杏吧传媒

Search
searchclose icon

A Brief Evolution of Hacker Tradecraft

Glitch effectGlitch effectGlitch effect
Glitch banner

Sometimes change happens so gradually it鈥檚 easy to miss. That鈥檚 often the case in cybersecurity.

We see statements like 鈥渢he security landscape is evolving鈥 or 鈥渉ackers are getting smarter鈥 that just get brushed off as the latest marketing lingo, but they actually hold some serious weight if you stop to think about it.听

At 杏吧传媒, our days are dedicated to studying and learning from hacker tradecraft. We want to understand exactly how attackers operate so we can pick up on their tricks and tactics and know how to defend against them. We know that in order to prepare for the future, we can鈥檛 dismiss the past. Read on for a brief history of how hackers are evolving their tradecraft and how it can help us better prepare for tomorrow鈥檚 threats.

Cybersecurity Supply and Demand: Then vs. Now

Looking back, the world鈥檚 approach to cybersecurity has been mostly reactionary. We settled into 鈥渘ew attack, new security product鈥 mode, where the attacks and threats themselves were driving the creation of protective products.

In the 1980s, for example, virus attacks on stand-alone PCs affected all businesses鈥攚hich drove the development of commercial antivirus software to protect against them. As we moved along to the mid 1990s, the internet opened the gates for the broad and rapid spread of malware鈥攚hich then introduced us to the firewall.听

But as time went on, cyberattacks could not be effectively stopped by firewalls or antivirus products alone. Hackers learned to leverage vulnerabilities鈥攎asking their attacks in anything from resumes to picture files, behind which awaited sophisticated code that was ready to launch. All they needed was a user to open an email attachment or plug in a USB and the attack was silently unleashed.听

In response, the IT industry boomed in the early 2000s鈥攂ringing with it fresh products and services to meet the needs of a hungry market. We saw new technologies emerge like signature-based detection, automation and artificial intelligence. But all the while, hackers were watching and learning how to beat these tools.

The Modern Hacker

What began as inquisitive teenagers hacking for the sheer fun and challenge of it all has now turned into a more organized and formidable force. Hacker motives changed from recognition and notoriety to being in it for the money鈥攖urning cybercrime into a multi-billion dollar industry.

Today鈥檚 hackers have moved beyond the Hollywood stereotype of the lone hacker in a basement. Instead, they鈥檙e operating in highly organized groups (very similar to the professional environments we鈥檙e all familiar with). And not only has this dynamic introduced a more economically-focused adversary, it has also provided a wider distribution of hacker skills and know-how.

There鈥檚 more knowledge and resources at a hacker鈥檚 fingertips than ever before. Look no further than the dark web. It鈥檚 got malicious gadgets and gizmos a-plenty, even keyloggers and wipers galore. You want a hacker for hire? There are many.听

The point is: modern hackers know there is money to be made in cybercrime and they鈥檙e using the dark web to source tools or skills that they might not have鈥攁nd this has completely changed the way bad actors go about their attacks.

Tactics, Techniques and Procedures Hackers Use Today

Most attackers will go for the low-hanging fruit and use the path of least resistance. Phishing is a popular choice for that reason鈥攜ou can use malicious links and fake documents to lure users into clicking or opening something.听

And while phishing is an effective way to gain initial access, if the user shuts down their computer, the attacker has just lost their access. Can you imagine if any time that happened, the hacker would just re-phish the user? That would be the world鈥檚 most efficient hacker!

Getting in is no longer the hard part, it鈥檚 staying in. That鈥檚 where persistence comes in handy for hackers.

How Do Hackers Use Persistence In Their Attacks?

Attackers are turning away from methods that are easy to detect and shut down. Instead, more and more bad actors are opting for a 鈥渓ow-and-slow鈥 approach, establishing persistence to lay low and maintain long-term access to their targets.

Although slower, this persistent strategy enables more covert operations. Here鈥檚 a look at how hackers are using persistence in their attacks.


At the end of the day, all cyberattacks are not created equal鈥攏or are all cybercriminals. Some are more persistent than others, so it鈥檚 becoming increasingly important to understand our adversaries and better equip ourselves for the fight.

Want to learn more?

Share

Sign Up for 杏吧传媒 Updates

Get insider access to 杏吧传媒 tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy
Oops! Something went wrong while submitting the form.
杏吧传媒 at work