HomeSecurityFormbook is the most widespread malware

Formbook is the most widespread malware

Formbook takes the throne as the most widespread malware.

Check Point cybersecurity researchers have released their September 2023 Global Threat Index, revealing significant changes in the cyberthreat landscape. The report highlights a major phishing attack that affected multiple organizations in Colombia, leading to the rise of the Remcos Remote Access Trojan (RAT) malware and the rise of Formbook as the most prevalent malware after Qbot disappeared.

It is important to note that Qbot, also known as Qakbot and Pinkslipbot malware, faced disruption from the FBI in August 2023, having infected 700,000 computers worldwide. Despite this disruption, a recent report from Cisco Talos Intelligence Group reveals that the cybercriminals responsible for Qbot remain active, now distributing a new malware known as Ransom Knight.

See also: Hackers affect Modern Warfare 3 Beta even on PlayStation

Formbook

Colombia under attack: Remcos RAT released

In September, Check Point research uncovered a large, aggressive phishing campaign targeting over 40 well-known businesses across various industries in Colombia. The main goal of this campaign was to silently install the Remcos RAT on victims’ computers

Remcos ranked as the second most widespread malware in September. It is a sophisticated Remote Access Trojan that offers attackers complete control over infected systems and flexible malicious capabilities. The consequences of a Remcos infection are severe, including data theft, subsequent malware infections, and account takeover.

Maya Horowitz, Vice President of Research at Check Point Software, said: “The campaign we uncovered in Colombia gives us a glimpse into the complex world of evasion techniques used by hackers. It’s also a good illustration of how aggressive these techniques are and why we need cyber resilience to protect ourselves from various types of attacks.”

See also: HelloKitty Ransomware source code leaked

Formbook takes the throne

The September Official Global Threat Report also revealed a significant change at the top of the malware rankings. Formbook, an Infostealer that attacks Windows computers, took the top spot with a global impact of 3% on organizations worldwide.

First detected in 2016, the Formbook data stealer malware is promoted as a Malware as a Service (MaaS) on underground hacker forums due to its powerful evasion techniques and relatively low price. Its capabilities include collecting credentials from web browsers, capturing screenshots, logging typed characters, and executing files at the attacker’s command.

See also: Google: Expands exploit reward programs for Chrome V8, Google Cloud

End of Qbot dominance?

The most significant change in the malware landscape was the departure of Qbot from the top malware list. The FBI gained control of the Qbot network in August, marking the end of its long reign as the most prevalent malware for much of 2023.

However, as the group responsible for Qbot is still active and already spreading new malware, the importance of the malware's infrastructure disruption may have diminished somewhat.

Information source: hackread.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS