HomeSecurityCybercriminals: They continue to target remote access services

Cybercriminals: They continue to target remote access services

Cybercriminals still prefer to target services that are vulnerable due to remote access.

cybercriminals

Corey Nachreiner, chief security at WatchGuard, stresses the importance of organizations staying informed about evolving threat tactics. He points out that modern security platforms offer improved protection, but social engineering requires active participation from the user, which is why proper training is required.

Read more: Norton Healthcare: May ransomware attack led to data breach

Medusa ransomware is growing

The ransomware saw an 89% increase in ransomware attacks in the third quarter. Threats are increasingly exploiting remote administration tools to evade detection. According to Threat Lab research, a tech support scam was detected using a pre-configured version of TeamViewer. Additionally, malicious scripts decreased by 11%, while attacks exploiting Windows binaries increased by 32%. Script-based attacks remain the largest attack vector, accounting for 56% of the total, using scripting languages ​​such as PowerShell.

Malware via encrypted connections shows decline

Malware delivered via encrypted connections decreased to 48%, indicating a significant decrease compared to the previous quarter. The total number of malware detections increased by 14%. A dropper family, which uses email to deliver malicious payloads, took four of the top five spots in encrypted malware detections. A new threat, known as the Lazy.360502 family, entered the top ten list, delivering adware and the Vidar password. The report also highlights the risk of sending malicious emails, such as fake invoices or important documents, with the aim of defrauding users. The Lazy.360502 threat is associated with a Chinese-origin website that provides credential theft services.

Cyber ​​attacks are on the rise

Cyberattacks vulnerability stood out as the top network attack, accounting for 10% of all network detections.

Three new reports appeared in the Top 50 network attacks. These included a vulnerability in Apache's PHP Common Gateway Interface from 2012 that could cause a buffer overflow. In addition, another vulnerability was reported in Microsoft .NET Framework 2.0 from 2016 that could lead to a DDoS attack.

cybercriminals

Drupal, the open source CMS, has also been plagued by an SQL injection vulnerability since 2014. This vulnerability allowed cybercriminals to exploit Drupal remotely without the need for authentication.

See also: Cybercriminal training center discovered by authorities

Source: helpnetsecurity.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS