In 2014, which will give way to the new year in a few days, users of computers and Android mobile phones/tablets experienced a lot of attacks from all kinds of viruses, Trojans and malware. The most important trends that will concern cyberspace in 2015 werepredicted and presented in summary by ESET: these main points will be analyzed in more detail in the ESET “Cybercrime Trends & Predictions 2015”. While last year the interest was focused on ensuring privacy on the Internet and on malware targeting Android, in 2015 new areas are emerging as important, due to the risks they pose for IT security.
Increase in targeted attacks
Targeted attacks will continue to become more sophisticated in 2015. Often referred to as “APT” (Advanced Persistent Threats), attacks are differentiated from traditional cyberthreats in that, being designed to target specific victims and being silent, targeted attacks can often lurk undetected in less secure networks.
“The attack method in these targeted cases is usually through the exploitation of social engineering attacks,” said Pablo Ramos, Head of Research Lab at ESET Latin America. “In such cases, psychological manipulation is used to motivate potential victims to perform actions or reveal confidential information. Attacks can also take the form of zero-day exploits, in which newly discovered vulnerabilities in a specific Operating System or application are exploited.”
During 2014, ESET's "We Live Security" blog published a series of detailed analyses of targeted attacks, such as the "BlackEnergy Campaign" and "Operation Windigo.".
Digital payment systems attract more malware
“As users start to adopt online payment systems as a means of paying for services and goods, these systems become a magnet for malware creators who are interested in making a profit,” adds Ramos. In 2014, the largest attack known to date in the digital payments sector occurred, earning the cybercriminal more than 600,000 US dollars in digital currencies “Bitcoin” and Dogecoins, using a network of infected machines.
In May, ESET reported on the attacks against the Dogevault website, in which users of the popular e-wallet reported unauthorized withdrawals from their accounts, until the website was forced to shut down when the attackers destroyed its data. It is estimated that 56,000 US dollars were stolen from Dogevault e-wallet users.
There have also been brute force attacks, such as “Win32/BrutPOS,” which attempted to gain access to password-protected accounts by using popular passwords to gain remote access, reminding us all of the need to use strong, unique passwords.
Internet of Things – new games for hackers
As new devices connect to the Internet and store more data, they also become an attractive target for cybercriminals. In 2014, more cases of this growing trend appeared, such as attacks on exhibition vehicles at the Defcon conference using their brains, or the Tesla vehicle that was hacked and its doors opened while it was in motion.
Attacks and incidents that verify this theory have also occurred on several SMART TVs, Boxee TV devices, biometric systems on smartphones, routers, and even Google glasses.
“This is an emerging area for cybercrime and the security industry should focus its attention,” added Camilo Gutierrez, Senior Security Researcher at ESET Latin America. “Although it will take years for it to become a significant threat of this magnitude, we need to act now to prevent these types of attacks.”
Source: zougla.gr




