The extremely dangerous vulnerability called Bash/ShellShock dominated the malware for the third quarter of 2014. It caused alarm among security experts, as criminals can easily exploit the Bash vulnerability, gaining full access to the operating system of many popular devices, such as routers and wireless access points.
In addition to the above incident, Kaspersky Lab’s Global Research and Analysis Team discovered two cyber espionage campaigns that hit more than 2,800 high-profile targets in over 45 countries around the world. At the same time, the geographic distribution of untargeted mass attacks is becoming truly global. For example, attacks carried out using mobile malware were detected in 205 countries.
The third quarter in numbers
- Over one billion malicious attacks were blocked from Kaspersky Lab users’ computers and mobile devices. This is a 33.1% increase compared to the previous quarter.
- Two digital espionage campaigns (Crouching Yeti and Epic Turla) affected high-profile victims from at least 10 industries, including government agencies, embassies, militaries, research organizations, and IT companies.
- 74.500 new mobile malware samples were added to Kaspersky Lab's collection. This is an increase of 14.4% compared to the second quarter
- Over 7,000 mobile banking Trojans were detected in Q3. This number is 3.4 times higher compared to the previous quarter.
- Banking Trojan attacks detected in 70 countries, up from 31 in the second quarter
"In the third quarter, web antivirus functions were activated at least once on the computers of one third of users when they were surfing the Internet. This is an increase, while this figure has been decreasing over the past year. Specifically, in the third quarter of 2013 it was 34.1%, in the first quarter of 2014 it fell to 33.2% and since the beginning of the second quarter it has stabilized at 29.5%. This development is due to several factors. First, browsers and search engines have started to contribute to the fight against malicious websites. In addition, there have been fewer attacks involving "exploit kits", following the arrests of several developers. However, it would be naive to expect a sharp decrease in the use of exploits. "Exploits remain the main choice when it comes to malware delivery methods for targeted attacks," said Maria Garnaeva, Security Researcher at Kaspersky Lab's Global Research and Analysis Team.
The good news
Kaspersky Lab joined a coalition of law enforcement and industry partners, led by the UK’s National Crime Agency (NCA), to disrupt the infrastructure behind the Shylock Trojan. Like other well-known banking Trojans (e.g. Zeus, SpyEye and Carberp), Shylock is a “man-in-the-browser” attack designed to steal bank account credentials from bank customers’ computers. When activated, Shylock transfers money from users’ accounts into the pockets of cybercriminals.
How an expert "hacked" his own home
A Kaspersky Lab security researcher conducted a survey of his home to see if it was truly digitally secure. He examined various devices, including network-attached storage devices, a smart TV, a router, and a satellite receiver, to see if they were vulnerable to digital attacks. The results were impressive. The researcher found 14 vulnerabilities in the storage devices, one in the smart TV, and several potentially hidden remote control features in the router.
The origin of digital attacks
There were major changes in the “sources of origin” of cyber threats. In the second quarter, the top five were occupied by Germany, the US, the Netherlands, Russia and Canada. In the third quarter, the US recorded a large increase (11.2 percentage points) and topped the list with 33%. Germany fell to third place (13.5%) while the Netherlands was in second place (18%). Ukraine took fifth place (4%), displacing Canada from the top five. Russia maintained fourth place with 9%.
The full version of Kaspersky Lab's Q3 2014 Cyber Threat Report is available on Securelist.
An interactive map that offers a visual representation of cybersecurity incidents around the world in real time is available here.
