Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


09:05 AM
Connect Directly

Enterprise Malware Detections Up 79% as Attackers Refocus

A new report on the state of malware shows a spike in B2B malware, with former banking Trojans Emotet and TrickBot topping the list.

Enterprise threats ramped up toward the end of 2018 as cybercriminals shifted their strategies to hit business victims with unpatched, insecure networks – and found plenty of targets.

That's one of the key findings from Malwarebytes Labs' "State of Malware Report 2019," which analyzes threats from January through November 2018 and compares them with the same period from 2017. After cryptomining exploded near the end of 2017, the next year began with attackers broadening their strategies to hit Mac and Android devices and use browser-based threats.

But cryptomining began to slow down by the second quarter of 2018, researchers report, and a new set of attacks took its place. Former banking Trojans Emotet and TrickBot evolved into droppers with several modules for spam production, network propagation, and data skimming. New malware variants targeted the enterprise, hunting sensitive data they could sell for profit.

Criminals have historically gone after consumers, says Malwarebytes CEO Marcin Kleczynski, but the past year has shown they've found value in targeting the enterprise. One corporate login can grant them access to troves of far more valuable information, and it's not hard to get.

A Pivot Toward the Enterprise
Most attackers don't plan to hit specific companies, Kleczynski points out. They start by casting a wide net, conducting online research to see who's most vulnerable, then pursuing them. Business malware detections rose 79% over the last year, report Malwarebytes researchers, who link the rise to an increase in backdoors, miners, spyware, and information stealers.

While 2017 can be considered the year of global outbreaks – WannaCry and NotPetya made sure of it – 2018 was the "year of the mega breach." Attackers hit major corporations, including Facebook, Marriott, Exactis, MyHeritage, and Quora, affecting hundreds of millions of customers and driving the numbers of compromised records up 133% compared with 2017.

Companies may worry about becoming the next Marriott, Kleczynski says, but most of the attacks Malwarebytes sees aren't the big ones. Many businesses are affected with popular strains of malware like Emotet, which he explains is "going around like the flu." Trojan detections were up 132%, a rise led by the prevalence of the Emotet, which, like other info-stealing malware, uses exploits to move across corporate networks and brute-forces credentials.

Backdoors increased 173% among enterprise victims, spyware was up 142%, and RiskwareTool rose by 126%, researchers report. They attribute the rise in spyware to similar variants and families of Emotet and TrickBot being identified as spyware in the wild – a sign attackers have focused on information stealing and creating footholds in corporate networks, they explain.

Common attack vectors like spam "work so well" on business victims, Kleczynski says. "At the end of the day, it's still very common to spread an attack like Emotet," he adds, just by getting more people to click on a malicious email. It doesn't help that company websites and platforms like LinkedIn expose useful information (full names, job titles) that help make attacks targeted.

Emotet and Trickbot topped the threats of 2018 and found success in malspam, a technique that disguises the threats as a legitimate email. What made their attacks successful was how they spread.For Emotet, this meant infected attachments and embedded URLs, with social engineering tactics designed to make targets believe messages come from trusted sources.

While businesses saw more malware detections, consumers saw fewer. In 2017, there were 775,327,346 consumer detections, Malwarebytes reports. The most recent year brought about 25 million fewer instances and a 3% decline – "a healthy decrease," percentages aside.

"Always, at the end of the day, [it's] around money and the value of some of these assets," Kleczynski says of cyberattackers eyeing enterprise data. "I would claim that credit card and Social Security and passport numbers aren't as valuable as they were 10 years ago."

Ransomware: It's Complicated
Toward the end of 2017, security experts predicted the cryptomining crazy would continue. Indeed, 2018 brought the decline of ransomware and rise of cryptominers, following a spike in Bitcoin value at the end of 2017. Criminals seeking financial gain jumped on the trend, hitting Mac, Windows, and Android devices with software- and browser-based cryptomining attacks.

However, cryptomining only increased 7% last year as the second half of 2018 brought its decline. It's still one of the major malware trends of 2018, but the drop in cryptocurrency value has slowed it down. "Bitcoin losing more than 80% of its value over the last year has led cybercriminals to pivot," Kleczynski explains.

As the trend lagged, cybercriminals shifted their ransomware techniques from malvertising exploits and ransomware payloads to manual, targeted ransomware attacks. While it's not the wide-ranging threat it was in 2017, it's still a threat to keep in mind. Trends show an increase in focused, sophisticated attacks geared toward the enterprise and lack of interest in consumers.

Businesses, unlike individuals, have the potential funds to pay a ransom and several pressing reasons to get back up and running after a ransomware attack. Delays caused by ransomware can be incredibly expensive, researchers say, especially when the victim has a wealth of infected endpoints and no backup plan in place. Incident response is costlier than paying up.

SamSam, which hit the city of Atlanta and medical organizations across the US in 2018, was revamped to charge victims a more moderate price compared with recovery methods that businesses would otherwise have to pay. The change led to operators making more overall. GandCrab, the top ransomware variants of Q2 2018, adopted the Magnitude exploit kit, which plagued network admins and home users with its unusual malware-loading method.

High Risk Meets Few Resources
Kleczynski says many companies have stepped up their security game despite struggling with a lack of resources. Despite attacks over the past decade, he says, the pressure on security teams to request sufficient resources from their organizations is still relevant. In the education and state/local government sectors, for example, budgets are a significant concern.

"It's interesting to see companies doing what they can with as little as they have," he says.

Security-focused conversations are also making their way to the board, where execs are concerned about being hit with the next major breach. "I think the weight of the topic is significant," he adds. It's especially difficult for companies with small security teams, which struggle to cover every aspect of security with few people. Open source software, free tools, and outsourcing have helped drive security efforts, Kleczynski adds.

Read the report here.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Latest Comment: Exactly
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are...
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from versio...
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from...
PUBLISHED: 2020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
PUBLISHED: 2020-09-19
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our secu...