Check Point Research, the research division of Check Point Software Technologies Ltd., has published its latest Global Threat Catalog for May 2019.
The research team is warning organizations to check and update systems vulnerable to the BlueKeep Microsoft RDP vulnerability (CVE-2019-0708) on machines running Windows 7 and Windows Server 2008, to avoid the risk of being exploited for ransomware and cryptomining attacks.

The BlueKeep vulnerability affects approximately 1 million machines that have access to the internet, and even more that are located within organizational networks.
The vulnerability is critical because it does not require user interaction to be exploited for malicious purposes. RDP is an established, popular attack vector that has been used to install ransomware such as SamSam and Dharma.
The Check Point Research team has identified multiple scan attempts for this flaw in recent weeks, originating from various countries worldwide, which could be the initial phase of an attack. In addition to the relevant updates from Microsoft, Check Point provides both network and endpoint for this attack.
Maya Horowitz, Director of Threat Intelligence and Research at Check Point, commented:
The biggest threat we saw last month was BlueKeep. While no exploits have been observed yet, there is plenty of public evidence that the project is in the works.
We agree with Microsoft and other cybersecurity industry observers that BlueKeep could be used to carry out attacks on a scale comparable to the WannaCry and NotPetya campaigns, which were implemented in 2017. A single computer with this flaw can be used to infect an entire network.
All infected computers with Internet access can then infect other vulnerable devices around the world – allowing the attack to spread exponentially, at an unstoppable pace. So it’s critical that organizations protect themselves – and others – by patching the flaw now, before it’s too late.

In another major cybersecurity news story in May, the developers of the GandCrab Ransomware-as-a-Service affiliate programannounced on the last day of May that they were shutting down the program and asked their partners to stop distributing the ransomware within 20 days.
The operation had been active since January 2018 and in just two months had infected over 50,000 victims. The total profits for the developers and their partners amount to billions of dollars.
Being one of the malware that was very often in the list of the 10 most widespread, GandCrab was frequently updated with new features to evade detection tools.
The 3 most prevalent malware threats in May 2019:
*Arrows indicate the change in ranking compared to the previous month.
- ↔ Cryptoloot – Cryptocurrency mining software that uses the victim's CPU or GPU power and existing resources for cryptomining – adding transactions to the blockchain and generating new coins. It competes with Coinhive, trying to displace it by demanding a smaller percentage of revenue from websites.
- ↔ XMRig – XMRig is an open source CPU mining software for the Monero cryptocurrency mining process that was first seen in circulation in May 2017.
- ↔ JSEcoin – JavaScript mining software that can be embedded into websites. With JSEcoin, you can run mining software directly in your browser in exchange for an ad-free browsing experience, in-game coins, and other incentives.
The 3 most prevalent mobile malware threats in May 2019:
For the month of May, Lotoor was the most prevalent mobile malware, while in April it was in second place. Triada falls from first place to third, while Hiddad rises from third to second.
- ↑ Lotoor– A hacking tool that exploits vulnerabilities in the Android operating system to gain root access to compromised mobile devices.
- ↑ Hiddad – Android malware that repackages legitimate apps and then makes them available in a third-party store. Its main function is to display ads, however, it is also capable of accessing important security components built into the operating system, allowing an attacker to obtain sensitive user data.
- ↓ Triada – A modular backdoor for Android that grants superuser privileges to downloaded malware, helping it integrate into system processes. Triada has also been observed to spoof URLs loaded in the browser.
Check Point researchers also analyzed the most frequently exploited cyber vulnerabilities. OpenSSL TLS DTLS Heartbeat Information Disclosure is at the top, affecting 44% of organizations worldwide.
For the first time in 12 months, the CVE-2017-7269 vulnerability was in second place, affecting 40% of organizations worldwide, while the CVE-2017-5638 vulnerability took third place, affecting 38% of organizations worldwide.
The 3 "most frequently exploited" vulnerabilities for May 2019:
May saw a return to traditional attack techniques (likely due to the decline in cryptominers’ profitability), with SQL Injections topping the list, affecting 49% of organizations worldwide. Web Server Exposed Git Repository Disclosure Information and OpenSSL TLS DTLS Heartbeat Information Disclosure vulnerabilities are in second and third place, affecting 44% and 41% of organizations worldwide, respectively.
- ↑ SQL Injection – The attack relies on crafted SQL queries in forms to trick the application that processes them, bypassing any checks and executing them, thus allowing the attacker to give commands to the database to leak data from it.
- ↑ Web Server Exposed Git Repository Information Disclosure – There are reports of an information disclosure vulnerability in the Git Repository. Successful exploitation of this vulnerability could allow the inadvertent disclosure of user account information.
- ↓ OpenSSL TLS DTLS Heartbeat Information Disclosure (CVE-2014-0160; CVE-2014-0346) – An information disclosure vulnerability exists in OpenSSL. The vulnerability is due to an error in the handling of TLS/DTLS heartbeat packets. An attacker could exploit this vulnerability to disclose the contents of the memory of a connected client or server system.
___________________
- Windows exploit in a highly targeted attack
- Microsoft: Android apps with ads
- How internet speed tests work and how accurate are they?
