Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
4/18/2017
11:00 AM
Malwarebytes Labs
Malwarebytes Labs
Partner Perspectives
50%
50%

Cybercrime Tactics & Techniques: Q1 2017

A deep dive into the threats that got our attention during the first three months of the year - and what to expect going forward.

The first quarter of 2017 brought with it some significant changes to the threat landscape, and we aren’t talking about heavy ransomware distribution either.

In our second Cybercrime Tactics & Techniques report. (Read the first one here.), we take a deep dive into what threats got our attention the most during the first three months of the year, what we expect to happen moving through the next quarter, and a behind the scenes interview with one of our Malwarebytes Labs analysts. Here is a sneak peek at what’s in the report.

  • Cerber ransomware took over as top dog with respect to distribution and market share.
  • Locky ransomware has dropped off the map, likely due to the desired change by the controllers of the Necurs spam botnet. However, with a lack of new Locky versions being developed since before the beginning of the year, the fate of its creators are unknown.
  • The Mac threat landscape saw a surge of new malware and backdoors in Q1 2017, including a new Mac ransomware (FindZip).
  • On the Android side, two notable malware families have been causing a lot of trouble: HiddenAds.lck, which locks the device from being able to remove the app, therefore allowing for more advertisement revenue for the creators, and Jisut, a mobile ransomware family that has been spreading like wildfire.
  • In the exploit kit world, RIG continues to have the greatest market share of the few exploit kits that are still active, and we expect this to continue. RIG exploit kit remains on top mainly due to its lack of competition rather than its technical sophistication.
  • Malicious spam campaigns have also started utilizing password protected zipped files and protected Office documents to evade auto analysis sandboxes utilized by security researchers.
  • In social media scams, users were bombarded with links to WWE nude photo dumps that lead to gift card survey scams.
  • Tech support scammers, finding difficulty working with North American payment processors, have begun accepting alternate forms of payment, such as Apple gift cards and bitcoin.

Looking ahead to the second quarter of the year:

  • We expect to see continued heavy distribution of Cerber through Q2 2017 due to new developments made to the malware design, and its continued use of the ransomware as a service (RaaS) model.
  • As far as Cerber losing its crown, it is unlikely within the next quarter that any competitor will rise in market share enough to dethrone Cerber, barring something happening to the developers of Cerber, and their ability to develop and distribute the ransomware.
  • The continued heavy development of Mac malware throughout Q2 is highly likely.
  • The Android ransomware Jisut is expected to continue its trend of high distribution and spread. We predict the same for HiddenAds.lck.
  • Distribution mechanisms are likely going to develop new features and functionality, be it through social engineering tactics utilized by exploit kits and malicious spam or from the discovery of new exploits, potentially revitalizing the exploit kit market.
  • Finally, in the world of scams, we expect to see an uptick of ‘exit scams’ and tech support scammers utilizing social media advertising to scam each other. At the same time, we predict the increase collaboration of PUPs and TSS through the spread of tech support scammer advertisements being pushed alongside potentially unwanted programs.

Download the full Cybercrime Tactics & Techniques report here.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
3 Ways to Retain Security Operations Staff
Oliver Rochford, Vice President of Security Evangelism at DFLabs,  11/20/2017
A Call for Greater Regulation of Digital Currencies
Kelly Sheridan, Associate Editor, Dark Reading,  11/21/2017
New OWASP Top 10 List Includes Three New Web Vulns
Jai Vijayan, Freelance writer,  11/21/2017
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
Malwarebytes protects businesses against malicious threats that escape detection by traditional antivirus solutions. Malwarebytes Anti-Malware, the companys flagship product, has a highly advanced heuristic detection engine that has removed more than five billion malicious threats from computers worldwide. SMBs and enterprise businesses worldwide trust Malwarebytes to protect their data. Founded in 2008, the company is headquartered in California with offices in Europe, and a global team of researchers and experts. For more information, please visit us at www.malwarebytes.com/business.
Featured Writers
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Managing Cyber-Risk
An online breach could have a huge impact on your organization. Here are some strategies for measuring and managing that risk.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.