worth noting that ransomware attacks tend to have a shorter dwell time than “stealth” attacks, because they are all about destruction

  • 90% of attacks seen involved the use of the Remote Desktop Protocol (RDP) – and in 69% of all cases, attackers used RDP for internal lateral movement – Security measures for RDP, such a VPNs and multi-factor authentication tend to focus on protecting external access.

However, these don’t work if the attacker is already inside the network. The use of RDP for internal lateral movement is increasingly common in active, hands-on-keyboard attacks such as those involving ransomware

  • Interesting correlations emerge among the top five tools found in victim networks. For instance, when PowerShell is used in an attack, Cobalt Strike is seen in 58% of cases, PsExec in 49%, Mimikatz in 33%, and GMER in 19%.

Cobalt Strike and PsExec are used together in 27% of attacks, while Mimikatz and PsExec occur together in 31% of attacks. Lastly, the combination of Cobalt Strike, PowerShell and PsExec occurs in 12% of all attacks.

Such correlations are important because their detection can serve as an early warning of an impending attack or confirm the presence of an active attack

  • Ransomware was involved in 81% of the attacks Sophos investigated. The release of ransomware is often the point at which an attack becomes visible to an IT security team. It is, therefore, not surprising that the vast majoirty of the incidents Sophos responded to involved ransomware.

Other attack types Sophos investigated included exfiltration only, cryptominers, banking trojans, wipers, droppers, pen test/attack tools, and more

Sophos

“The threat landscape is becoming more crowded and complex, with attacks launched by adversaries with a wide range of skills and resources, from script kiddies to nation-state backed threat groups. This can make life challenging for defenders,” said the Senior Security Advisor at Sophos, John Shier. “Over the last year, our incident responders helped to neutralize attacks launched by more than 37 attack groups, using more than 400 different tools between them. Many of these tools are also used by IT administrators and security professionals for their everyday tasks and spotting the difference between benign and malicious activity isn’t always easy.

“With adversaries spending a median of 11 days in the network, implementing their attack while blending in with routine IT activity, it is critical that defenders understand the warning signs to look out for and investigate. One of the biggest red flags, for instance, is when a legitimate tool or activity is detected in an unexpected place. Most of all, defenders should remember that technology can do a great deal but, in today’s threat landscape, may not be enough by itself. Human experience and the ability to respond are a vital part of any security solution.”

Other topics covered in the playbook include the tactics and techniques most likely to signpost an active threat and warrant closer investigation, the earliest signs of attack, the most widely seen stagers, threat types and malicious artefacts, the most prevalent adversary groups seen, and more.

Advertisement

Cyber attacks

sophos

To learn more about attacker behaviors, tactics, techniques and procedures (TTPs) read the Sophos Active Adversary Playbook 2021 on Sophos News.

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has directed all Data Controllers and Data Processors of Major Importance (DCPMIs), yet to register with the commission to do so immediately.

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

This followed a Federal High Court judgment affirming NDPC statutory powers to designate and register such entities.

DCPMIs are entities operating in Nigeria that handle sensitive personal data or large volumes of information, requiring mandatory registration with the NDPC under the Nigeria Data Protection Act (NDPA).

In a statement issued on Tuesday by Babatunde Bamigboye, head of Legal, Enforcement and Regulations at the NDPC,  described the judgment as a major milestone for data accountability and regulatory oversight in Nigeria.

The commission said the ruling arose from a suit filed by Emmanuel Harunna against the NDPC in Emmanuel Harunna v. NDPC (FHC/L/CS/1116/2024), in which the applicant sought a declaration that Point of Sale agents were not Data Controllers or Processors of Major Importance under the Nigeria Data Protection Act and requested a perpetual injunction restraining the commission from registering them.

Advertisement

According to the statement, Justice F.N. Ogazi examined the commission’s Guidance Notice on Registration alongside Sections 5(d), 6(c), 44, 45 and 65 of the Nigeria Data Protection Act before concluding that the commission acted within its statutory powers in designating entities under the Major Data Processing – Ordinary High Level category as Data Controllers and Processors of Major Importance.

Quoting the judgment, the statement read, “The Nigeria Data Protection Act was enacted to promote accountability, transparency and responsible data governance. Registration enables the Respondent to identify entities engaged in significant data processing activities, monitor compliance.”

It added that the court held that, “Far from undermining the constitutional right to privacy, the registration framework is one of the statutory mechanisms designed to safeguard that very right by subjecting data controllers and data processors to effective regulatory oversight.”

The statement further quoted the court as saying, “Looking at the recitals of the Guidance Notice, there is every indication that the Guidance Notice is also aimed at protecting the privacy and security of data subjects, thus bringing the registration requirement of the Guidance Notice within the protective shield of Section 45 of the 1999 Constitution.”

According to the commission, the court also held that, “Remarkably, Section 63 of the Data Protection Act provides that the provisions of the Act shall prevail over any other law inconsistent with its provisions on matters relating to the processing of personal data.”

Advertisement

Reacting to the judgment, the commission described the decision as a significant boost to Nigeria’s data protection regime.

“The Commission appreciates the ground-breaking efforts of the court towards the advancement of the jurisprudence relating to data accountability in Nigeria, as eloquently demonstrated in this case,” the statement read.

Following the ruling, Vincent Olatunji, national commissioner and chief executive officer, had directed every Data Controller and Processor of Major Importance that had yet to comply with the registration requirement to register without delay.

The commission warned that entities failing to comply with the registration requirement could face legal consequences.

