Attacks Happen As Soon As Solution Was Found Says Trend Micro

ransomware-update

According to security expert company, Trend Micro, cyberattacks by cyber criminals to enterprise and businesses happens as soon as solution is found, making it difficult for the companies to protect themselves from the cyberattacks. And these attacks costs losses of millions of dollars for companies and they are targeting mainly companies in the United States. “It bodes well for businesses to anticipate being targeted and to prepare accordingly, implementing the latest security solutions, virtual patching and employee education to mitigate risks from all angles.” said Ed Cabrera, chief cybersecurity officer for Trend Micro, calling it the year of online extortion.

https://www.youtube.com/watch?v=Sm5TbBKeFvU

In the first half of 2016, Trend Micro discovered 473 vulnerabilities in a variety of products, with 28 coming from Adobe Flash and 108 from Advantech’s Web Access, demonstrating the full capabilities of the company’s research teams.

Ransomware is a Trojan virus that spreads itself through email and locks the victim’s data with encryption and asking for ransom or money to be transferred to decrypt the files. While Business Email Compromise (BEC) is an email attack that lures top decision makers in a company such as banks to transfer a huge sum of money.

cryptolocker2

The following report findings highlight trends from the first half of 2016:

  • Ransomware dominates the threat landscape: The occurrence of ransomware families nearly doubled, with an increase of 172 percent, in the first half of 2016 compared to 2015, further establishing ransomware as a prevalent and pervasive threat. Variants are designed to attack all levels of the network.
  • BEC scams spread across the world: The FBI listed more than 22,000 victims in 2016 to date, with more than US $3 billion in losses. Trend Micro has found that the U.S. is the most targeted country for these attacks.
  • New vulnerabilities and ransomware strengthen attacks through exploit kits: The declining use of Angler EK can be attributed to the arrest of 50 cybercriminals. As such, other EKs have taken its place, including new players like Rig and Sundown.
  • Rising number of vulnerabilities found in Adobe Flash and IoT platforms: Trend Micro and the ZDI reported several significant browser and kernel vulnerabilities, which were identified during the Pwn2Own competition
  • Incidents of data breaches plague various industries: Both private and public sectors fell victim to data breaches in the first half of the year, including Myspace and Verizon, several hospitals and government entities.
  • Updates in Point-of-Sale malware give rise to new attacks: FastPoS came equipped with efficient credit card theft capabilities, affecting small to medium businesses across the globe, including some in the U.S. FighterPoS also made its debut, showing worm-like qualities that allowed cross-network infection.
  • Exploits revive old vulnerabilities in their attacks: Shellshock exploits increased in the first half of the year, despite available patches, with thousands of new exploits seen each month. This is another example of the benefit to virtual patching, which provides faster protection to enterprise networks when vulnerabilities surface.
  • Cybercriminals defy the odds with banking Trojans: Trojans like QAKBOT increased their attacks following the arrest of the creators of DYRE. This variant goes after crucial information including banking credentials, browsing habits and other sensitive user data.

Share this post:

Comment what you think!