These findings are part of the latest Fortinet Global Threat Landscape Report*, which also says:
Evolving attack methods
Cybercriminals are getting better and more sophisticated in their use of malware, and leveraging newly-announced zero-day vulnerabilities to attack at speed and scale. While the number of exploit detections per firm dropped by 13% in Q118, the number of unique exploit detections grew by over 11%, and 73% of companies experienced a severe exploit.
![]() |
| Source: Fortinet infographic. Cyberattacks are increasingly targeted at specific victims. |
![]() |
| Source: Fortinet infographic. Cryptojacking is the new up-and-coming malware. |
Spike in cryptojacking
Malware is evolving and becoming more difficult to prevent and detect. The prevalence of cryptomining malware more than doubled from quarter to quarter, growing from 13% to 28%. Additionally, cryptojacking was quite prevalent in the Middle East.
Cryptomining malware is also showing incredible diversity for such a relatively new threat. Cybercriminals are creating stealthier fileless malware to inject infected code into browsers with less detection. Fileless malware does not need to save a file on the hard disk to cause problems, and often escapes detection because a lot of cybersecurity solutions check files instead of looking elsewhere for the malware.
Miners are also targeting multiple operating systems as well as different cryptocurrencies, including Bitcoin, Dash, and Monero. They are additionally finetuning and adopting delivery and propagation techniques from other threats based on what was successful or unsuccessful to improve future success rates.
Targeted attacks
The impact of destructive malware remains high, particularly as criminals combine it with designer attacks. For these types of more targeted attacks, criminals conduct significant reconnaissance on an organisation before launching an attack, which helps them to increase success rates. Once they penetrate the network, attackers spread laterally across the network before triggering the most destructive part of their planned attack.
The Olympic Destroyer malware and the more recent SamSam ransomware are examples of where cybercriminals combined a designer attack with a destructive payload for maximum impact.
Ransomware continues to disrupt
The growth in both the volume and sophistication of ransomware continues to be a significant security challenge for organisations. Ransomware continues to evolve, leveraging new delivery channels such as social engineering, and new techniques such as multistage attacks to evade detection and infect systems.
GandCrab ransomware emerged in January with the distinction of being the first ransomware to require Dash cryptocurrency as a payment. BlackRuby and SamSam were two other ransomware variants that emerged as major threats during the first quarter of 2018.
Multiple attack vectors
Although the side channel attacks dubbed Meltdown and Spectre dominated the news headlines during the quarter, some of the top attacks targeted mobile devices or known exploits on router, web or Internet technologies. Two in 10 (21%) organisations reported mobile malware, up 7%, demonstrating that Internet of Things (IoT) devices continue to be targeted.
Cybercriminals also continue to recognise the value of exploiting known vulnerabilities that haven’t been patched along with recently discovered zero-days for increased opportunity. Microsoft continued to be the number one target for exploits, and routers took the number two spot in total attack volume. Content management systems (CMS) and web-oriented technologies were also heavily targeted.
Cyberhygiene
Measuring how long botnet infections persist based on the number of consecutive days in which continued communications are detected reveals that hygiene involves more than just patching. It is also about cleanup.
Data showed that 58.5% of botnet infections are detected and cleaned up the same day. However, 17.6% of botnets persist for two days in a row and 7.3% last three days. About 5% persist for more than a week. As an example, the Andromeda botnet was taken down in Q417 but data from Q1 found it continued to show up prominently in both volume and prevalence.
Attacks on operational technology (OT)
While OT attacks are a smaller percentage of the overall attack landscape, this sector is increasingly becoming connected to the Internet, with potentially serious ramifications for security. Currently, the vast majority of exploit activity is directed against the two most common industrial communication protocols, primarily because they are so widely deployed. Data shows that in Asia industrial control system (ICS) exploit attempts appear to be somewhat more prevalent when compared to ICS exploit activity across other regions.
Gavin Chow, Network and Security Strategist, Fortinet Asia Pacific said, “In the Asia Pacific (APAC) region, exploits targeting known vulnerabilities in enterprise web systems running Apache Struts (CVE-2017-5638), Oracle WebLogic Server (CVE-2017-10271, CVE-2017-3506) and older IIS 6.0 web servers (CVE-2017-7269) were the most prevalent in Q118.
"This is followed closely by exploits targeting old vulnerabilities in IoT devices such as Linksys and D-Link home routers.
"Cryptojacking malware continues to be popular, with JavaScript variants joining the top 10 most prevalent in the APAC region. Other malware coded in JavaScript and Microsoft Office Visual Basic for Applications (VBA) macros are also highly prevalent, followed by malware leveraging on a known Microsoft Office exploit (CVE 2017-11882) that is used to gain control of a victim's system to perform other malicious activity.
"The Gh0st.RAT botnet (popular in countries with a large Chinese speaking population) continue to be prevalent in APAC, even though this botnet has been around for almost 10 years since it first surfaced back in 2008. This is followed by the Andromeda botnet, even though the Andromeda botnet infrastructure was already taken down in Q417.
"Another interesting observation we noticed is that exploit attempts on critical infrastructure such as ICS appear to be more prevalent in Asia when compared to other regions. The key takeaway here is that attackers are actively looking for low-hanging fruit targeting known vulnerabilities. These known vulnerabilities already have fixes available and system owners who are not aware of these risks would continue to be exposed to these attacks.”
Fortinet suggests that the best defense against intelligent and automated threats is an integrated, broad, and automated security fabric. A highly aware and proactive security defense system is needed to keep pace with the next generation of automated and AI-based attacks, the company said.
Peerapong Jongvibool, Fortinet’s Regional Director for Southeast Asia and Hong Kong said, “We face a troubling convergence of trends across the cybersecurity landscape. Malicious cyber actors are demonstrating their efficiency and agility by exploiting the expanding digital attack surface, taking advantage of newly announced zero-day threats, and maximising the accessibility of malware for bad intent. In addition, IT and OT teams often don’t have the resources necessary to keep systems appropriately hardened or protected. However, implementing a security fabric which prioritises speed, integration, advanced analytics, and risk-based decision making can enable comprehensive protection at machine speed and scale.”


No comments:
Post a Comment