Mandiant M-Trends 2024: Inside the annual cybersecurity report
Mandiant has released their annual M-Trends report, available to download now.

Cybersecurity firm Mandiant, now owned by Google, has released the M-Trends 2024 report. It contains the top cybersecurity trends, threats, and analyses Mandiant has detected over the past year. Relevant attacker and defender metrics, tactics, techniques, procedures (TTPs), and guidance on best practices are valuable contributions to its customers and the cybersecurity field.

The M-Trends 2024 report covers investigations conducted between January 1, 2023 to December 31, 2023. Mandiant documented an increased number of advanced techniques attackers use to evade detection for longer durations.

Mandiant Attack Surface Management helps customers mitigate external cyber threats by continuously monitoring IT infrastructure for vulnerabilities, misconfigurations, and exposures. (source: Mandiant / YouTube)

Unprecedented Zero-day usage, Living off the Land tactics

In the calendar year 2023, Mandiant reported an unprecedented number of zero-days used by well-financed attackers and espionage groups. More than 90, or a 50% growth in zero-day usage, was reported for 2023.

Well-financed or nation-state attackers increasingly leverage “living off the land” attack vectors, which utilize legitimate, pre-installed tools or software within an environment. Indeed, the advanced persistent threat group Volt Typhoon used this method to penetrate U.S. military base IT infrastructure in Guam and other strategic locations in the Asia-Pacific.

The financial sector remained the top targeted industry vertical, representing 17.3%, business and professional services second with 13.3%, and high-tech third at 12.4%.

Mandiant has released an annual M-Trends report to aid cybersecurity professionals and customers with insights from the cyber frontlines for years.

If you want to download the M-Trends 2024 report or past years, you can grab them all from Mandiant’s website.


Discover more from Cybersecurity Careers Blog

Subscribe to get the latest posts sent to your email.