HomeSecurityThe most widespread and critical malware for 2019

The most widespread and critical malware for 2019

We present to you the most widespread and dangerous malware for 2019 (so far at least…):

Most wanted malware

  1. Coinhive – Crypto Miner designed to perform online mining of Monero cryptocurrency when a user visits a website. The embedded JavaScript uses a lot of computing resources of the users’ machines for mining, and may crash the system.
  2. Cryptoloot – Crypto-Miner that uses the victim’s CPU or GPU power and existing resources for crypto mining – adding transactions to the blockchain and releasing new currency. It is a competitor to Coinhive, trying to take the glory from it by demanding a smaller percentage of revenue from victim websites.
  3. Emotet – Advanced Trojan . Emotet once operated as a banking Trojan and has recently been used as a distributor in other malicious campaigns. It uses multiple methods to persist and evade detection. Additionally, it can spread via phishing emails that contain malicious attachments or links.

malware

Most wanted mobile malware

  1. Lotoor – Hack tool that exploits vulnerabilities in the Android operating system to gain root privileges on damaged mobile devices.
  2. Hiddad – Android malware that repackages legitimate apps and then releases them on a third-party store. Its primary function is to display ads, but it is also able to access key security details built into the operating system, allowing an attacker to obtain sensitive user data.
  3. Triada – Modular Backdoor for Android, which grants super user privileges to download malware, as well as helps it integrate into system processes. Triada also creates misleading URLs that are loaded into the browser.

The most widespread and critical malware for 2019

Most exploited vulnerabilities

  1. Microsoft IIS WebDAV ScStoragePathFromUrl Buffer Overflow (CVE-2017-7269) – By sending a crafted request over a network to Microsoft Windows Server 2003 R2 via Microsoft Internet Information Services0, a remote attacker could execute arbitrary code or cause a denial of service on the target server. This is primarily due to a buffer overflow vulnerability resulting from improper validation of a header in the HTTP request.
  2. OpenSSL TLS DTLS Heartbeat Information Disclosure (CVE-2014-0160; CVE-2014-0346)– An information disclosure vulnerability exists in OpenSSL. The vulnerability is due to an error in the handling of TLS/DTLS heartbeat packets. An attacker could exploit this vulnerability to disclose the memory contents of a connected client or server.
  3. Web servers PHPMyAdmin Misconfiguration Code Injection – A code injection vulnerability has been reported in PHPMyAdmin. The vulnerability is due to a misconfiguration of PHPMyAdmin. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP request to the target.

Be safe!!!

The most widespread and critical malware for 2019

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS