In the last quarter of 2016, the number of users who were forced to deal with malicious online software (malware), capable of extorting money or valuable financial personal information, reached 319,000, a number increased by 22.49% compared to the same period in 2015.
The increase in the total number of attacks was detected during the Black Friday, Cyber Monday and of course during the Christmas period. 
The holiday season is a very attractive time, not only for retailers due to increased demand for products and for consumers looking for great deals, but also for digital criminals, who do not hesitate to seize every new opportunity to illegally exploit people's financial data, at a time of year when more users than usual decide to spend their money online.
At the end of 2016, Kaspersky Lab researchers conducted a major review of the digital threat landscape during the holiday season (October, November, and December) for the past three years. The main conclusion of their analysis was that criminals are trying to link their malicious actions to specific holidays.
The dynamics of financial malware during Q42016 (holiday season)
According to the analysis of Kaspersky Lab experts, the 2016 holiday season was no exception. Kaspersky Lab’s protection technologies detected attacks on 22.49% more users compared to the same period in 2015. This means that after a slight decline in 2014, cybercriminals are once again investing in the development and distribution of malware capable of stealing financial data, such as credit card details and/or confidential login details of users during their online banking transactions.
As the dynamics of attacks in November 2016 showed, the most attractive day of the autumn/winter holidays for cybercriminals was Cyber Monday (the first Monday after Black Friday). Especially in November 2016, Kaspersky Lab’s protection technologies detected a clear and sharp increase in the number of users attacked, and specifically on November 28 (Cyber Monday) the number of users attacked was twice as high as the day before.
When it comes to Black Friday and the Christmas period, the pattern is quite different, with most attacks occurring one or two days before the exact dates of the holidays. These differences in malicious behavior can be explained by the different nature of the holidays. Unlike Black Friday and Christmas, Cyber Monday is completely associated with online sales, so criminals find it more meaningful to focus their malicious campaigns on this date.
To achieve their goals, criminals use one of the 30 “families” of banking trojans constantly monitored by Kaspersky Lab. The five most widespread of them are: Zbot, Nymaim, Shiotob, Gozi and Neurevt. These trojans are responsible for attacks against 92.35% of users during the holiday season.
“Data on attack dynamics shows that financial malware operators attempted to tie their activity to specific dates in 2016, and the contribution of the holiday season to the number of financial malware attacks during this period is clearly visible. Financial malware are once again on the rise, and all their targets – from online store owners and customers, to credit card holders and banks – should be aware of the risks and take appropriate preventive measures to stay safe. As a protective measure, following the attacks that occurred during the holiday season, we advise shoppers who used credit cards to purchase gifts and goods during the past three months to systematically check their financial transaction information in the coming months. Typically, criminals do not start withdrawing money from stolen card details immediately after the theft. They often wait several weeks, or even months, to have enough time to prepare for the cashout,” said Oleg Kupreev, security expert at Kaspersky Lab.
As the most recent holiday season comes to an end, Kaspersky Lab advises consumers to keep a few simple rules in mind to stay safe, especially when it comes to online financial transactions:
- Do not open links you receive from unknown people, or suspicious links sent by your friends via Social Media or via email, as they may be malicious.
- Do not enter your credit card details on unknown or suspicious websites to avoid them falling into the hands of cybercriminals. If these websites offer deals that seem too good to be true, they probably belong to criminals.
- Always check if the website is genuine before entering any of your login details or confidential information (at least take a look at the URL). Fake websites can look exactly like the real ones.
- Install a security solution on your devices, with built-in technologies aimed at preventing any potential financial fraud. For example, Safe Money technology from Kaspersky Lab's recommended solutions creates a secure environment for financial transactions at all levels.
More information about financial threats during the 2016 holiday season can be found at Securelist.com.

Download the PDF