Hiding in Plain Sight: Abuse Of Trusted Applications Grows By 51%

Sophos, a global leader in innovating and delivering cybersecurity as a service, today released “The Bite from Inside: The Sophos Active Adversary Report,” an in-depth look at the changing behaviors and attack techniques that adversaries used in the first half of 2024.
The data, derived from nearly 200 incident response [IR] cases from across both the Sophos X-Ops IR team and Sophos X-Ops Managed Detection and Response [MDR] team, found that attackers are leveraging trusted applications and tools on Windows systems, commonly called “living off the land” binaries, to conduct discovery on systems and maintain persistence. When compared to 2023, Sophos saw a 51% increase in abusing “Living off the Land” binaries or LOLbins; since 2021, it’s increased by 83%.
Among the 187 unique Microsoft LOLbins detected in the first half of the year, the most frequently abused trusted application was remote desktop protocol [RDP]. Of the nearly 200 IR cases analyzed, attackers abused RDP in 89% of them. This dominance continues a trend first observed in the 2023 Active Adversary report in which RDP abuse was prevalent in 90% of all IR cases investigated.
“Living-off-the-land not only offers stealth to an attacker’s activities but also provides a tacit endorsement of their activities. While abusing some legitimate tools might raise a few defenders’ eyebrows, and hopefully some alerts, abusing a Microsoft binary often has the opposite effect. Many of these abused Microsoft tools are integral to Windows and have legitimate uses, but it’s up to system administrators to understand how they are used in their environments and what constitutes abuse. Without nuanced and contextual awareness of the environment, including continuous vigilance to new and developing events within the network, today’s stretched IT teams risk missing key threat activity that often leads to ransomware,” says John Shier, field CTO, Sophos.
In addition, the report found that, despite the government disruption of LockBit’s main leak website and infrastructure in February, LockBit was the most frequently encountered ransomware group, accounting for approximately 21% of infections in the first half of 2024.
Other key findings from the latest Active Adversary Report:
Root Cause of Attacks: Continuing a trend first noted in the Active Adversary Report for Tech Leaders, compromised credentials are still the number one root cause of attacks, accounting for the root cause in 39% of cases. This is, however, a decline from the 56% noted in 2023
Network Breaches Dominate for MDR: When examining solely the cases from the Sophos MDR team, network breaches were the dominant incident the team encountered
Dwell Times Are Shorter for MDR Teams: For cases from the Sophos IR team, dwell time [the time from when an attack starts to when it’s detected] has remained approximately eight days. However, with MDR, the median dwell time is just one day for all types of incidents and only three days for ransomware attacks
The Most Frequently Compromised Active Directory Servers Are Nearing End of Life: Attackers most frequently compromised the 2019, 2016, and 2012 server versions of Active Directory [AD]. All three of these versions are now out of mainstream Microsoft support—one step before they become end-of-life [EOL] and impossible to patch without paid support from Microsoft. In addition, a full 21% of the AD server versions compromised were already EOL.
Read Also: Sophos Unveils China-Based Threats In Pacific Cyber Defense
About Soko Directory Team
Soko Directory is a Financial and Markets digital portal that tracks brands, listed firms on the NSE, SMEs and trend setters in the markets eco-system.Find us on Facebook: facebook.com/SokoDirectory and on Twitter: twitter.com/SokoDirectory
- January 2026 (220)
- February 2026 (248)
- March 2026 (287)
- April 2026 (208)
- May 2026 (191)
- June 2026 (238)
- July 2026 (279)
- August 2026 (140)
- January 2025 (119)
- February 2025 (191)
- March 2025 (212)
- April 2025 (193)
- May 2025 (161)
- June 2025 (157)
- July 2025 (227)
- August 2025 (211)
- September 2025 (267)
- October 2025 (297)
- November 2025 (230)
- December 2025 (220)
- January 2024 (238)
- February 2024 (227)
- March 2024 (190)
- April 2024 (133)
- May 2024 (157)
- June 2024 (145)
- July 2024 (136)
- August 2024 (154)
- September 2024 (212)
- October 2024 (255)
- November 2024 (196)
- December 2024 (143)
- January 2023 (182)
- February 2023 (203)
- March 2023 (322)
- April 2023 (297)
- May 2023 (267)
- June 2023 (214)
- July 2023 (212)
- August 2023 (257)
- September 2023 (237)
- October 2023 (264)
- November 2023 (286)
- December 2023 (177)
- January 2022 (293)
- February 2022 (329)
- March 2022 (358)
- April 2022 (292)
- May 2022 (271)
- June 2022 (232)
- July 2022 (278)
- August 2022 (253)
- September 2022 (246)
- October 2022 (196)
- November 2022 (232)
- December 2022 (167)
- January 2021 (182)
- February 2021 (227)
- March 2021 (325)
- April 2021 (259)
- May 2021 (285)
- June 2021 (272)
- July 2021 (277)
- August 2021 (232)
- September 2021 (271)
- October 2021 (303)
- November 2021 (364)
- December 2021 (249)
- January 2020 (272)
- February 2020 (310)
- March 2020 (390)
- April 2020 (321)
- May 2020 (335)
- June 2020 (327)
- July 2020 (333)
- August 2020 (276)
- September 2020 (214)
- October 2020 (233)
- November 2020 (242)
- December 2020 (187)
- January 2019 (251)
- February 2019 (215)
- March 2019 (283)
- April 2019 (254)
- May 2019 (269)
- June 2019 (249)
- July 2019 (335)
- August 2019 (292)
- September 2019 (306)
- October 2019 (313)
- November 2019 (362)
- December 2019 (318)
- January 2018 (291)
- February 2018 (213)
- March 2018 (275)
- April 2018 (223)
- May 2018 (235)
- June 2018 (176)
- July 2018 (256)
- August 2018 (247)
- September 2018 (255)
- October 2018 (282)
- November 2018 (282)
- December 2018 (184)
- January 2017 (183)
- February 2017 (194)
- March 2017 (207)
- April 2017 (104)
- May 2017 (169)
- June 2017 (205)
- July 2017 (189)
- August 2017 (195)
- September 2017 (186)
- October 2017 (235)
- November 2017 (253)
- December 2017 (266)
- January 2016 (164)
- February 2016 (165)
- March 2016 (189)
- April 2016 (143)
- May 2016 (245)
- June 2016 (182)
- July 2016 (271)
- August 2016 (247)
- September 2016 (233)
- October 2016 (191)
- November 2016 (243)
- December 2016 (153)
- January 2015 (1)
- February 2015 (4)
- March 2015 (164)
- April 2015 (107)
- May 2015 (116)
- June 2015 (119)
- July 2015 (145)
- August 2015 (157)
- September 2015 (186)
- October 2015 (169)
- November 2015 (173)
- December 2015 (205)
- March 2014 (2)
- March 2013 (10)
- June 2013 (1)
- March 2012 (7)
- April 2012 (15)
- May 2012 (1)
- July 2012 (1)
- August 2012 (4)
- October 2012 (2)
- November 2012 (2)
- December 2012 (1)
