您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [北极狼(Arctic Wolf)]:2026网络安全威胁报告 - 发现报告

2026网络安全威胁报告

报告封面

Foreword3Key Takeaways42026 Predictions Preview5Data Sourcing & Methodology6The Threat Landscape in 20257Ransomware Ecosystem Shifts11Initial Access Trends14Edge Device Abuse & Infrastructure Exploitation16Trusted Platform & Supply Chain Abuse18Ransomware Impact Analysis19Ransomware Economics & Extortion Trends212026 Predictions2412 Recommendations for 202626Conclusion29How Arctic Wolf Can Help30T A B L EO FC O N T E N T S Foreword actors continued to adapt — shifting towarddata-only extortion, abusing trusted platformsand developer ecosystems, and operating with The past year has reinforced a lesson defendersoften learn the hard way: Attackers don’t neednew tricks when the old ones still work. Whether it’s ransomware crews abusing remoteaccess, social engineers weaponizing trust andtiming, or affiliates pivoting to pure data theft whenencryption loses its edge, the pattern is the same. That’s why this report matters. Its insights comenot from hypothetical trends, but from the mostdisruptive incidents our teams were called in tocontain and investigate — revealing how attackers From the vantage point of Arctic Wolf®Labs, wherewe analyze thousands of real-world intrusions, If there’s one takeaway, it’s this:Defensibilitybeats novelty.Organizations that invested in thefundamentals — identity, segmentation, logging,disciplined remote access, and monitoring of •Attackers are compressing the kill chain throughautomation•They are bypassing controls by logging in, not This report is designed to give you two advantages:better decisions and more time. You don’t needperfect security — you need defenses built for how Most modern intrusions, in other words, arenot technical surprises. They are architectural Think Red. Act Blue. This year, organizations that hardened remoteaccess, segmented their environments, andinvested in strong identity controls consistently Vice President of Labs,Threat Research & Intelligence We understand that your time is in high demand, so for those readers in a rush, here’s a summary of this Three common cyber incident types account for 92% of Arctic WolfIR cases Organizations typically reserve third-party IR engagements for only the most disruptive and damagingincidents, so it’s telling that our cases are dominated by ransomware (44% of cases), business emailcompromise (BEC) (26%), and data incidents (22%). While the relative contribution of ransomwareand BEC to our caseload remained essentially consistent, data incidents surged 20% from our prior Improved defenses are stopping ransomware before detonation Pre-ransomware incidents accounted for 5% of Arctic Wolf IR cases (in these incidents, an intrusionwas detected and contained prior to detonation of what was later confirmed to be an attemptedransomware attack). In particular, behavioral analytics and endpoint telemetry allowed defenders Professional incident response pays off Engaging with a ransomware actor is best left to the experts, as they generally have a great deal moreexperience with handling these events than any in-house personnel. In 77% of ransomware IRcases handled by Arctic Wolf, the impacted organization elected not to pay a ransom. In the 23% ofransomware IR cases in which the victim made the business decision to pay a ransom, Arctic Wolf’s IR Blurred lines and shifting allegiances define the modern ransomwarelandscape Ransomware groups continue to operate like profit-driven business enterprises, offering structuredaffiliate programs, tiered revenue models, and operational support to attract and retain a broader poolof cybercriminals. These developments have contributed to a more competitive and interconnected Attackers are abusing common remote access tools to gain initial access Nearly two-thirds of our non-BEC IR cases (65%) are attributable to abuse of external remote accessproducts and services including remote desktop protocol (RDP), virtual private networks (VPN), andremote monitoring and management (RMM) tools. This dramatic surge from 24% just two years ago To stop BEC fraud, invest in phishing defenses A whopping 85% of BEC fraud incidents were traced to email phishing, an 11% jump from last year’sreport. As AI empowers threat actors to build efficient workflows and craft more convincing lures,robust phishing defenses — including security awareness training — are necessary for combating BEC. Prioritized patching remains effective, but don’t forget to rotatecredentials Each of the 10 CVEs we encountered in the majority of non-BEC IR cases date to 2024 or earlier,indicating that patching even just the most-exploited vulnerabilities can significantly improvean organization’s security posture. However, organizations must rotate credentials following any 180+ Threat actors are targeting key roles by abusing trusted channels A number of campaigns (notably GPUGate, Oyster/Broomstick, and the compromise of 180+ npmpackages) specifically targeted IT personnel and developers to gain initial acc