HomeinetDigital threats in the first quarter of 2014

Digital threats in the first quarter of 2014

fds

– Mobile banking Trojans doubled

– Rapid increase in attacks on bitcoinwallets

– “Resurrection” of digital espionage

Athens, 24 April 2014

Last December, Kaspersky Lab published its predictions for the digital threat landscape in 2014. Within just three months, the company's experts found that all three of their predictions for threats against end users had already been confirmed.

Specifically, Kaspersky Lab experts predicted that cybercriminals would target:

–     User privacy, resulting in the increasing popularity of VPN services and Tor-anonymizers. Today, the number of users turning to the Darknet in an attempt to protect their personal data is constantly increasing. However, in addition to well-intentioned users, Tor continues to become a magnet for malicious activities, as anonymous networks can cover malware activity, transactions on illegal websites, and money laundering. For example, in February, KasperskyLabdetected the first Android Trojan that uses a domain in the pseudo zone “.onion” as a Command & Control location.

–     Users’ money, with experts estimating that cybercriminals will continue to develop related tools. The prediction was confirmed in March, with the detection of Trojan-SMS.AndroidOS.Waller.a. This Trojan can steal money from QIWI e-wallets, which belong to owners of “infected” smartphones. To date, this Trojan has only targeted Russian users, but it can spread anywhere that e-wallets are controlled via text messages. In addition, cybercriminals have also used established methods, such as spreading Trojans for mobile devices that steal money with the help of malicious spam. In this case, the problem is clearly wider. For example, the mobile banking Trojan “Faketoken” has affected users in 55 countries, including Germany, Sweden, France, Italy, the UK and the USA. It is noted that the number of banking mobileTrojansalmost doubled in the first quarter of 2014, reaching 2,503 from 1,321.

–     Bitcoins ,with experts expecting a significant increase in the number of attacks targeting Bitcoin wallets, pools and exchanges. Several incidents in the first three months of 2014 proved that prediction correct. The most notable of these include the bankruptcy of MtGox, one of the largest bitcoin exchanges, after a hacker attack and the attack on the personal blog and Reddit account of Mark Karpeles, CEO of MtGox. In this way, cybercriminals managed to publish the file MtGox2014Leak.zip, which turned out to be malware with the ability to search for and steal Bitcoin wallets. In their attempt to increase their illegal profits, cybercriminals attack computers and use their resources to produce more digital currencies. Trojan.Win32.Agent.aduro, which ranked twelfth on the list of most frequently detected malicious objects on the Internet in the first quarter of 2014, is one of the Trojans used in such processes.

The “Walking Dead” are back: The “Resurrection” of digital espionage campaigns

The first quarter of 2014 also saw a major cyber-espionage incident. In February, Kaspersky Lab published its report on one of the most advanced threats of our time, called “The Mask.” Its main target was the confidential information of government agencies, embassies, energy companies, research institutions, investment firms and activists from 31 countries. According to the researchers, the sophistication of the tools used by the attackers and several other factors indicate that this campaign could have had state support.

“In addition to new incidents, we noticed that campaigns that seemed to have been completed continued. For example, after cybercriminals had shut down all known command servers involved in Operation Icefog, we detected a Java variant of the threat. The previous attack had primarily targeted organizations in South Korea and Japan, but the new variant was only interested in organizations in the US, judging by the IP addresses detected,” commented Alexander Gostev, Chief Security Expert of the Global Research and Analysis Team at KasperskyLab.

Thefirst quarter in numbers

  • 33.2% of computer users worldwide experienced at least one cyberattack in the last three months – a 5.9% decrease compared to the same period in 2013.
  • 39% of the cyberattacks neutralized were carried out via online resources based in the US and Russia. The overall share for both countries fell by 5 percentage points compared to the first quarter of 2013. They were followed by the Netherlands (10.8%), Germany (10.5%) and the United Kingdom (6.3%).
  • Over 99% of mobile malware targeted Android devices. The total number of mobile malware increased by 1% in the last quarter.
  • At the end of 2013, KasperskyLab had collected 189,626 mobile malware samples. In the first quarter of 2014 alone, 110,324 new malware samples were added to the company's database. At the end of the first quarter, KasperskyLab had collected 299,950 samples.

KasperskyLab's full threat landscape report for Q1 2014 is available at securelist.com .

 

About Kaspersky Lab

Kaspersky Lab is the world's largest privately held computer security company. The company is among the top four security providers in the world*. Throughout its 16-year history, Kaspersky Lab has been pioneering security innovations, providing cost-effective solutions to protect consumers, small and medium-sized businesses and large enterprises. Today, Kaspersky Lab operates in 200 countries and regions around the world, providing online security to over 300 million users. For more information, visit: www.kaspersky.com .

  • Based on IDC’s “Worldwide Endpoint Security Revenue by Vendor” ranking for 2012. Ranking included in IDC’s “Worldwide Endpoint Security 2013–2017 Forecast and 2012 Vendor Shares” report (IDC #235930, August 2013). The report included a ranking of software vendors based on revenue from sales of computer security solutions in 2012.

Digital threats_Q1 2014

 

Kaspersky Contact

Konstantinos Memos
Advocate/ Burson-Marsteller
210 6931000
kmemmos@advocate-bm.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS