Malware Has Increased By 64%

The most common domains that attackers use to host malware and launch phishing attacks include several subdomains of legitimate sites and content delivery networks. 

These sites include CloudFlare.net which belongs to Amazon, SharePoint and Amazonaws.com, along with a number of legitimate file-sharing websites, according to WatchGuard who have completed a report on these problems. 

The research shows that year-on-year malware volume has increased by 64% and that it is increasingly targeting Europe and APAC

The report highlights that modules from the popular Kali Linux penetration testing tool made the top ten malware list for the first time in Q2 2019.

WatchGuard 2019 Internet Security Report highlights:

  • Zero-day malware accounted for 38% of all malware detections, within a few percentage points of the previous two quarters.
  • Overall    malware detections trended down around 5% this quarter compared to Q1 2019. 
  • Malware is still up 64% compared to Q2 2018.
  • DNSWatch blocked multiple campaigns that used 
  • Content Delivery Networks (CDNs) to host browser-hijacking malware. 
  • In Q2 2019, there was an increased overlap between the most-widespread malware detection affecting individual networks and the most prolific malware by volume, with three threats found in both lists.
  • The EMEA region saw the most malware detections per Firebox, with APAC in a close second and AMER bringing up the rear. This is almost the perfect opposite to the previous quarter.
  • Multiple popular backdoor shell scripts, used by both penetration testers and cyber criminals, showed up in top malware attacks. 
  • 11% of the sextortion (sexual extortion) phishing emails associated with Trojan.Phishing.MH targeted Japan
  • Network attacks more than doubled from Q1 to Q2. This was the largest percent increase we’ve seen since 2017.
  • In Q2 2019, WatchGuard Fireboxes blocked 22,619,836 malware variants (549 per device) across all three anti-malware engines and 2,265,425 network attacks (60 per device).
  • 4 Trojan.GenericKD, which covers a family of malware that creates a backdoor to a command-and-control server, and backdoor.Small.DT, a web shell script used to create backdoors on web servers, were sixth and seventh on the list. 

The research shows that malware volume increased by 64% annually and that it is increasingly targeting Europe and the APAC region.

According to WatchGuard ,  nearly 37% of malware targeted the EMEA region, with several individual attacks focusing on the UK, Italy and Germany in Q2 2019. APAC came in second, targeted by 36% of overall malware attacks. In particular, the Razy and Trojan.Phishing. MH malware variants primarily targeted the APAC region, with 11% of Trojan.Phishing.MH detections found in Japan.

“This edition of the Internet Security Report exposes the gritty details of the methods hackers use to sneak malware or phishing emails onto networks by hiding them on legitimate content hosting domains,” said Corey Nachreiner, CTO at WatchGuard Technologies. 

“Luckily there are several ways to defend against this, including DNS-level filtering to block connections to known malicious websites, advanced anti-malware services, multi-factor authentication to prevent attacks leveraging compromised credentials, and training to help employees recognise phishing emails......No one defence will prevent every attack, so the best way for organisations to protect themselves is with a unified security platform that offers multiple layered security services.”

Widespread Phishing and Office Exploit Malware Increases
Two pieces of malware, a phishing attack that threatens to release fake compromising information on the victim and a Microsoft Office exploit, that appeared on the most widespread malware list in Q1 2019 and Q4 2018 have graduated to the top ten list by volume. This illustrates that these campaigns are on the rise and are sending a high volume of attacks at a wide range of targets. Users should update Office regularly and invest in anti-phishing and DNS filtering security solutions.

SQL injection dominates Network Attacks
SQL injection attacks made up 34% of all network attacks detected in Q2 2019 and have increased significantly in volume year-over-year. One specific attack increased over 29,000% from Q2 2018 to Q2 2019.

Anyone who maintains a SQL database, or a web server with access to one, should patch systems regularly and invest in a web application firewall.

The Report also contains a detailed analysis of the actual malware used in the Sodinokibi MSP ransomware attacks. 
 WatchGuard’s research shows that the attackers leveraged weak, stolen, or leaked credentials to gain administrative access to legitimate management tools that these MSPs used to monitor and manage their clients’ networks, then used these tools to disable security controls and stage and deliver the Sodinokibi ransomware via PowerShell.

Help Net Security:         WatchGuard

You Might Also Read:

A New Era Of Malware:

 

 

 

 


 

 

« UK Announces Plans For A Workforce Cyber Security Audit
USA and Britain Agree To Share Crime Data »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Waterfall Security Solutions

Waterfall Security Solutions

Waterfall Security is focused on protecting critical infrastructure and industrial control systems from remote online cyber attacks,

Software Testing News

Software Testing News

Software Testing News provides the latest news in the industry; from the most up-to-date reports in web security to the latest testing tool that can help you perform better.

Modux

Modux

Modux focus on a number of core competencies across cyber security including; cyber intelligence & analytics, penetration testing and training.

CyberGuarded

CyberGuarded

CyberGuarded are an accredited vendor independent information security testing and auditing company.

Bangladesh Association of Software & Information Services (BASIS)

Bangladesh Association of Software & Information Services (BASIS)

BASIS is the national trade body for Software & IT Enabled Service industry of Bangladesh.

Venrock

Venrock

Venrock helps entrepreneurs build some of the world's most disruptive, successful companies. We invest in technology: Security, Cloud Services, Big Data, Healthcare IT, AdTech.

Nubeva Technologies

Nubeva Technologies

Nubeva provide a breakthrough TLS Decrypt solution with Symmetric Key Intercept to gain the visibility needed to monitor and secure network traffic.

BitNinja

BitNinja

BitNinja provides full-stack server security in one easy-to-use protection suite. Enjoy real-time protection, automatic false positive handling and threat analysis for more in-depth insights.

StartupXseed Ventures

StartupXseed Ventures

StartupXseed Ventures is a smart capital provider for Deep Tech, B2B, Early Stage Startups. We support, NextGen Tech Entrepreneurs, who have potential to deliver the outsized growth.

CyberCyte

CyberCyte

CyberCyte provides a disruptive built-in integrated physical, network and perimeter security solution framework.

StateRAMP

StateRAMP

StateRAMP reduces risk from unsecure cloud solutions and protects data by providing State and local governments a standardized approach for verifying and monitoring security postures.

MainNerve

MainNerve

MainNerve helps secure networks, applications, people, and facilities… enabling businesses to reduce risk and increase their cybersecurity posture.

ThreatLocker

ThreatLocker

The ThreatLocker Platform provides a Zero Trust security solution that offers a unified approach to protecting users, devices, and networks against the exploitation of zero day vulnerabilities.

Oleria Security

Oleria Security

Oleria is the only adaptive and autonomous security solution that helps organizations accelerate at the pace of change, trusting that data is protected.

SafeLiShare

SafeLiShare

SafeLiShare’s data security platform unifies encryption strategies for organizations with hybrid and multi-cloud infrastructures, ensuring data is secure regardless of its location.

CyberUpgrade

CyberUpgrade

CyberUpgrade is on a mission to empower executives to gain control over their organization’s cybersecurity.