Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CrowdStrike Intelligence began tracking 33 additional adversaries during 2022, bringing its tracked total to more than 200, according to the company’s 2023 Global Threat Report. That figure means CrowdStrike added them to its tracking—not that all 33 first emerged in 2022. The company publicly named several examples, but its release does not provide a complete roster of all 33.

What CrowdStrike’s count means

The 33 figure is CrowdStrike Intelligence’s count of adversaries newly tracked during calendar year 2022, as reported in 2023. It describes a change in the company’s tracking coverage, not a count of groups proven to have begun operating that year. CrowdStrike said the additions took its tracked total above 200.

CrowdStrike also said more than 20 of the additions were “SPIDERS,” its naming convention for eCrime adversaries. “Newly tracked” and “SPIDER” are CrowdStrike’s terms and classifications; they should not be treated as independent proof of an actor’s identity or activity.

Which newly tracked adversaries did CrowdStrike name?

The company’s February 28, 2023 announcement gives selected examples rather than a complete list. These are the names and descriptions it specifically highlights:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • SCATTERED SPIDER and SLIPPY SPIDER: CrowdStrike described these as prolific additions associated with high-profile attacks on telecommunications, business process outsourcing (BPO), and technology companies.
  • GOSSAMER BEAR: CrowdStrike characterized this as a Russia-nexus credential-phishing actor. It said the actor’s operations were active during the first year of the Russia-Ukraine conflict and reported targeting of government research labs, military suppliers, logistics companies, and nongovernmental organizations.
  • DEADEYE HAWK: CrowdStrike called this its first Syria-nexus adversary and said it had previously tracked the actor as DEADEYE JACKAL.

These examples do not account for all 33. CrowdStrike’s accessible announcement does not name every addition, so a complete name-by-name answer cannot be established from that release.

What else did CrowdStrike report about 2022 activity?

The same report placed the new tracking count in a broader account of threats observed by CrowdStrike. The figures below are the company’s own measurements and definitions, not universal rates for all cyber incidents or security vendors.

Measure CrowdStrike’s reported finding
Malware-free detected attacks 71% in 2022, compared with 62% in 2021
Interactive intrusions Increased 50% in 2022
Cloud exploitation Grew 95% in 2022
Adversaries conducting data-theft and extortion campaigns Increased 20% during 2022
Average eCrime breakout time 84 minutes in 2022, down from 98 minutes in 2021
Targeting by China-nexus adversaries and actors using consistent tactics, techniques, and procedures (TTPs) Nearly all of the 39 industry sectors and 20 geographic regions tracked by CrowdStrike Intelligence

CrowdStrike described a landscape that included malware-free and interactive intrusions, cloud exploitation, data theft and extortion, and rapid eCrime movement. The figures reflect the company’s observations and tracking scope. They should not be read as estimates of the share or speed of attacks everywhere.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret the actor descriptions

Terms such as “Russia-nexus” and “Syria-nexus” communicate CrowdStrike’s assessment of an adversary’s relationship or alignment; they are not, by themselves, a definitive public attribution of every operation to a government. The report’s examples also show why a single list of names is not enough to compare groups: CrowdStrike describes different targets and activity, including credential phishing by GOSSAMER BEAR and attacks on telecommunications, BPO, and technology companies associated with SCATTERED SPIDER and SLIPPY SPIDER.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For context on the company’s framing, CrowdStrike head of intelligence Adam Meyers said in the February 28, 2023 release: “The past 12 months brought a unique combination of threats to the forefront of security. Splintered eCrime groups re-emerged with greater sophistication, relentless threat actors sidestepped patched or mitigated vulnerabilities, and the feared threats of the Russia-Ukraine conflict masked more sinister and successful traction by a growing number of China-nexus adversaries.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.