partner-enabled hunt forward operations that identify malicious cyber activity abroad and
constrain adversaries’ freedom of maneuver.
In October 2023, the White House-led Counter-Ransomware Initiative (CRI) convened its third
summit to coordinate international efforts to defeat ransomware activity around the world. This
year, the CRI focused its efforts on developing capabilities to disrupt ransomware attacks and
infrastructure, improve information sharing, and fight back against the structural underpinnings
of the ransomware ecosystem. To achieve these objectives, the CRI announced new
commitments to establish intelligence sharing and operational collaboration platforms, build the
cyber capacity of CRI members, and jointly issue the CRI’s first-ever policy statement that
member governments should not pay ransoms.
When the United States coordinates with allies and partners, takedowns and other disruption
activities are more effective, impose more severe consequences on adversaries, and provide more
impactful support to victims. These activities can also be paired with diplomatic actions,
economic sanctions, and other tools tailored to impact malicious cyber actors. Allies and
partners are also making significant contributions to the production of joint CSAs that attribute
malicious cyber activity and provide important details on adversary TTPs. To enable additional
information sharing and operational collaboration with foreign partners, the FBI has expanded its
overseas presence of cyber assistant legal attaches by nearly 40%.
The private sector also plays an important role in enhancing awareness of cyber threats across
critical infrastructure through cyber threat intelligence sharing. Private sector organizations
often have visibility into certain aspects of malicious activity that the Federal Government does
not. The willingness of these organizations to share information directly with law enforcement
or through NSA’s CCC or CISA’s JCDC strengthens the Federal Government’s ability to assess
and understand threats, devise mitigations, and facilitate victim notifications.
The Federal Government is working to establish rules to prevent malicious actors from abusing
U.S.-based cloud, AI, and other third-party services. In January 2024, consistent with EO 14110
on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence and EO 13984
on Taking Additional Steps to Address the National Emergency with Respect to Significant
Malicious Cyber-Enabled Activities, the Department of Commerce proposed a rule requiring
U.S. Infrastructure-as-a-Service providers to prevent the abuse of their products and services by
foreign persons to enable malicious cyber activity.
The Federal Government has increased the speed, scale, and impact of disruption campaigns to
counter cybercriminal activity and dissuade adversaries from using cyber capabilities to achieve
their malicious goals. The following campaigns illustrate the range of recent U.S. actions to
disrupt malicious cyber activity affecting victims around the world:
•
January 2023: DOJ announced a disruption campaign against the HIVE ransomware
group, which had claimed over 1,500 victims in over 80 countries. The FBI and
international partners penetrated HIVE networks, took its decryption keys, and made
those keys available to victims. CISA, the FBI, and HHS disseminated HIVE indicators
of compromise (IOCs) and TTPs through a joint CSA.
2024 REPORT
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE
15