SOCRadar Report - Brazil
SOCRadar Report - Brazil
SOCRadar Report - Brazil
Technical Details 5
socradar.io
Executive Summary
socradar.io 3
Top Takeaways
socradar.io 4
Technical Details
SOCRadar observed 629 Dark Web forum posts linked to 91 distinct threat
actors during this period. Public Administration emerged as the most
prominently affected industry among the targeted industries, representing
10.65% of the identified cyber threats during this period. Following closely
behind, the Retail Trade and Information Services industries accounted for
9.45% and 7.95% respectively.
socradar.io 5
Distribution of Dark Web Threats by Post Type
Selling 27,19%
Sharing 21,30%
Buying 0,32%
Data/Database 33,64%
Access 13,12%
Website 4,25%
Admin Access 3,88%
RDP Access 2,59%
Sensitive Data 2,22%
Wordpress 1,48%
Network Access 1,48%
Credit Card 1,29%
VPN Access 1,11%
socradar.io 6
SOCRadar's Advanced Dark Web Monitoring provides Brazilian organizations
with critical insights into hidden threats targeting their sectors, including Public
Administration and Retail Trade, which have faced significant risks over the
past year. With real-time tracking of underground chatter and sensitive data
exposure, SOCRadar enables proactive defense against dark web threats.
Activate your free demo today to safeguard your organization’s most valuable
assets.
socradar.io 7
The Alleged Data of Schadek Automotive is Leaked
22 Sep A new alleged data leak for Schadek Automotive was detected in a
2024 hacker forum monitored by SOCRadar. The leaked data includes
sensitive information such as projects, employee details, customer
data, financial information, and manufacturing designs.
socradar.io 8
Ransomware Attacks Targeting Brazilian Entities
Ransomware attacks represent significant threats to
organizations, often resulting in dire consequences such as
extensive data loss and the exposure of sensitive information.
SOCRadar's surveillance has identified 248 instances of
ransomware victim notifications attributable to various
ransomware threat actors and/or groups.
Manufacturing 20,56%
Information Services 12,90%
Professional, Scientific, and Technical Services 6,05%
Health Care and Social Assistance 6,05%
Utilities 4,84%
Construction 4,44%
Public Administration 4,03%
Chemical Manufacturing (Chemical &
Pharmaceutical Manufacturing) 4,03%
Educational Services 4,03%
Automobile Dealers 3,23%
0,00% 5,00% 10,00% 15,00% 20,00% 25,00%
socradar.io 9
Top Ransomware Groups Targeting Brazil
When examining the top ransomware groups targeting Brazil, LockBit 3.0
emerges as the most prolific threat, accounting for 27.42% of the attacks.
Following this, Conti represents 9.27% of the ransomware incidents. ALPHV
Blackcat accounts for 6.85%, while 8base accounts for 6.45%. Lastly, Revil
contributes to 4.84% of the ransomware activity in Brazil.
This analysis highlights the dominant presence of LockBit 3.0, followed by a
diverse range of other ransomware groups.
4,84%
6,45%
LockBit 3.0
Conti
27,42% ALPHV Blackcat
6,85%
8base
Revil
9,27%
socradar.io 10
Recent Ransomware Attacks Targeting Brazilian Entities
The New Ransomware Victim of LockBit 3.0:
05 Feb Tgestiona Logística
2024 On the LockBit 3.0 ransomware group website monitored by
SOCRadar, a new victim was allegedly announced as Tgestiona
Logística. The group has already uploaded some of the company's files
to its website and is threatening to publish the rest if the ransom is not
paid by February 22, 2024, as the payment deadline draws near.
socradar.io 11
Hunters International Ransomware Group
22 Jan Leaked The Data of Alupar Investimento
2024 In the Hunters International ransomware group website monitored by
SOCRadar, new data leaks detected allegedly belong to Alupar
Investimento. The leaked data includes various files, such as bank
details, contracts, and social information, totaling 699.8 GB.
socradar.io 12
Top Threat Actors Targeting Brazilian Organizations
-Ransomware Group-
You can visit our blog post for more detailed Lockbit 3.0 Ransomware
Group information.
socradar.io 13
Conti Ransomware Group
The Conti group was also linked to several high-profile attacks, including
incidents targeting critical infrastructure and healthcare organizations.
Their aggressive tactics and willingness to target essential services have
made them one of the most disruptive ransomware groups in recent years.
You can visit our blog post for more detailed information about the Conti
Ransomware Group.
socradar.io 14
ALPHV Blackcat Ransomware Group
-Ransomware Group-
BlackCat
Ransomware Motivation: Financial Gain
You can visit our blog post for more detailed information about the
ALPHV BlackCat Ransomware Group.
