{"id":33030,"date":"2018-09-05T12:02:35","date_gmt":"2018-09-05T04:02:35","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=33030"},"modified":"2018-09-05T12:02:35","modified_gmt":"2018-09-05T04:02:35","slug":"iot-devices-at-homes-are-latest-target-for-cryptojacking","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/09\/05\/iot-devices-at-homes-are-latest-target-for-cryptojacking\/","title":{"rendered":"IoT devices at homes are latest target for cryptojacking"},"content":{"rendered":"<p><strong>Fortinet announced the findings of its latest\u00a0<span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/threat-landscape-report--virtually-no-firm-is-immune-from-severe.html\" target=\"_blank\" rel=\"nofollow noopener\">Global Threat Landscape Report<\/a><\/span>. The research reveals cyber criminals are becoming smarter and faster in how they leverage exploits to their advantage. They are also maximizing their efforts by targeting an expanding attack surface and by using iterative approaches to software development facilitating the evolution of their attack methodologies.<\/strong><\/p>\n<p>Highlights of the report follow:<\/p>\n<ul>\n<li><b><i><span lang=\"EN-US\">Virtually No Firm is Immune from Severe Exploits:\u00a0<\/span><\/i><\/b><span lang=\"EN-US\">Analysis focused on critical and high-<\/span><span lang=\"EN-US\">severity detections demonstrates an alarming trend with 96% of firms experiencing at least one severe exploit. Almost no firm is immune to the evolving attack trends of cyber criminals. In addition, nearly a quarter of companies saw cryptojacking malware, and only six malware variants spread to over 10% of all organizations. FortiGuard Labs also found 30 new zero-day vulnerabilities during the quarter.<\/span><u><\/u><u><\/u><\/li>\n<li><b><i><span lang=\"EN-US\">Cryptojacking Moves to IoT Devices in the Home:<\/span><\/i><\/b><i><span lang=\"EN-US\">\u00a0<\/span><\/i><span lang=\"EN-US\">Mining for cryptocurrency continues, cyber criminals\u00a0<\/span><span lang=\"EN-US\">added IoT devices, including media devices in the home to their arsenals. They<\/span><span lang=\"EN-US\">\u00a0are an\u00a0<\/span><span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><span lang=\"EN-US\"><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/hide--n-seek--from-home-routers-to-smart-home-insecurities.html\" target=\"_blank\" rel=\"nofollow noopener\">especially attractive target<\/a><\/span><\/span><span lang=\"EN-US\">\u00a0because of\u00a0<\/span><span lang=\"EN-US\">their rich source of computational horsepower, which can be used for malicious purposes.\u00a0<\/span><span lang=\"EN-US\">Attackers are taking advantage of them by loading malware that is continually mining because these devices are always on and connected. In addition, the interfaces for these devices are being exploited as modified web browsers, which expands the vulnerabilities and exploit vectors on them. Segmentation will be increasingly important for devices connected to enterprise networks as this trend continues.<\/span><u><\/u><u><\/u><\/li>\n<li class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoListParagraphCxSpLast\"><b><i><span lang=\"EN-US\">Botnet Trends Demonstrate the Creativity of Cyber Criminals:\u00a0<\/span><\/i><\/b><span lang=\"EN-US\">Data on botnet trends gives a valuable post-compromise viewpoint of how cybercriminals are maximizing impact with multiple malicious actions.\u00a0<\/span><span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><span lang=\"EN-US\"><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/a-wicked-family-of-bots.html\" target=\"_blank\" rel=\"nofollow noopener\">WICKED<\/a><\/span><\/span><span lang=\"EN-US\">, a new Mirai botnet variant, added at least three exploits to its arsenal to target unpatched IoT devices.\u00a0<\/span><span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><span lang=\"EN-US\"><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/defending-against-the-new-vpnfilter-botnet.html\" target=\"_blank\" rel=\"nofollow noopener\">VPNFilter<\/a><\/span><\/span><span lang=\"EN-US\">, the advanced nation-state-sponsored attack that targets SCADA\/ICS environments by monitoring MODBUS SCADA protocols, emerged as a significant threat. It is particularly dangerous because it not only performs data exfiltration, but can also render devices completely inoperable, either individually or as a group. The Anubis variant from the Bankbot family introduced several innovations. It is capable of performing ransomware, keylogger, RAT functions, SMS interception, lock screen, and call forwarding. Keeping tabs of morphing attacks with actionable threat intelligence is vital as creativity expands.<u><\/u><u><\/u><\/span><\/li>\n<li class=\"yiv5038476695MsoNormal\"><u><\/u>\u00a0<b><i><span lang=\"EN-US\">Malware Developers Leverage Agile Development:<\/span><\/i><\/b><i><span lang=\"EN-US\">\u00a0<\/span><\/i><span lang=\"EN-US\">Malware authors have long relied on\u00a0<\/span><span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><span lang=\"EN-US\"><a href=\"https:\/\/www.fortinet.com\/blog\/business-and-technology\/fortinet-fortiguard-2018-threat-landscape-predictions.html\" target=\"_blank\" rel=\"nofollow noopener\">polymorphism<\/a><\/span><\/span><span lang=\"EN-US\">\u00a0to evade detection. Recent attack trends show they are turning to agile development practices to make their malware even more difficult to detect and to counter the latest tactics of anti-malware products.