您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [KELA]:2026年网络犯罪状况:新兴威胁与预测 - 发现报告

2026年网络犯罪状况:新兴威胁与预测

信息技术 2026-06-15 - KELA 健康🧧
报告封面

Cybercrime Table of contents Millions Infected: Infostealers by the Numbers2.86 Billion: Mapping the 2025 Compromised Credentials EpidemicMacOS Infostealers Explode: Four Years of Growth Culminate in 2025KELA’s 2026 Predictions: Growth, Automation, and ResilienceCountermeasures1315182223 KELA’s 2025 Ransomware InsightsActor HighlightNotable Ransom AttacksKELA’s 2026 Predictions: Encryption, Extortion, and the Race for Fast MonetizationCountermeasures2630364041 Top CVEs Discussed by Threat ActorsUnderground Activity Surrounding the Top 5 CVEsKELA’s Conclusion 2026 PredictionsCountermeasures44455152 Notable Hacktivist Attacks and Campaigns (2025)Statistics of Hacktivism in 2025KELA’s 2026 Predictions: Growth of HacktivismCountermeasures55575960 Major Events Triggered State-Backed Cyber CampaignsKELA’s 2025 Insights: Spotlight on Hybrid Warfare and Cyber-Industrial ExposureKELA’s 2026 Predictions: Geopolitical Conflict and AI as Key Drivers of APT ActivityCountermeasures62656667 Trends in Supply Chain AttacksMajor Case Studies Observed in 2025KELA’s 2026 Predictions of The Supply Chain Threat LandscapeCountermeasures70717576 The Autonomous Shift: How AI Fully Integrated into the 2025 Kill Chain78 Vibe Hacking the Evolution of AI AbuseThe Threat of AI-Driven MalwareAttacks Against AI CompaniesKELA’s 2026 Predictions: AI-Driven and Agentic Attack ModelsCybercrime Chatter on LLM ExploitationCountermeasures798081838485 Executive Summary The zero-trust crisis: How AI-driven attacks and supply chainexploitation redefined risk in 2025 In 2025, the ‘Trust by Default’ security model became the ultimate corporate liability. Threat actorshave moved past your perimeter and into your identity infrastructure, weaponizing everythingfrom your SaaS integrations to your own AI systems. With a45%surge in ransomware and a7,000%explosion in macOS infections, the2026 mandate for leadership is clear. Secure the Identity, or Lose the Enterprise.” Davidi Carmiel, CEO, KELA Group Kela Perspective: The Top Strategic Threats of 2025 Identity is the New Perimeter: The Infostealer Epidemic Traditional defenses are failing because attackers aren’t breaking in, they’re logging in. The ScaleKELA tracked2.86 billioncompromised credentials this year alone. The Mac MythmacOS is no longer a safe haven; infections skyrocketed fromunder 1,000 toover 70,000as ‘Atomic Stealer’ (AMOS)professionalized Mac-targeted attacks. The RiskBusiness Cloud and Authentication services account forover 30%of all targeted data, making every employee a potential gatewayfor total network compromise. Industrial-Scale Extortion: The Ransomware Surge Ransomware has evolved into a high-velocity business model, prioritizing US manufacturing andprofessional services. The Stats7,549 victimswere claimed in 2025—a massive45% increasefrom 2024. US Victim BiasOver 53%of all global ransomware victims wereUS-basedorganizations. The DamageThe Jaguar Land Rover (JLR) breach alone cost the automotiveeconomy$2.5 billion, proving that a single vendor compromisecan trigger a national GDP contraction. ‘Vibe Hacking’ & The Autonomous Threat: The Malicious AI Frontier Attackers have moved from using AI as a tool to making it a core part of the attack kill chain. Vibe HackingAdversaries are nowcontextually manipulating your AI’sautonomous logic to bypass safety protocols without triggeringtechnical alarms. Agentic AttacksState-sponsored actors (specifically from China) are now usingautonomous AI agents to run80-90%of a campaign withminimal human oversight. VelocityAI-driven malware is shrinking the window between initial accessand total exfiltration fromdays to minutes. The Fragile Ecosystem: Supply Chain & Nth-Party Sabotage The primary target is no longer your network; it is the trusted service provider you already pay for. The ShiftAttackers have moved to "Upstream Exploitation," where a singlevulnerability in a shared SaaS platform—like the recent SalesforceAura data theft—provides a skeleton key to thousands ofdownstream corporate environments. The Case StudyGroups like ShinyHunters are now weaponizing misconfigurationsin Experience Cloud instances to exfiltrate sensitive data fromthousands of organizations globally by targeting the provider'sshared infrastructure. The RiskEven with robust internal security, a vulnerability in your Nth-partysupply chain creates a systemic failure of the digital trust model,turning your most essential business tools into a direct gatewayfor total data compromise. 2026 Predictions:The Road Ahead for Executives The Rise of the Agentic Insider: 2026 will see the first major public breach caused not by a human, but by an autonomous AIAgent. As companies rush to deploy Agentic AI for productivity, these systems will becomeNon-Human Identities with over-privileged access. Attackers will use Prompt Injection tohijack these agents, turning your own automation into an insider threat that can drainaccounts or leak data witho