SOCRadar enhances
cybersecurity measures
with its Threat Actor
Intelligence module,
which features advanced
Threat Actor Tracking
capabilities for
organizations that want
to stay ahead of cyber
threats in real-time.
socradar.io 15
Stealer Log Statistics: Top Domains in Brazil
The table below lists the domains that receive the highest traffic from Brazil.
uol.com.br
globo.com
tudocelular.com
gov.br
mercadolivre.com.br
terra.com.br
caixa.gov.br
metropoles.com
acesso.gov.br
cnnbrasil.com.br
socradar.io 16
Stealer Logs- Compromise Data
Victim IP 124
These discoveries emphasize the gravity of data compromises that impact users,
highlighting the urgent need for robust cybersecurity protocols to mitigate such risks
efficiently.
SOCRadar’s Identity & Access Intelligence Module can detect stealers on your
devices and identify their location, facilitating a secure working environment.
Changing passwords without eliminating stealers is insufficient to secure your
organization, as it will only provide new passwords to threat actors.
socradar.io 17
Phishing Threats Targeting Brazil
Phishing is an effective method to initially breach an organization's
infrastructure by deceiving individuals into divulging sensitive credentials on
fraudulent websites.
With SOCRadar’s AI-powered Phishing Domain Detection module, you can swiftly
identify malicious domains and protect your brand from phishing threats. Start
safeguarding your digital presence today with SOCRadar— request a free demo
and see the platform in action.
socradar.io 18
The graph below illustrates the distribution of Page Titles used by threat
actors for phishing attacks. Notably, the data reveals a predominant usage of
the Aliança Administradora de Condomínios page title.
Netflix 0,76%
socradar.io 19
When closely examining the SSL/TLS protocols of domains prepared for
phishing attacks by threat actors, we observe an increasing trend in the
usage of HTTPS compared to the past.
HTTP
46,51%
HTTPS
53,49%
socradar.io 20
DDoS Attack Statistics
Brazil experienced a dynamic DDoS threat landscape marked by considerable
cyber activity in 2024.
• The highest recorded throughput during these incidents was 350.00 Mpps
(peak aggregate throughput in one minute), underscoring the intense rate
at which data packets were sent.
Enhance your DDoS defense with SOCRadar's DoS Resilience Free Tool, a
sophisticated tool designed to assess and fortify your infrastructure's resilience to
DoS attacks.
socradar.io 21
Lessons Learned: Key Insights and
Strategic Recommendations
The dynamic nature of the cyber threat landscape, marked by an increase in Dark
Web activities and ransomware incidents related to Brazil, demands constant
vigilance.
Organizations must keep pace with these changes by adapting their security
strategies. By adopting a proactive approach like SOCRadar’s Extended Threat
Intelligence solution, organizations can gain real-time insights into emerging
threats, positioning them to counteract cyber adversaries proactively.
The persistent ransomware threat underscores the need for defensive, solid, and
responsive strategies. SOCRadar’s Attack Surface Management capabilities are
crucial for businesses to identify potential ransomware threats and to formulate
effective countermeasures.
The ongoing risk of phishing attacks makes continuous employee education and
training imperative. Enhancing their ability to recognize phishing tactics and
detection methods is vital.
socradar.io 22
Robust Defenses Against Stealer Malware
Enhance your DDoS defense with SOCRadar's DoS Resilience Free Tool, a
sophisticated tool designed to assess and fortify your infrastructure's resilience
to DoS attacks. Leveraging state-of-the-art AI and cloud technologies, this
module provides a crucial layer of protection for global organizations.
socradar.io 23
Who is Your Eyes Beyond
?
SOCRadar provides Extended Threat Intelligence (XTI) that
combines: "Cyber Threat Intelligence, Brand Protection, External Trusted by
Attack Surface Management, and Dark Web Radar Services." 21.000+ companies
SOCRadar provides the actionable and timely intelligence context in 150+ countries
you need to manage the risks in the transformation era.
Dark Web Monitoring: SOCRadar's fusion of Protecting Customers’ PII: Scan millions of
its unique Dark Web recon technology with the data points on the surface, deep and Dark
human analyst eye further provides in-depth Web to accurately identify the leakage of your
insights into financially-targeted APT groups customers' Personally Identifiable Information
and the threat landscape. (PII) in compliance with regulations.
Credit Card Monitoring: Enhance your fraud 360-Degree Visibility: Achieve digital
detection mechanisms with automation speed resilience by maintaining internet-facing
by identifying stolen credit card data on digital asset inventory. Significantly accelerate
popular global black markets, carding forums, this process by automated discovery,
social channels, and chatters. mapping, and continuous asset monitoring.