Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

11/25/2019
11:20 AM
50%
50%

They See You When You're Shopping: Holiday Cybercrime Starts Early

Researchers notice year-end phishing attacks starting in July and ramping up in September.

It seems the holiday season starts earlier every year. This trend extends to the world of cybercrime, where this year attackers started to ramp up malicious year-end activity as early as July. By September, phishing URL detections were up over 2.5 times compared with 2018.

The period between September and December is "the most active malware season of the year," reports the Avira Protection Lab. Researchers charted a 61% increase in phishing during the 2018 holiday shopping season. This year, the seasonal activity started earlier, and it's moving faster and growing more diverse as attackers map new campaigns for both mobile and desktop devices.

Android, the most common mobile OS, is the most frequently targeted, researchers report. The amount of Android malware typically intercepted, which mostly includes banking Trojans, climbs 50% during the holiday shopping season. The Android/Banker, specifically, climbs 17.5%.

Criminals can distribute a wide variety of malware with a simple WhatsApp message: "Click here to receive the latest Black Friday coupons" may arrive with a link to a new coupon app, researcher say as an example. Banking Trojans, premium SMS fraud, and adware are most commonly delivered in scams like this. Trojans such as the new ExoBot variant have dynamic overlays to collect payment card data and other banking data, such as PIN codes, they say.

Some free coupon apps — for example, Black Friday Ads 2019 — toe the line between adware and traditional ad-supported apps. Researchers advise shoppers to stick with official apps and app stores and, even then, read the reviews and review permissions before downloading.

Read more details here.

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "In the Market for a MSSP? Ask These Questions First"

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Concrete ContractorsC463
50%
50%
Concrete ContractorsC463,
User Rank: Apprentice
1/7/2020 | 6:26:22 AM
Re: They See You When You're Shopping: Holiday Cybercrime Starts Early
This is iso true. I received a lot of phishing messages last black Friday. Good thing I have a techy wife.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17478
PUBLISHED: 2020-08-10
ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.
CVE-2020-15648
PUBLISHED: 2020-08-10
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
CVE-2020-15649
PUBLISHED: 2020-08-10
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR...
CVE-2020-15650
PUBLISHED: 2020-08-10
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Fir...
CVE-2020-15651
PUBLISHED: 2020-08-10
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.