Websense Websense Security Labs 2014 Threat Report,” which analyzes the threats that marked the past year.
The report shows that 85% of malicious links contained in emails or used in other online attacks led to legitimate websites that had been compromised by cybercriminals. The hackers mainly targeted businesses operating in the IT and financial sectors, online shopping websites and travel sites.
Malicious links, as well as other malicious content, were detected in 3.3% of all spam messages.
When it comes to Exploit Kits, after the arrest of the developer of the BlackHole Exploit Kit, Paunch, cybercriminals started turning to other crimeware packs. Most of them turned to Magnitube and Neutrino.
Additionally, the notorious ZeuS, which was originally developed to attack financial institutions, has been completely repurposed. The malware is now being used to target organizations in the services, finance, government, communications, education, retail, healthcare, transportation, and utilities sectors.
“Cybercriminals continue to evolve, plan and precisely execute their attacks, overcoming most existing security measures and solutions,” explains Charles Renert of Websense.
“While attackers continue to successfully operate in the area of advanced, strategic attacks using zero-day exploits and advanced malware, there is also an explosion in cybercriminal activity on a massive scale,” he continues.
The full Websense Security Labs 2014 Threat Report is available via the website (registration is required to access it).

