Skip to main content

There's a new top dog when it comes to dangerous malware

Qbot has become the most prevalent banking trojan around, taking the top spot from Emotet, new figures have claimed.

According to fresh figures from the Check Point Global Threat Index for December 2022, Qbot (also known as Qakbot) impacted 7% of organizations worldwide, retaking the number one spot from Emotet (4%).

Based on proprietary data, Check Point’s report says that besides Qbot and Emotet, XMRig rounded off the top three most prevalent malicious programs around, for the last month of the year.

Abusing known vulnerabilities

XMRig, impacting 3% of businesses worldwide is a cryptominer, a program that “mines” the XMR cryptocurrency for the attackers. It’s a popular application, which the threat actors aim mostly to install on servers and other high-end machines.

When it comes to mobile devices, a completely different set of malware prevailed. Anubis was the most prevalent variant, followed by Hiddad and AlienBot.

But to install these malware, hackers need to have some way to access the target endpoints, which is mostly done through known vulnerabilities.

“Web Server Exposed Git Repository Information Disclosure” was the most commonly exploited vulnerability, Check Point said, impacting almost half (46%) of organizations globally. “Web Server Malicious URL Directory Traversal” was second-placed with 44% of businesses around the world being impacted. The top three were rounded off with “Command INjection Over HTTP” - 43%. 

Education and Research remained the most attacked industry, before Government and Military, and Healthcare.

“The overwhelming theme from our latest research is how malware often masquerades as legitimate software to give hackers backdoor access to devices without raising suspicion. said Maya Horowitz, VP Research at Check Point Software. “That is why it is important to do your due diligence when downloading any software and applications or clicking on links, regardless of how genuine they look.”  

Last year, hackers were busy building fake landing pages, tricking people into either downloading malware, or giving away sensitive data. In just one instance, in late October last year, cybersecurity researchers from Malwarebytes discovered a major campaign that leveraged more than 200 landing pages used to gain access to people’s bank accounts. 



Comments

Popular posts from this blog

Garmin's new radar-equipped tail light will keep you safe on your e-bike

Garmin's Varia bike radars are some of the most popular pieces of cycling tech around – and now the company has delivered its first rearview radar to have been specially designed for some of the best e-Bikes .   Garmin's Varia range mounts to the back of your bike and broadcasts a radar signal behind you, so you can get visual and audible alerts when something's overtaking you. Even better, the new Varia eRTL615 plugs directly into most e-bikes, with no battery required. Because the catchily-named Varia eRTL615 is also a tail light, it'll also make sure you're visible to other vehicles too, promising to emit a flashing or solid light that's visible from up to a mile away in daylight. To connect Garmin's new radar tail light to your e-bike, you'll need to pick the right Garmin adapter cable (which isn't included). You can buy power cables compatible with Bosch, Shimano, or USB-A terminals or connections, with more info on those available on Garmin...

Revolution Software is using their own AI technology to remake Broken Sword

TechRadar Gaming is reporting live from Gamescom 2023 on the latest and greatest developments in gaming and hardware. Revolution Software announced at Gamescom 2023 that Broken Sword would be coming back, with Broken Sword - The Shadow of the Templars getting a full remake while a sixth title in the series is coming in the future too, under the title Broken Sword - Parzival’s Stone .  Speaking to TRG ahead of the announcement, Cecil talked about the studio’s plans for a Broken Sword remake and the sixth title in the series. Cecil is a larger-than-life character, who is able to talk about the studio’s plans with enthusiasm. It even carries a pocketful of stones to illustrate the plans for Parzival’s Stone , but he also talks about how Broken Sword - The Shadow of the Templars would be using AI to upscale.  Cecil wasn’t shy about the studio’s use of AI technology, but he gave a fairly robust explanation of why the game was using it. The AI technology will be used to upda...

Hackers steal passwords, emails from hookup websites

Two gay hookup websites have been breached with sensitive and personal user data stolen and sold online, new reports have claimed. The databases, which are now being sold on dark web forums, were taken from platforms called TruckerSucker, and CityJerks. They contain enough personally identifiable information to engage in identity theft , such as usernames and passwords, email addresses, profile pictures, sexual preferences, birth dates, postal addresses, IP addresses, and bios. The passwords are encrypted, but according to TechCrunch, the algorithm is “weak” and could be broken by a more persistent hacker. The silent treatment HaveIBeenPwned founder Troy Hunt, who was tipped off on the leak, described the incident as a “typical forum breach, albeit with super sensitive content.”  However the content includes more than just identity data, as there are also messages users exchanged, including arranging meetings and describing their sexual preferences.  In total, more than...