{"id":30558,"date":"2017-12-20T12:44:22","date_gmt":"2017-12-20T04:44:22","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=30558"},"modified":"2017-12-20T12:44:22","modified_gmt":"2017-12-20T04:44:22","slug":"mcafee-labs-report-sees-known-exploits-and-fileless-malware-drive-record-new-malware-surge","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/12\/20\/mcafee-labs-report-sees-known-exploits-and-fileless-malware-drive-record-new-malware-surge\/","title":{"rendered":"McAfee Labs report sees known exploits and fileless malware drive record new malware surge"},"content":{"rendered":"<p><strong>McAfee released its\u00a0<em>McAfee Labs Threat Report: December 2017<\/em>, examining the growth and trends of new malware, ransomware, and other threats in Q3 2017. McAfee Labs saw malware reach an all-time high of 57.6 million new samples\u2014four new samples per second\u2014featuring developments such as new fileless malware using malicious macros, a new version of Locky ransomware dubbed Lukitus, and new variations of the banking Trojans Trickbot and Emotet.<\/strong><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/08\/security.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-29420 size-full\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/08\/security.jpg\" alt=\"\" width=\"622\" height=\"432\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/08\/security.jpg 622w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/08\/security-300x208.jpg 300w\" sizes=\"auto, (max-width: 622px) 100vw, 622px\" \/><\/a><\/p>\n<p>Threats attempting to exploit Microsoft technology vulnerabilities were very prominent despite the fact that the platform vendor addressed these issues with patches as early as the first quarter of 2017.<\/p>\n<p>\u201cThe third quarter revealed that attackers\u2019 threat designs continue to benefit from the dynamic, benign capabilities of platform technologies like PowerShell, a reliable recklessness on the part of individual phishing victims, and what seems to be an equally reliable failure of organizations to patch known vulnerabilities with available security updates,\u201d said Raj Samani, McAfee\u2019s chief scientist. \u201cAlthough attackers will always seek ways to use newly developed innovations and established platforms against us, our industry perhaps faces a greater challenge in the effort to influence individuals and organizations away from becoming their own worst enemies.\u201d<\/p>\n<p>Each quarter, McAfee Labs assesses the state of the cyber threat landscape based on threat data gathered by the McAfee Global Threat Intelligence cloud from hundreds of millions of sensors across multiple threat vectors around the world. McAfee Advanced Threat Intelligence complements McAfee Labs by providing in-depth investigative analysis of cyberattacks from around the globe.<\/p>\n<p><strong>Known Vulnerabilities Exploited<\/strong><\/p>\n<p>The third quarter of 2017 saw cybercriminals continue to take advantage of Microsoft Office vulnerabilities such as CVE-2017-0199, which took advantage of a vulnerability within both Microsoft Office and WordPad to allow remote code execution through specially crafted files. To execute this attack, many took advantage of a tool available via GitHub offering an easy route to creating a backdoor attack without complex configuration.<\/p>\n<p>New variations of the Trickbot banking Trojan featured code that embedded the EternalBlue exploit responsible for the massive WannaCry and NotPetya ransomware outbreaks in Q2. Despite Microsoft\u2019s continued efforts to counter EternalBlue with security patches, the new Trickbot authors still found the proven technique to be effective. They combined it with new features such as cryptocurrency theft and new delivery methods, and made these new Trickbot versions the most active banking Trojans in Q3.<\/p>\n<p>\u201cOnce vulnerabilities are discovered and disclosed \u2018into the wild,\u2019 or the hacker community, they present a blueprint for malicious parties seeking to develop sophisticated threats that exploit them,\u201d said Steve Grobman, CTO at McAfee. \u201cThe year 2017 will be remembered as the time when such vulnerabilities were exploited to orchestrate large-scale cyber events, including the WannaCry and NotPetya ransomware outbreaks, and high-profile breaches such as at Equifax. Only by investing more in the discovery and remediation of cyber vulnerabilities can technology vendors, governments, and business enterprises hope to gain a step on the cybercriminals working furiously to uncover and take advantage of them.\u201d<\/p>\n<p><strong>Fileless Threats<\/strong><\/p>\n<p>Fileless threats continued to be a growing concern in Q3, with PowerShell malware growing by 119%. Very prominent in this category was the Emotet banking Trojan, which spread around the world through large spamming campaigns, and lured users into downloading Microsoft Word documents. This act inadvertently activates a PowerShell macro that downloads and installs the malware on their systems.