Technical reports
The reports explore various topical issues relating to incidents and developments in information and communication technologies (ICT) and will address the corresponding set of problems and put them in a major context.

Cyber Resilience Assessment (CyRA): How resilient are Swiss communes and companies to cyberattacks?
The National Cyber Security Centre (NCSC) has developed a standardised tool for assessing cyber resilience and tested it under real-world conditions for the first time in the canton of Aargau. The results show that basic protective IT measures have been put in place, but many organisations still lack a holistic, process-oriented resilience strategy.

Anti-Phishing Report 2024
Last year, the NCSC received a total of 975,309 reports of phishing. Based on these reports, 20,872 were identified as actual phishing websites. This represents an increase of 108% compared to the previous year, in which a total of 10,007 phishing websites were identified. The latest anti-phishing report explains how the NCSC handles phishing reports, the figures that characterised 2024, and the types of phishing that were common last year. The report also contains recommendations on how to protect yourself against phishing.

Report: Phone fraud in the cyber domain
Gli utenti telefonici si trovano sempre più spesso confrontati con telefonate fraudolente. Il fenomeno della truffa telefonica, tuttavia, non è nuovo. Da sempre esistono criminali che cercano di manipolare le persone con telefonate nell’intento di appropriarsi del loro denaro. Nelle pagine che seguono, il rapporto spiega il modus operandi della truffa, la prevalenza del fenomeno nel conte-sto degli sviluppi tecnologici e gli elementi utili a identificare tali tentativi di frode. Vengono inoltre illustrate le misure messe in atto dagli operatori di telecomunicazioni e dal legislatore.

Brief technical analysis of the "Gorilla" botnet
In September 2024, the NCSC recorded an increase in DDoS attacks carried out by a botnet called "Gorilla". This is a "DDoS-as-a-service" service offered on Telegram, which can be rented for some fee. As an operator of a critical infrastructure in Switzerland was affected by such DDoS attacks, the NCSC has published the technical findings in a short report.

Brief technical analysis of the "Poseidon Stealer" malware
At the end of June 2024, cybercriminals spread the malware "Poseidon Stealer" in German-speaking Switzerland by email, using AGOV as a lure with the aim of infecting computers with the macOS operating system. The NCSC has now produced and published a brief technical analysis of the malware.

Summit on Peace in Ukraine: first NCSC report on Cyber Situation Network
Even before the Summit on Peace in Ukraine got under way, cyberattacks on the conference and network infrastructure in Switzerland were expected. A number of cyberattacks were then confirmed, but they were all detected early and quickly averted. In order to jointly counter the expected cyberattacks, Switzerland set up a Cyber Situation Network coordinated by the National Cyber Security Centre (NCSC). Today, the NCSC published an initial review of the work of the Cyber Situation Network.

Data analysis report of the hacker attack on Xplain
The National Cyber Security Centre (NCSC) took over responsibility for incident management in the Federal Administration in the wake of the hacker attack on Xplain, a major provider of IT services to national and cantonal authorities. Part of its activities involved analysing the data that the perpetrators published on the darknet. The NCSC released a report today explaining its analysis and providing information on what type of data was affected and the challenges as-sociated with analysing the data. The report does not evaluate the content of the data, nor does it analyse why certain data was leaked. The latter question will be clarified as part of the ongoing administrative investigation.

Anti-Phishing Report 2023
Last year, the NCSC received and analysed around 554,000 phishing reports. Of those, 10,007 websites were ultimately identified as phishing websites and the website operators informed. In the Anti-Phishing Report published today, the NCSC provides insight into that analysis and information on the most frequently misused brand names and domains. It also sets out the most important measures and recommendations to protect against phishing.

Detailed analysis report on the DDoS attacks «NoName057(16)»
The report analyses the distributed denial of service (DDoS) attacks on Swiss organisations and authorities in the first two weeks of June 2023 (weeks 23 and 24). The type of application-layer DDoS attack deployed is explained in detail.

General forms of threats, perpetrators and tools
Cyber threats pose an increasingly serious danger to companies, public authorities and individuals. Attackers use ever more sophisticated methods to gain unauthorised access to networks and data.

Technical Report about the Malware used in the Cyberespionage against RUAG
The Reporting and Analysis Center for Information Assurance (MELANI) was tasked by the Federal Council to produce a report about the technical findings concerning the RUAG Incident. It is targeted towards network security professionals and is meant to support those responsible for security identifying risks within their own networks, as well as implementing additional security measures. The use and implementation of the information and recommendation, lays with each’s individual responsibility.