As 2024 closed out, the final quarter brought a sharp focus on targeted extortion, mobile identity abuse, and increasingly invisible compromises across the software supply chain.
While big headlines focused on mega-breaches and ransom demands, the more interesting signals were quieter: unauthorized access via phone number migration, persistent payloads disguised as legitimate updates, and third-party dependencies opening backdoors.
Here are the key incidents that defined Q4 2024.
1.LastPass supply chain breach reopens trust debates
Date reported: October 9, 2024
New forensic analysis revealed that threat actors who breached LastPass earlier in 2023 maintained access via embedded dev toolchains—even post-migration to new infrastructure.
The attackers used replicated build environments and token theft to mimic developer access.
This triggered industry-wide discussions about securing CI/CD secrets and developer MFA enforcement.
2.Large-scale SIM swap attacks tied to internal telco access
Wave detected: November 2024
Multiple reports across the US, UK, and Gulf states revealed that SIM swap fraud was executed using privileged access from inside mobile carriers.
Unlike previous social engineering attacks, these swaps were authorized at Tier 2 support levels, bypassing typical user verification.
Impacted sectors included fintech apps, wallets, and secure messaging platforms.
In several cases, attackers intercepted OTPs, reset cloud access, and stole funds within 20 minutes.
3.RansomHouse resurgence: quiet, calculated, and selective
Observed: October–December 2024
The RansomHouse group, previously dormant, launched a small but effective campaign targeting legal firms and healthcare organizations across Europe and Canada.
They didn’t encrypt systems—instead, they exfiltrated sensitive internal documents and used low-key extortion demands under NDAs.
Most victims paid quietly. The group’s restraint helped them evade press attention—but not detection by proactive SOCs.
4.MacStealer targets Apple M-series chip users
Discovered: November 2024
Researchers revealed MacStealer, a credential-harvesting tool built specifically to evade Apple M1 and M2 chip security features.
It focused on exfiltrating passwords, iCloud tokens, and keychain entries via malicious apps disguised as productivity tools.
First discovered in malware loaded from non-App Store browser extensions, it was later found in pirated software marketplaces and GitHub forks.
5.Critical TLS downgrade attack (Raccoon 2.0) patched across major libraries
Date patched: December 2024
A new variant of the Raccoon attack allowed man-in-the-middle actors to force insecure TLS cipher suite negotiations, bypassing forward secrecy.
Patches were rushed out for OpenSSL, NSS, and LibreSSL.
While the attack requires close network positioning, its stealth and applicability to internal services triggered urgent patching across enterprise VPNs and proxies.
Noteworthy trends
- Extortion ≠ encryption. Attackers are choosing silence over spectacle, especially when targeting high-value institutions.
- Mobile identity is fragile. SIM swaps have entered the “insider threat” phase, bypassing consumer defenses.
- Macs are no longer safe by default. The myth of macOS immunity continues to fade.
- TLS weaknesses are back. Libraries once considered “done” are again under active research and exploit pressure.
Final word
Q4 2024 confirmed what many suspected: the attackers are evolving faster than the response playbooks.
They don’t need to breach your firewalls if they can breach your phone number.
They don’t need to drop ransomware if they can quietly leak your client files.
They don’t need new zero-days if your developers are still using 2020-era build tools.
