HomeSecurityCheck Point July 2019 the most widespread malware in Greece

Check Point July 2019 the most widespread malware in Greece

Check Point Research, the research division of Check Point® Software Technologies Ltd., has published the most prevalent malware in Greece for July 2019.

Check Point July 2019 the most widespread malware in Greece
Image theregister.co.uk

AgentTesla – AgentTesla is a sophisticated RAT that functions as a keylogger and password stealer, infecting computers since 2014. AgentTesla has the ability to monitor and collect the victim’s keyboard and system clipboard entries, take screenshots, and extract credentials from software installed on the victim’s machine (including Google Chrome, Mozilla Firefox, and the Microsoft Outlook email client). AgentTesla is sold as a legitimate RAT with interested parties paying $15 – $69 for a user license.

Lokibot – Lokibot is information-sniffing software that is primarily spread through phishing emails and is used to steal data such as email credentials, as well as passwords to cryptocurrency wallets and FTP servers.

NanoCore – NanoCore is a remote access trojan, first observed in 2013, targeting Windows users. All versions include features such as screen recording, cryptocurrency mining, remote control, and more.

Jsecoin – JavaScript mining software that can be embedded into websites. With JSEcoin, you can run mining software directly in your browser in exchange for an ad-free browsing experience, in-game coins, and other incentives.

AZORult – AZORult is a trojan that collects and removes data from the infected system. Once the malware is installed on a system (usually delivered by an exploit kit like RIG), it can send saved passwords, local files, crypto wallets, and computer profile information to a remote command & control server.

XMRig – XMRig is an open source CPU mining software used for the Monero cryptocurrency mining process and was first seen in circulation in May 2017.

Trickbot – Trickbot is a variant of Dyre that appeared in October 2016. Since then, it has mainly targeted banking users in Australia and the United Kingdom, and has recently started appearing in India, Singapore, and Malaysia.

Emotet – A sophisticated, self-replicating modular trojan. Emotet was once a banking account stealing Trojan and has recently been used to distribute other malware or in malware distribution campaigns. It uses multiple evasion methods and techniques to persist on a system and evade detection. It can also be spread through unsolicited phishing emails that contain attachments or links with malicious content.

FormBook – FormBook is an InfoStealer targeting the Windows operating system and was first detected in 2016. It is advertised on hacking forums as a tool that has strong evasion techniques and relatively low prices. FormBook collects credentials from various web browsers and screenshots, monitors and records keystrokes, and can download and execute files according to C&C instructions given to it.

Dorkbot – IRC-based worm designed to allow remote code execution by its operator, as well as downloading additional malware to the infected system, with the main purpose of intercepting sensitive information and carrying out denial-of-service attacks.

Malware family

Global impact

Impact Greece

AgentTesla

4.74%

15.61%

Lokibot

3.01%

15.61%

Nanocore

5.04%

13.50%

Jsecoin

6.40%

12.66%

AZORult

1.29%

12.24%

XMRig

7.62%

8.86%

Trickbot

4.60%

6.75%

Emotet

5.30%

6.33%

Formbook

3.61%

5.91%

Dorkbot

5.77%

5.06%

The Global Threat Incident Catalog and the ThreatCloud Map from Check Point are based on Check Point's ThreatCloud intelligence, the largest collaborative network for combating cybercrime, which provides data on threats and trends prevailing in attacks, leveraging a global network of threat detectors.

The ThreatCloud database includes more than 250 million addresses that are analyzed for bot detection, more than 11 million malware signatures, and over 5.5 million infected websites, while it identifies millions of malware types daily.

Check Point Threat Prevention Resources are available at:
https://www.checkpoint.com/threat-prevention-resources/index.html

______________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS