HomeSecurityCheck Point Greece: widespread malware in August

Check Point Greece: widespread malware in August

Check Point Research, the research division of Check Point Software Technologies Ltd., published the latest Threat List for Greece in August 2019.

Below you will find Check Point's full list of the 10 most prevalent malware threats in Greece for August:Checkpoint

AgentTesla – AgentTesla is a sophisticated RAT that functions as a keylogger and password stealer, infecting computers since 2014. AgentTesla has the ability to monitor and collect the victim’s keyboard and system clipboard entries, take screenshots, and extract credentials from software installed on the victim’s machine (including Google Chrome, Mozilla Firefox, and the Microsoft Outlook email client). AgentTesla is sold as a legitimate RAT with interested parties paying $15 – $69 for a user license.

Lokibot – Lokibot is information-sniffing software that is primarily spread through phishing emails and is used to steal data such as email credentials, as well as passwords to cryptocurrency wallets and FTP servers.

Jsecoin – JavaScript mining software that can be embedded into websites. With JSEcoin, you can run mining software directly in your browser in exchange for an ad-free browsing experience, in-game coins, and other incentives.

XMRig – XMRig is an open source CPU mining software used for the Monero cryptocurrency mining process and was first seen in circulation in May 2017.

Hawkeye – Hawkeye is a malicious Info Stealer, which was primarily designed to extract user credentials from infected Windows platforms. In recent months, Hawkeye has been enhanced to include keylogging capabilities in addition to stealing email and web browser passwords. It is often marketed as MaaS (Malware as a Service) through various infection chain techniques.

NanoCore – NanoCore is a remote access trojan, first observed in 2013, targeting Windows users. All versions include features such as screen recording, cryptocurrency mining, remote control, and more.

Nanobot – Nanobot is a botnet of hosts controlled by the NanoCore RAT, a remote access Trojan that targets Windows users. All versions of the RAT include basic functionality, such as screen recording, cryptocurrency mining, remote desktop control, and webcam hijacking. NanoCore is sold on dark web forums for around $25, and various versions of the RAT have been leaked over time.

Trickbot – Trickbot is a variant of Dyre that appeared in October 2016. Since then, it has mainly targeted banking users in Australia and the United Kingdom, and has recently started appearing in India, Singapore, and Malaysia.

Cryptoloot – Cryptocurrency mining software that uses the victim's CPU or GPU power and existing resources to mine cryptocurrency – adding transactions to the blockchain and generating new coins. Competes with Coinhive.

Ramnit – Ramnit is a worm that infects and spreads primarily through removable drives and files uploaded to public FTP services. The malware creates a copy of itself to infect removable and permanent drivers. The malware also acts as a backdoor.

Malware familyGlobal impactImpact Greece
AgentTesla5.20%24.07%
Lokibot2.60%13.69%
Jsecoin7.14%10.37%
XMRig7.26%7.47%
Hawkeye2.50%7.05%
Nanocore0.68%7.05%
Nanobot0.68%7.05%
Trickbot5.40%4.98%
Cryptoloot3.32%4.56%
Ramnit3.77%4.15%
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS