Full Report
Two of Huntress’ heavy hitters John Hammond and Dray Agha lace up their gloves to join the good fight and add their predictions for 2023.
Analysis Summary
# Industry News: Huntress Forecasts the Evolution of "Professionalized" Cybercrime
## Summary
Huntress security researchers John Hammond and Dray Agha have released their strategic predictions for the threat landscape, emphasizing a shift toward high-quality social engineering and the professionalization of cybercrime operations. The analysis moves beyond purely technical defenses, arguing that fostering a "security culture" is the most critical business lever for reducing risk and adversary ROI in the coming year.
## Key Details
- **Date:** January 3, 2023
- **Companies Involved:** Huntress
- **Category:** Market Analysis and Predictions
## The Story
In this strategic outlook, Huntress identifies five "Trusted Knowledge Observations" (TKOs) derived from their 2022 threat intelligence data. The overarching theme is the convergence of cybercrime tactics with legitimate business practices.
Threat actors are increasingly leveraging economic and political volatility—such as layoff announcements and election cycles—to craft hyper-relevant phishing campaigns. Furthermore, the "Dark Web" is undergoing a marketing transformation where criminal groups now utilize FAQs, case studies, and professionalized branding to sell malware-as-a-service. Huntress notes a brazen trend where attackers even share tools with security researchers to gain "educational" exposure, treating their malicious software like a legitimate product launch.
## Business Impact
### For the Companies Involved
- **Huntress:** Positions itself as a thought leader in the SMB and MSP space by bridging the gap between deep technical tradecraft and boardroom-level cultural strategy.
### For Competitors
- **Managed Detection and Response (MDR) Providers:** There is increasing pressure to integrate "Security Awareness" messaging into technical product suites, as detection alone is no longer sufficient against sophisticated social engineering.
### For Customers
- **End Users:** Employees face higher risks from "catchy" social engineering (e.g., "Layoffs 2023" documents). Organizations must pivot from viewing users as "weak links" to viewing them as a trained defensive perimeter.
### For the Market
- **Professionalization of Crime:** The market must account for "Cybercrime-as-a-Service" models that mirror SaaS businesses, lowering the barrier to entry for low-skill attackers and increasing the volume of high-quality attacks.
## Technical Implications
- **Phishing Vectors:** Continued reliance on email as the primary delivery mechanism for malware and credential theft.
- **Dark Web Sophistication:** Evolution of specialized software and network configurations used by threat actors to maintain anonymity while scaling their "customer" support for buyers of stolen data.
## Strategic Analysis
- **Market Positioning:** Huntress is shifting the conversation from "tools" to "culture," targeting the human element of the kill chain where automated tools often fail.
- **Competitive Advantage:** By identifying the "business-like" nature of dark web groups, Huntress provides IT leaders with a framework to treat cybersecurity as a cost-imposition game against an organized competitor.
- **Challenges:** Overcoming "training fatigue" among employees who view security awareness as a box-ticking exercise rather than a vital defensive skill.
## Industry Reactions
- **Analyst Opinion:** Analysts note that the focus on "Security Culture" is a response to the diminishing returns of pure-play antivirus in the face of identity-based attacks.
- **Expert Commentary:** John Hammond highlights that ignoring user training essentially creates "intentional insider threats" by leaving staff unprepared for modern lures.
## Future Outlook
- **Predictions:** Expect a rise in "Economic Lure" phishing as global markets remain volatile.
- **Watch For:** Increased activity on "BreachForums" and similar platforms, where threat actors are engaging in high-drama marketing and community building to attract affiliates.
## For Security Professionals
Practitioners should prioritize **Security Awareness Training (SAT)** not just as a compliance requirement, but as a technical control. The goal for 2023 is to "impose a greater cost on adversaries" by making the environment hostile to their primary entry method: the human user. Focus on reporting mechanisms—ensuring users know *who* to tell when they see something suspicious is as important as the detection itself.