HomeSecurityCheck Point The most widespread malware in August

Check Point The most widespread malware in August

Check Point Research, the research arm of Check Point Software Technologies Ltd., has published its latest Global Threat List for August 2019. The research team warns organizations about Echobot, a new variant of the Mirai IoT Botnet, which has launched widespread attacks against a range of IoT devices.

Checkpoint

Echobot inthe “Command Injection Over HTTP” vulnerability, which has affected 34% of organizations globally.

During August, two months after its operations were suspended, the Emotet. Emotet was the largest active botnet during the first half of 2019. Although no significant attacks have yet been observed exploiting this malware, it is likely that it will soon be used in spam campaigns.

“The sharp increase in exploits is a fact worth highlighting, as Echobot first emerged in mid-May as a new variant of the infamous Mirai IoT Botnet, and now targets more than 50 different vulnerabilities. Echobot has impacted 34% of companies worldwide, demonstrating that network, software, and IoT device updates are critical for organizations,” said Maya Horowitz, Director of Threat Intelligence and Research at Check Point.

Check Point The 3 most prevalent malware threats in August 2019:

*Arrows indicate the change in ranking compared to the previous month.

XMRig continues to top the list, followed by Jsecoin. The two malwares affected 7% of organizations worldwide, while Dorkbot came in third place, affecting 6% of organizations worldwide .

  1. ↔ XMRig – XMRig is an open source CPU mining software for the Monero cryptocurrency mining process that was first seen in circulation in May 2017.
  2. ↔ Jsecoin – JavaScript mining software that can be embedded into websites. With JSEcoin, you can run mining software directly in your browser in exchange for an ad-free browsing experience, in-game coins, and other incentives.
  3. ↔ Dorkbot – IRC-based worm designed to allow remote code execution by its operator, as well as downloading additional malware to the infected system, with the main purpose of intercepting sensitive information and carrying out denial-of-service attacks.

The 3 most prevalent mobile malware threats in August 2019:

During August, Lotoor was the most widespread mobile malware, followed by AndroidBauts and Triada.

  1. Lotoor – A hacking tool that exploits vulnerabilities in the Android operating system to gain full root access to compromised mobile devices.
  2. AndroidBauts – This is an adware that targets Android users. The software erases the IMEI, IMSI, GPS location and other device information and allows the installation of third-party applications on the device.
  3. Triada – A modular backdoor for Android that grants superuser privileges to downloaded malware, helping it integrate into system processes. Triada has also been observed to spoof URLs loaded in the browser.

The 3 most frequently exploited vulnerabilities in August 2019

In August, SQL Injection techniques continued to top the list, followed by the OpenSSL TLS DTLS Heartbeat Information Disclosure vulnerability. The use of these techniques and the exploitation of the aforementioned vulnerability affected 39% of organizations worldwide. In third place was the MVPower DVR Remote Code Execution vulnerability, affecting 38% of organizations worldwide.

  1. ↔ SQL Injection (various techniques) – This involves inserting an SQL query into the data provided by the client in an application, resulting in the exploitation of a vulnerability in the code of that application.
  2. ↔ OpenSSL TLS DTLS Heartbeat Information Disclosure (CVE-2014-0160; CVE-2014-0346) – An information disclosure vulnerability exists in OpenSSL. The vulnerability is due to an error in the handling of TLS/DTLS heartbeat packets. An attacker could exploit this vulnerability to disclose the contents of the memory of a connected client or server system.
  3. ↔ MVPower DVR Remote Code Execution – A remote code execution vulnerability exists in MVPower DVR devices. A remote attacker could exploit this flaw and execute arbitrary code on the affected router via a crafted request.

*The full list of the 10 most prevalent malware threats worldwide can be found here.

Check Point's Threat Prevention Sources are available on the website:

https://www.checkpoint.com/threat-prevention-resources/index.html

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS