Wipers and fileless malware: The first three months of 2017 saw a sharp increase in the sophistication of state-sponsored cyberattacks, with threat actors turning their attention to wipers, as well as financial crime. 
These, as well as other trends, are covered in Kaspersky Lab's first quarterly summary report with data from its regular digital threat update reports sent exclusively to its subscribers.
The new quarterly report “APT Trends” will be available for free and will highlight significant developments in targeted attacks, as well as emerging trends that require the immediate attention of businesses and organizations. The content of the first quarter report is drawn from the observations of Kaspersky Lab experts, who monitored the activity of APT actors during the first quarter
Highlights of the first quarter of 2017 include:
- Wipers are used by targeted threat actors, both for digital sabotage and to erase traces of cyber espionage operations. An advanced generation of wipers was used in the new wave of attacks by the Shamoon group . The subsequent investigation led to the discovery of StoneDrill and similarities in code to that of the NewsBeef (Charming Kitten) group. A victim of StoneDrill was found in Europe.
- Targeted attackers vary in the way they steal money. Long-term monitoring of the Lazarus group has identified a subgroup, which Kaspersky Lab has named BlueNoroff , that is actively attacking financial institutions in different countries, including a high-intensity attack in Poland. BlueNoroff is believed to be behind the infamous Bangladesh bank robberies.
- Fileless malware is used in attacks by both targeted attack actors and cybercriminals in general – helping to evade detection and making forensic investigations more difficult . Kaspersky Lab experts have found examples in the lateral movement tools used in the Shamoon attacks, in attacks against Eastern European banks , and in the hands of a number of other APT actors.
“The targeted threat landscape is constantly evolving and attackers are increasingly better prepared, seeking and exploiting new gaps and opportunities. This is why Threat Intelligence is so important: it embraces organizations with understanding and reveals the actions they need to take. For example, the threat landscape for Q1 highlights the need for memory-based malware detection and incident response to combat fileless malware attacks, as well as security that can detect anomalies throughout the network’s lifecycle,” said Juan Andres Guerrero-Saade, Senior Security Researcher at Kaspersky Lab’s Global Research and Analysis Team.
Kaspersky Lab’s Global Research and Analysis Team currently monitors over a hundred threat actors and sophisticated malicious operations targeting commercial and government organizations in over 80 countries. During the first quarter of 2017, the company’s expertise generated 33 private reports for Intelligence Services subscribers, with Indicators of Compromise data and YARA rules to help flag and hunt malware.
