Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

2/7/2017
09:00 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Point-of-Sale Malware Declined 93% Since 2014

SonicWall study highlights alarming growth in ransomware incidents.

Science dictates that for every action there's a reaction.

That's one of the main points of a new SonicWall study, which reports a 93% decline in point-of-sale (PoS) malware creation since 2014, but counters that news with a reality-check that ransomware grew by a rate of 167 times year-over-year.

The study, conducted by the SonicWall Global Response Intelligent Defense (GRID) Threat Network, found that ransomware was the payload of choice for malicious email campaigns and exploit kits. Ransomware attack attempts went from 4 million in 2015 to a staggering 638 million last year.

"It's pretty clear that the move to chip-and-PIN credit cards decreased PoS malware over the past couple of years," says Dmitriy Ayrapetov, executive director of product development at SonicWall. "This is a dramatic drop compared to 2014, which was the high point of PoS malware, the time that top retailers like Target, Home Depot, and Staples were hit with massive data breaches."

Ayrapetov adds that cybercriminals go where the money is, and during the last year, ransomware has become a very profitable business.

"With ransomware, attackers can hit both small and large businesses," Ayrapetov says. "And it's a lot less risky, since the attackers get paid in bitcoins and don't have to use a credit card. Also, the emergence of ransomware-as-a-service has reduced the barrier to entry, [so] anybody can purchase ransomware-as-a-service now."

The SonicWall study also found that SSL/TLS traffic grew by 38% last year, partly due to the growth in cloud application adoption. But yet again, the increase in SSL/TLS traffic has created another flaw: an uninspected backdoor into the network that cybercriminals can potentially exploit.

"Companies now need to look inside the network and inspect and protect encrypted traffic," says Mike Spanbauer, vice president of security, test & advisory at NSS Networks, which had an early briefing on the SonicWall report. "It's really not terribly difficult to make money spreading ransomware. You can now get service agreements. It’s really scary how accomplished a business model they have."

Other findings of the SonicWall study:

On the plus side: Dominant exploit kits, Angler, Nuclear, and Nutrino disappeared in mid-2016; unique malware samples fell to 60 million in 2016 compared with 64 million in 2015, a 6.25% decrease, while total attack attempts dropped to 7.87 billion in 2016, down from 8.19 billion in 2015.

On the minus side: IoT devices were compromised on a massive scale, leading to numerous DDoS attacks, most notably, the attack on DNS provider Dyn last fall; Android devices saw increased security protections, but remained vulnerable to overlay attacks.

The SonicWare GRID Threat Network is based on more than 1 million sensors placed in more than 200 countries and territories. The GRID Threat Network monitors traffic 24x7x365, developing its analysis on more than 100,000 malware samples collected daily. 

Related Content:

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Latest Comment: Exactly
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4643
PUBLISHED: 2020-09-21
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
CVE-2020-4590
PUBLISHED: 2020-09-21
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
CVE-2020-4731
PUBLISHED: 2020-09-21
IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188055.
CVE-2020-4315
PUBLISHED: 2020-09-21
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the i...
CVE-2020-4579
PUBLISHED: 2020-09-21
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.