Ransomware is being deployed within one day of initial access in more than 50 percent of cases, says the latest Secureworks State of the Threat Report. In just 12 months the median dwell time has fallen from 4.5 days to less than one day. In 10% of cases, ransomware was even deployed within five hours of initial access.
The driver for the reduction in median dwell time is likely due to the cybercriminals’ desire for a lower chance of detection. The cyber security industry has become much more adept at detecting activity that is a precursor to ransomware. As a result, threat actors are focusing on simpler and quicker to implement operations, rather than big, multi-site enterprise-wide encryption events that are significantly more complex. But the risk from those attacks is still high.
Don Smith, VP Threat Intelligence, Secureworks Counter Threat Unit.
The State of the Threat report examines the cyber security landscape from June 2022 to July 2023. Key findings include:
- The three largest initial access vectors (IAV) observed in ransomware engagements where customers engaged Secureworks incident responders were: scan-and-exploit (32%), stolen credentials (32%), and commodity malware via phishing emails (14%).
- Exploitation of known vulnerabilities from 2022 and earlier continued and accounted for more than half of the most exploited vulnerabilities during the report period.
- The highest number of monthly victims ever was posted to leak sites in May 2023 with 600 victims, three times as many as in May 2022.






