M-Trends 2024 Special Report

Published on: 
May 1, 2024

In this 15th edition, M-Trends provides an inside look at the evolving cyber threat landscape, with data drawn directly from frontline incident response investigations and threat intelligence findings of high-impact attacks and remediations around the globe.

  • The latest incident response metrics including dwell times, detection sources, initial infection vectors, and so much more
  • China-nexus attackers increasingly targeting edge devices and platforms that lack EDR
  • Trending adversary operations and motivations behind zero day attacks
  • The evolution of phishing techniques amidst modern security controls
  • How attackers are leveraging AiTM to compromise multi-factor authentication safeguards
  • The reasons and solutions behind growing cloud and hybrid cloud environment intrusions
  • How AI is effectively used in red and purple team operations to help boost cyber defenses

Read Anton Chavakin's take on the report: https://medium.com/anton-on-security/reading-the-mandiant-m-trends-2024-acb3208add80

Related Content

Research
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

Moving beyond traditional state-centric APT structures, the pro-Iran coalition of jihadist-aligned collectives, nationalist actors, and opportunistic groups coordinates via Telegram to turn low-cost cyber operations into high-impact psychological warfare. While individual actors primarily rely on technically unsophisticated tradecraft like DDoS-for-hire tools, website defacements, and recycled breach data, their strategic strength lies in speed, visibility, and rapid mobilization alongside real-world kinetic events.

Learn More
Research
Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

DTI reveals how Russia, China, and Iran are exploiting weak OT security and internet-facing PLCs to target critical water and wastewater infrastructure. From Volt Typhoon's strategic pre-positioning to Sandworm-adjacent sabotage, discover the primary TTPs, vulnerabilities, and MITRE ATT&CK mappings reshaping modern hybrid warfare.

Learn More
Research
Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations

New research exposes Russian GRU (APT28) cyber operations using router compromise, DNS hijacking, and Signal/WhatsApp phishing for long-term espionage.

Learn More