<\/p>\n<p>\u201cAlthough many cyberattacks continue to rely on the exploitation of basic security vulnerabilities, exposures, and user behaviors, fileless threats leverage the utility of our own system capabilities,\u201d said Vincent Weafer, Vice President for McAfee Labs. \u201cBy leveraging trusted applications or gaining access to native system operating tools such as PowerShell or JavaScript, attackers have made the development leap forward to take control of computers without downloading any executable files, at least in the initial stages of the attack.<\/p>\n<p><strong>Lukitus Ransomware<\/strong><\/p>\n<p>One of the key developments in the ransomware space was the emergence of Lukitus, a new version of Locky ransomware. The ransomware was distributed by more than 23 million spam emails within the first 24 hours of the attack. Overall in the category,\u00a0new ransomware samples increased by 36%. The number of total ransomware samples has grown 44% in the past four quarters to 12.3 million samples.<\/p>\n<p><strong>DragonFly: New Industries, New Objectives<\/strong><\/p>\n<p>The McAfee Advanced Threat Research team found that DragonFly 2.0, the malware discovered earlier in 2017 in the energy sector, has targeted organizations beyond original discoveries, including the pharmaceutical, financial services, and accounting industries. These attacks were initiated through spear-phishing emails, luring recipients to click on links that download the Trojan and provide attackers with network access.<\/p>\n<p>\u201cThe actors involved in the DragonFly 2.0 attacks have a reputation for initiating attacks for the purpose of conducting reconnaissance on the inner workings of targeted sectors\u2014with energy and pharmaceutical confirmed as top priorities,\u201d said Christiaan Beek, McAfee Lead Scientist and Principal Engineer. \u201cThe intellectual property and insider insights they obtain upon gaining access to targeted sectors is of tremendous economic value.\u201d<\/p>\n<p><strong>Q3 2017 Threat Activity<\/strong><\/p>\n<p>Security incidents.\u00a0McAfee Labs counted 263 publicly disclosed security incidents in Q3, a decrease of 15% from Q2. More than 60% of all publicly disclosed security incidents in Q3 took place in the Americas.<\/p>\n<p>Vertical industry targets.\u00a0The health and public sectors accounted for more than 40% of total incidents in Q3.<\/p>\n<ul>\n<li>North America.\u00a0Health sector attacks continued to lead vertical sectors in Q3 security incidents.<\/li>\n<li>Asia.\u00a0Public sector, followed by technology and individual attacks led in reported Q3 incidents.<\/li>\n<li>Europe, Oceana and Africa.\u00a0Public sector attacks led reported Q3 incidents.<\/li>\n<\/ul>\n<p>Attack vectors.\u00a0Account hijacking led disclosed attack vectors, followed by leaks, malware, DDoS, and targeted attacks.<\/p>\n<p>Mobile malware.\u00a0Total mobile malware continued to grow, reaching 21.1 million samples. New mobile malware increased by 60% from Q2, largely due to a rapid increase in Android screen-locking ransomware.<\/p>\n<p>Malware overall.\u00a0New malware samples increased in Q3 to 57.5 million, a 10% increase. The total number of malware samples grew 27% in the past four quarters to almost 781 million samples.<\/p>\n<p>Fileless malware.\u00a0While JavaScript malware growth slowed by 26% in Q3, PowerShell malware more than doubled with 119%.<\/p>\n<p>Ransomware.\u00a0New ransomware samples rose by 36% in Q3. The total number of new ransomware samples grew 14% in the last quarter to 12.2 million samples.<\/p>\n<p>Mac malware.\u00a0Mac OS malware samples increased by 7% in Q3.<\/p>\n<p>Macro malware.\u00a0Total macro malware continued to grow, increasing by 8% in Q3.<\/p>\n<p>Spam campaigns.\u00a0The Gamut botnet remains the most prevalent spamming botnet during Q3, with the Necurs botnet a close second. Necurs proliferated several Ykcol (Locky) ransomware campaigns throughout the quarter with themese such as \u201cStatus Invoice,\u201d \u201cYour Payment,\u201d and \u201cEmailing: [Random Numbers] JPG.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>McAfee Labs saw malware reach an all-time high of 57.6 million new samples\u2014four new samples per second\u2014featuring developments such as new fileless malware using malicious macros, a new version of Locky ransomware dubbed Lukitus, and new variations of the banking Trojans Trickbot and Emotet.<\/p>\n","protected":false},"author":6,"featured_media":29420,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[5684,5682,5681,103,391,1591,54,5683],"class_list":["post-30558","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-emotet","tag-locky","tag-lukitus","tag-malware","tag-mcafee","tag-ransomware","tag-security","tag-trickbot"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30558","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=30558"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30558\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/29420"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=30558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=30558"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=30558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}