“Failure to register creates serious legal liabilities under the law, while compliance with registration requirements builds public trust and safeguards the fundamental rights and freedoms of data subjects in Nigeria,” the statement added.

Advertisement

 

Kindly share this post
Continue Reading

E-Business

UNN to Partner Firm on AI, Smart Mobility Innovation Centre

Published

on

Kindly share this post

The University of Nigeria (UNN) is set to partner with The Roxettes Group to establish a research and innovation centre focused on artificial intelligence (AI), smart and green mobility, and digital technologies, in a move aimed at strengthening research, entrepreneurship and technology-driven industrial development.

Chairman of The Roxettes Group, Arc. Dr. Kaycee Orji-Kelechi, announced the proposed partnership while delivering his acceptance speech after receiving an Honorary Doctor of Business Administration (Honoris Causa) during the university’s convocation ceremony.

The proposed facility, to be known as the Dr. Kaycee Orji Centre for Artificial Intelligence, Smart/Green Mobility and Digital Innovation, is expected to provide a platform for research, innovation and collaboration between academia and industry, with a focus on developing commercially viable solutions to local and continental challenges.

Orji-Kelechi said the initiative was conceived as a long-term investment in human capital and technological advancement rather than simply another physical infrastructure project.

He said the vision was to position the University of Nigeria among Africa’s leading institutions in artificial intelligence, smart mobility and digital innovation through research, entrepreneurship and technology development.

Advertisement

According to him, the centre will house five specialised laboratories covering artificial intelligence and machine learning, smart and green mobility, robotics and the Internet of Things (IoT), digital finance and financial technology, as well as cloud computing and advanced data centre technologies.

He also announced plans for the proposed Kaycee Orji Founders Innovation Challenge, an annual programme intended to identify, mentor and support innovative ideas from students, researchers and academic staff with the potential to become scalable businesses.

“Every student of this University should know that a great idea conceived in a classroom should have a pathway to becoming a patent, a startup, a global enterprise, and a solution that transforms society,” he said.

Orji-Kelechi disclosed that preliminary conceptual work on the project had commenced, with architectural and engineering designs being prepared by K.KH Contractors Ltd., a subsidiary of The Roxettes Group.

He added that discussions with the university would begin on identifying a suitable site for the project, while a comprehensive proposal containing architectural drawings, engineering designs and an implementation framework would be submitted after completion of the design phase.

Advertisement

Reflecting on his career, Orji-Kelechi said Africa must move beyond consuming innovation to creating it through investment in manufacturing, technology and entrepreneurship.

“We have pursued one simple vision: that Nigeria and Africa must move from consumption to production; from importing innovation to creating it; and from waiting for opportunities to building them,” he said.

He urged graduating students to see their education as a foundation for solving societal challenges through innovation, leadership and enterprise, adding that he remained committed to promoting industrial development, youth empowerment and sustainable economic growth.

The proposed collaboration forms part of broader efforts to strengthen university-industry partnerships, which are increasingly seen as critical to improving research commercialisation, innovation capacity and technology-led economic development in Nigeria.

Advertisement

Kindly share this post
Continue Reading

E-Business

NPC Opens 131 Births, Deaths Registration Centres in Anambra

Published

on

Kindly share this post

National Population Commission (NPC) has announced commencement of full digital registration of births and deaths through the VitalReg platform, which became operational nationwide on July 1, 2026.

NPC Opens 131 Births, Deaths Registration Centres in Anambra

Chidi Ezeoke, federal commissioner representing Anambra, disclosed this in Awka during a press conference to announce commencement of full digital birth and death registration under the Electronic Civil Registration and Vital Statistics (E-CRVS) system and the marking of World Population Day commemorated every July 11.

He revealed that a total of 131 registration centres had been opened in the 21 local government headquarters and several communities in the state, adding that more centres would be opened later.

Ezeoke described the initiative as a major milestone in Nigeria’s Civil Registration and Vital Statistics (CRVS) system, to ensure every birth and death in the country was captured through a digitally enabled registration platform.

“It builds on the launch of the E-CRVS system and the inauguration of the National Coordination Committee on Civil Registration and Vital Statistics by President Bola Tinubu on Nov. 8, 2023.

Advertisement

“A total of 4,011 functional registration centres has been established across the 774 LGAs of the federation and the commission iswas working to expand the number to about 8,000.

“In Anambra, 131 registration centres have been opened in the 21 local government headquarters and several communities. More centres had been proposed for the state,” he said.

According to the Commissioner, the VitalReg platform would provide faster registration services, 24-hour online access, digital certificate issuance where applicable, reduced paperwork and waiting time, improved data validation and a more secure national CRVS database.

While noting that the platform would serve as a foundational database to support other national data systems and strengthen interoperability across Nigeria’s digital identity ecosystem, Ezeoke urged Nigerians and other stakeholders to support the initiative by ensuring prompt registration of all births and deaths.

Speaking on the 2026 World Population Day themed, “Realising the Hopes and Aspirations of Young People – Today and for the Future”, the Commissioner called for greater investment in education, healthcare, skills development, decent employment opportunities and youth participation in governance for sustainable national development.

Advertisement

Earlier, Mr Obiakonwa Okagwu, state director, NPC, said the occasion served as a reminder of great opportunities provided to harness young people’s capabilities, which he said would shape the future of the country when adequately harnessed.

He called on residents to take registration of births and deaths as national responsibility, just as he urged the media to take the message on civil registration to all parts of the State.

Kindly share this post
Continue Reading

Trending