VORANT. Threat Intelligence Sign in Get the full feed

Experts weigh cybercrime's national security threat

low threat financial-servicesenergygovernment-nationalhealthcare

An expert panel discusses how cybercrime, ransomware, and identity fraud increasingly intersect with national security and state-sponsored activity.

This Atlantic Council 5x5 piece brings together five cybersecurity and law enforcement experts to discuss the intersection of cybercrime and national security. Panelists highlight that ransomware attacks against critical infrastructure (citing Colonial Pipeline, Kaseya, and Conti's attack on Costa Rica) have shifted cybercrime from a purely economic issue to a national security concern. Experts note that financially motivated cybercriminals and state-sponsored actors often share TTPs and infrastructure, with criminal networks sometimes serving as proxies providing plausible deniability for government-linked operations.

The discussion covers emerging trends including the access-broker-to-ransomware pipeline (with an average 71-day gap between initial access sales and ransomware deployment), credential-stealing malware like RedLine, Vidar, and Raccoon fueling roughly half of ransomware attacks via compromised credentials, synthetic identity fraud, SIM swapping to bypass MFA, and business email compromise (BEC) schemes that generate far greater financial losses than ransomware ($2.4 billion vs $49.2 million in 2021 per IC3 data). The piece is a policy/trend discussion rather than a technical threat report, referencing SolarWinds as a supply chain attack example and discussing international cooperation frameworks like the Budapest Convention and competing Russian-proposed UN cybercrime treaty.

Overall, this is an informational policy piece with no specific active threats, IOCs, or named campaigns—focused on strategic recommendations for public-private cooperation, international law enforcement collaboration, and resource allocation to counter transnational cybercrime networks.

Mentioned in this report

Malware ContiRaccoonRedLineVidar

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-cybercrime-and-national-security

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free