/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

CrowdStrike: in 2024, 79% of cyber intrusions were malware-free, up from 40% in 2019, voice phishing overtook phishing as the main first access method, and more

Duncan Riley / SiliconANGLE :

SiliconANGLE Duncan Riley

Context & Ripple Effects

CrowdStrike’s findings extend a trajectory already visible in its earlier coverage: cloud intrusions surged while attackers increasingly worked through legitimate access rather than exploiting networks directly. IBM likewise reported a growing preference for legitimate credentials as an entry route, making malware-free activity a material detection problem rather than a marginal tactic.

The reported rise of voice phishing as an initial-access route shifts attention from email-centric controls to attacks that target people and identity workflows.

First-order effects

  • Security teams must prioritize identity, authentication, endpoint behavior and help-desk verification alongside malware detection, since a large share of intrusions may not produce a conventional malicious-file signal.
  • Organizations face a more immediate social-engineering exposure as voice phishing becomes a leading entry method, increasing the importance of procedures for credential resets, payment changes and access requests.

Second-order effects

  • Endpoint-security vendors are pushed to demonstrate detection of credential abuse and hands-on-keyboard activity, not just file-based prevention; identity-security and phishing-defense tools gain strategic relevance.
  • Attackers that obtain valid access can move quickly inside an environment, a concern reinforced by CrowdStrike’s later finding that breakout times had fallen to 29 minutes. This raises the value of rapid containment and tightly scoped privileges.

Third-order effects

  • If malware-free intrusion continues to dominate, cyber-defense buying is likely to shift toward integrated identity, endpoint and response telemetry rather than treating antivirus-style malware detection as the primary control.
  • The pattern points to security operations becoming more behavior- and identity-led, though the pace of that shift will depend on whether organizations can reduce credential theft and voice-based manipulation at the access layer.

The trend: Cyber intrusions are moving from malware delivery toward identity compromise and interactive abuse of legitimate access, compressing defenders’ time to detect and contain attackers.