Back to Blog
Reports12 min readNov 1, 2024

Monthly Threat Landscape Report: October 2024

Breach volume, infostealer families, ransomware activity, and initial access broker pricing observed during October 2024.

B

Bob Adams

Threat Analyst at Revealer

October 2024 Threat Intelligence Summary

October 2024 numbers from the Revealer.US corpus: more breach records, more stealer logs, more combo lists than September. The rest of the report is where those records came from and who was using them.

Key Statistics

Metric October 2024 September 2024 Change
New breach records surfaced 847M 623M +36%
Unique stealer log entries 12.4M 9.8M +27%
New combo lists identified 156 134 +16%
Underground forum posts monitored 45K 41K +10%

Every number above moved in the same direction: more records, more logs, more chatter. If you want to check whether a specific address shows up in the new material, run it through the data breach lookup.

Major Breach Events

Healthcare Sector Under Siege

Healthcare stayed the loudest vertical:

Notable Incidents:

  • Regional hospital chain: 2.3M patient records
  • Health insurance provider: 890K member records
  • Medical laboratory network: 450K records including test results

Pattern Analysis:

  • Primary vector: Compromised VPN credentials
  • Ransomware groups claiming responsibility: BlackCat, LockBit
  • Average time to detection: 23 days

Twenty-three days is the number worth sitting with. That is three weeks of quiet access before anyone noticed.

E-Commerce Breaches

Holiday prep did not go quietly:

  • Three major retailers experienced Magecart-style attacks
  • Estimated 340K payment cards harvested
  • Increase in checkout page skimmers detected

Infostealer Trends

Lumma Stealer Dominance

Lumma led the family mix in October:

Distribution by Family:

  • Lumma: 34%
  • RedLine: 28%
  • Raccoon: 19%
  • Vidar: 12%
  • Other: 7%

Stealer output is where most corporate account takeovers now begin, so it pays to know what has already been dumped. Our stealer logs search covers that material directly.

Notable Lumma Capabilities

What the current Lumma builds actually do:

  • Browser cookie extraction (including Chrome's encrypted cookies)
  • Cryptocurrency wallet targeting (expanded to 40+ wallet types)
  • Session token harvesting for SaaS applications
  • Anti-analysis techniques to evade sandboxes

Session token theft is the part defenders keep underestimating. A stolen token walks straight past MFA because the login already happened.

Distribution Campaigns

Observed vectors this month:

  1. Fake CAPTCHA pages: Users tricked into running PowerShell commands
  2. Cracked software: Adobe, Microsoft Office, gaming tools
  3. YouTube tutorials: Links to "tools" in video descriptions
  4. Discord malware: Compromised game modifications

Credential Intelligence

Exposed Corporate Credentials

Corporate credentials in the October dump:

  • Fortune 500 companies: 12% showed new credential exposure
  • Technology sector most affected (34% of corporate exposures)
  • Average of 2,100 new corporate credentials surfacing daily

Checking a single work address against known breach datasets takes seconds with an email lookup, and it is the cheapest control most teams still skip.

Password Analysis

From October's breach data:

Most Common Passwords:

  1. password123 (still!)
  2. Company name + year
  3. Qwerty variations
  4. Welcome1
  5. Seasonal passwords (Fall2024)

Positive Trends:

  • Slight increase in password manager adoption indicators
  • More unique passwords in newer breaches

Threat Actor Activity

Ransomware Groups

Most Active Groups (by victim count):

  1. LockBit 3.0 - 89 claimed victims
  2. BlackCat/ALPHV - 67 claimed victims
  3. Play - 45 claimed victims
  4. Akira - 38 claimed victims

Initial Access Broker Activity

Increased activity from Initial Access Brokers (IABs) selling:

  • VPN credentials: Average price $2,400
  • RDP access: Average price $1,800
  • Web shell access: Average price $650

Those prices are the honest market value of a reused password on your VPN.

Nation-State Activity

Observed campaigns attributed to:

  • APT groups: Targeting defense contractors, think tanks
  • Focus areas: Intellectual property, policy documents
  • TTPs: Supply chain compromise, watering hole attacks

Geographic Trends

Most Affected Regions (by breach volume)

  1. United States: 42%
  2. European Union: 23%
  3. United Kingdom: 8%
  4. India: 7%
  5. Brazil: 5%

Emerging Targets

Increased targeting observed in:

  • Southeast Asian financial services
  • Middle Eastern energy sector
  • Latin American government entities

Recommendations

Immediate Actions

  1. Review VPN security: Implement MFA, monitor for credential exposure
  2. Employee awareness: Alert staff to ongoing phishing campaigns
  3. E-commerce monitoring: Extra vigilance during holiday preparation
  4. Healthcare sector: Prioritize network segmentation

Strategic Priorities

  1. Implement continuous credential monitoring
  2. Enhance detection for stealer malware
  3. Review third-party access controls
  4. Tabletop exercises for ransomware scenarios

If you are still checking exposures by hand, start from the OSINT tools list. One Revealer.US search (email, username, phone, name, or address) hits 800+ platforms, public records, and known breach datasets. Free tier, paid self-serve from $12.99/mo, custom Enterprise. Revealer is not a consumer reporting agency and must not be used for employment, tenant, or credit decisions.

Looking Ahead: November Predictions

What November is likely to look like, based on this month:

  • Increased holiday-themed phishing: Black Friday, Cyber Monday lures
  • Retail targeting: Point-of-sale and e-commerce focus
  • Tax preparation: Early tax-related phishing (some regions)
  • Year-end ransomware push: Groups seeking to meet quotas

About This Report

Counts in this report come from what Revealer.US actually monitors:

  • 200+ platforms
  • Real-time breach data monitoring
  • Underground forum analysis
  • Stealer log coverage

For detailed indicators of compromise (IOCs) from this month's threats, contact your Revealer.US account representative or reach out to our team.

Get started

Ready to check your exposure?

Create a free account and search live sources and known breach datasets.

Create account