Recorded Future
2024 Malicious Infrastructure Report
Pages
71
Time to read
84 mins
Publication
Language
English
Pages
71
Time to read
84 mins
Publication
Language
English
The 2024 Malicious Infrastructure Report is a comprehensive analysis that documents the evolving landscape of cyber threats, focusing on malware families, command-and-control (C2) servers, and the tactics employed by various threat actors. It outlines significant trends observed in 2024, including the rise of malware-as-a-service (MaaS) infostealers, particularly LummaC2, which has become the leading infection vector due to law enforcement pressure on competitors. The report details how Cobalt Strike remains the dominant offensive security tool, accounting for a substantial portion of C2 servers. Additionally, it highlights the geographical distribution of cyber threats, noting that the US and China are the primary hosting locations for malicious infrastructure. The document emphasizes the importance of adapting security measures to counter these threats, recommending enhanced monitoring and detection strategies. Furthermore, it anticipates that existing trends will persist into 2025, driven by continuous innovation among threat actors and the increasing reliance on legitimate services to evade detection.