\u00a0<\/span><span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><span lang=\"EN-US\"><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/gandcrab-v4-0-analysis--new-shell--same-old-menace.html\" target=\"_blank\" rel=\"nofollow noopener\">GandCrab<\/a><\/span><\/span><span lang=\"EN-US\">\u00a0had many new releases this year, and its developers continue to update this malware at a rapid pace. While automation of malware attacks presents new challenges, so does agile development because of the skills and processes to roll out new evading releases of attack methods.\u00a0<\/span><span lang=\"EN-US\">To keep pace with the agile development cyber criminals are employing, organizations need advanced threat protection and detection capabilities that help them pinpoint these recycled vulnerabilities.<u><\/u><u><\/u><\/span><\/li>\n<li class=\"yiv5038476695MsoNormal\"><u><\/u>\u00a0<b><i><span lang=\"EN-US\">Effective Targeting of Vulnerabilities:<\/span><\/i><\/b><i><span lang=\"EN-US\">\u00a0<\/span><\/i><span lang=\"EN-US\">Adversaries are selective in determining what vulnerabilities they target. With exploits examined from the lens of prevalence and volume of related exploit detections, only 5.7% of known vulnerabilities were exploited in the wild. If the vast majority of vulnerabilities won<\/span><span lang=\"EN-US\">\u2019t be exploited, organizations should consider taking<\/span><span lang=\"EN-US\">\u00a0a much more proactive and strategic approach to vulnerability remediation.<u><\/u><u><\/u><\/span><\/li>\n<li class=\"yiv5038476695MsoNormal\"><u><\/u>\u00a0<b><i><span lang=\"EN-US\">Education and Government Application Usage:<\/span><\/i><\/b><i><span lang=\"EN-US\">\u00a0<\/span><\/i><span lang=\"EN-US\">When comparing application count usage across industries,\u00a0<\/span><span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><span lang=\"EN-US\"><a href=\"https:\/\/www.fortinet.com\/blog\/business-and-technology\/security-strategies-that-federal-agencies-can-employ-to-enable-d.html\" target=\"_blank\" rel=\"nofollow noopener\">government<\/a><\/span><\/span><span lang=\"EN-US\">\u00a0use of SaaS applications is 108% higher than the mean and is second to\u00a0<span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><a href=\"https:\/\/www.fortinet.com\/blog\/industry-trends\/overcoming-multi-cloud-security-challenges-in-education.html\" target=\"_blank\" rel=\"nofollow noopener\">education<\/a><\/span>\u00a0in the total number of applications used daily, 22.5% and 69% higher than the mean, respectively. The likely cause for the higher usage in these two industry segments is a greater need for a wider diversity of applications. These organizations will require a security approach that breaks down silos between each of these applications, including their multi-cloud environments, for transparent visibility and security controls.<u><\/u><u><\/u><\/span><\/li>\n<\/ul>\n<p>The threat data in this quarter\u2019s report once again reinforces many of the\u00a0<span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><a href=\"http:\/\/blog.fortinet.com\/2017\/11\/14\/fortinet-fortiguard-2018-threat-landscape-predictions\" target=\"_blank\" rel=\"nofollow noopener\">prediction<\/a><\/span>\u00a0trends unveiled by the\u00a0<span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><a href=\"https:\/\/www.fortinet.com\/fortiguard\/threat-intelligence\/threat-research.html?utm_source=nreleaseblog&amp;utm_campaign=2018-q2-fortiguardlabs-cta\" target=\"_blank\" rel=\"nofollow noopener\">FortiGuard Labs<\/a><\/span>\u00a0global research team for 2018. A\u00a0<span class=\"yiv5038476695m_-660984446339743068m_-3370626491116629149m_3599518936643084939m_3003519668875073167m_5586998205294637523m_2048446881777042827m_3278724568991260240m_-5349593205980617823MsoHyperlink\"><a href=\"https:\/\/www.fortinet.com\/blog\/business-and-technology\/innovation-insights--our-security-fabric-vision-is-reality.html\" target=\"_blank\" rel=\"nofollow noopener\">security fabric<\/a><\/span>\u00a0that is integrated across the attack surface and between each security element is vital. This approach enables actionable threat intelligence to be shared at speed and scale, shrinks the necessary windows of detection, and provides the automated remediation required for the\u00a0multi-vector exploits of today.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent attack trends show they are turning to agile development practices to make their malware even more difficult to detect and to counter the latest tactics of anti-malware products.\u00a0<\/p>\n","protected":false},"author":6,"featured_media":31029,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,25],"tags":[169,3216,54,535],"class_list":["post-33030","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-software","tag-fortinet","tag-iot","tag-security","tag-software-2"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/33030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=33030"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/33030\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/31029"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=33030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=33030"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=33030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}