TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»State of Malware: Attacks on Business Grow as Threats Become More Sophisticated
    Cyber Security

    State of Malware: Attacks on Business Grow as Threats Become More Sophisticated

    January 24, 2019Updated:January 24, 2019No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The 2019 State of Malware report from Malwarebytes is packed with statistics on when, where and what malware was detected through 2018. One trend and one fact stand out: consumer detections are decreasing while business infections are increasing; and there is a marked difference between western world threats and eastern threats.

    The report compares the state of malware in 2018 to that of 2017 using intelligence compiled from researchers and data collected by honeypots, virtual sandboxes, and the company’s business and consumer product telemetry. 

    Over the last year, “Businesses became a greater target than consumers by a significant amount,” Adam Kujawa (director of Malwarebytes Labs) told SecurityWeek. “Based on our detections, the business side jumped up almost 80% from the previous year, while the consumer side dropped 3%.” The reason for this is that criminals will always go where the money is — and a perfect example can be seen in the evolution of ransomware through 2018.

    Initial ransomware attacks were based on spray and pray spam campaigns and malvertising exploits. During 2018, however, this shotgun approach, according to the report, “was replaced with brute force, as witnessed in the most successful SamSam campaigns of the year.” The reason was that consumers became less likely to pay a ransom (through better understanding the risk, improved defenses, and the availability of decryptors from NoMoreRansom); while business was more likely to pay a higher ransom because of their need to maintain operations. “The chances of getting any significant return from spray and pray campaigns, or for a consumer to pay a ransom, is probably lower now than it has ever been,” added Kujawa.

    Business-targeting ransomware attacks highlight another malware evolution of 2018: multi-mode attacks. This in turn is a response to attackers going where the money is. The big development in early 2018 was the rise of cryptomining malware, following the late 2017 boom in cryptocurrency values. In the latter half of 2018, these attacks tailed off. They haven’t disappeared, but are more likely now an option rather than a main driver.

    But as this threat declined, a new one emerged: Emotet and Trickbot trojans. Kujawa doesn’t see a causal link between the two events, but nor does he think they are entirely coincidental. “I don’t think we would see this level of trojan infections if cryptomining was still worth it,” he said.

    Emotet and Trickbot also highlight the switch in direction from consumer to business attacks. “Emotet and Trickbot have grown on the business side and declined on the consumer side,” he added, “to the extent that it is now one of the few major malware families that has more corporate than consumer real-estate.”

    One of the reasons for this is the adoption of the Eternal exploits, and the inclusion of lateral movement in these new malware families.

    “Emotet and Trickbot — basically banking trojans — are now also information stealers able to move laterally through a network. “Where the new exploits really thrive,” explained Kujawa, “is on corporate networks. Now, when you get something like Emotet getting a foothold on an endpoint — still being delivered by the same phishing email with a malicious Office document — it is able to drop Trickbot and other malware and start spreading through the network. Emotet was Malwarebytes’ number one trojan detection through the year, so it’s very popular.”

    “Our Trojan detections were topped by the Emotet family, which can move laterally throughout corporate networks using exploits and credential brute forcing,” notes the report. “This same functionality is mirrored in other information stealing malware, such as TrickBot.”

    Once an attacker gets a firm foothold in a network, he can choose which option is likely to make the most money: stealing data, or dropping a cryptominer or ransomware. Recent Ryuk ransomware attacks — such as those against the Onslow Water authority and the Tribune Publishing group started from Emotet infections.

    Geographically, the areas experiencing the highest number of attacks in 2018 were the U.S.A, Indonesia and the UK. The U.S. is simply the most attractive and affluent target. Kujawa is not surprised that the UK also figures highly. While the population is not so high as other countries, the concentration of major international commercial companies within the UK make it an attractive target for cybercriminals targeting businesses.

    Indonesia is included because of the large number of backdoor Vools attacks. This highlights one of the other major findings in Malwarebytes’ analysis: east and west suffer different threats. Emotet and Trickbot are western world problems — they do not occur so much in the east. Vools is an eastern problem, with little evidence in the west. Vools uses the same EternalBlue propagation method employed by WannaCry; and Shodan shows there are many severs still unpatched. Like elsewhere in the world, Vools largely delivered cryptominers in the first half of the year, but has become less virulent in the latter half.

    Nevertheless, given the large number of servers still unpatched against the Eternal exploits in the east, Kujawa suspects there are many dormant and potential infections. “Since the infection vector is still available,” he commented, “it is interesting to see what they do next with all of the systems they have infected.”

    A second regional difference is that exploit kits have diminished in the west but are prevalent in the east. “We don’t see a lot of EK activity in the west these days,” he told SecurityWeek, “because there aren’t so many exploits — there were a few new ones released earlier in the year, for Flash and IE, but for the most part EKs aren’t really a western problem anymore.” A failure to expeditiously patch systems in the east means that users remain as vulnerable to EKs as they are to the Eternal family.

    “Our main threat in the west today,” added Kujawa, “is getting fooled by the social engineering phishing mails that deliver trojans such as Emotet.”

    Santa Clara, Calif-based Malwarebytes — founded in 2008 by Bruce Harrison, Doug Swanson, Marcin Kleczynski and Marcus Chung — raised $50 million in a Series B funding round from Fidelity Management and Research Company in January 2016; bringing the total venture funding raised by the firm to $80 million. 

    view counter

    Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

    Previous Columns by Kevin Townsend:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.