Report: Trojans Constituted More Than Half Of All New Threats In Third Quarter

PandaLabs, Panda Security's antimalware laboratory, recently published its Q3 Quarterly Report on global malware activity, covering security events and incidents from July to September. Continuing the theme from the last report, PandaLabs once again found Trojans in the spotlight, comprising 55 percent of all new threats. Infection via e-mail, traditionally the most popular vector for spreading malware, has declined in favor of greater use of social media. These include clickjacking attacks using the Facebook "Like" button, fake Web pages positioned on search engines (BlackHat SEO) and zero-day vulnerability exploits.

The rise in popularity of smart phones powered by Google's Android operating system for smart phones has been accompanied by an increase in attacks targeting these devices. A number of different threats have appeared, primarily aimed at racking up phone bills or using the geolocalization function to transmit a user's position to a third party.

There were few surprises in the quantity of malware reported: 55 percent of new threats created this quarter were Trojans, most of them banker Trojans. This is in line with the general increase in these types of threats that PandaLabs has witnessed over the last two years. In the ranking of countries and regions suffering the most infections, Taiwan heads the list, followed by Russia, Brazil, Argentina, Poland, and Spain.

Spam shows no sign of slowing either; 95 percent of all e-mail circulated across the Internet during the last quarter was junk mail and approximately 50 percent of all spam was sent from just ten countries, with India, Brazil and Russia as the top three originators. For the first time, the United Kingdom has disappeared from the Top 10 list of spammers.

A number of interesting security incidents have surfaced over the past few months. The "Here you Have" worm emerged in an apparent attempt to trigger a major epidemic, like those in the past caused by ILoveYou or Sircam;  responsibility for the worm has been claimed by an Iraqi resistance group.

There has also been a great deal of commotion around two serious zero-day flaws in Microsoft OS code, one of which was exploited to attack SCADA systems (specifically in, nuclear power stations).

Of particular interest to Panda was the arrest of the creator of the Butterfly botnet kit, the source of the notorious Mariposa network that impacted 13 million computers around the world almost a year ago. PandaLabs researchers were instrumental in both shutting down the botnet and identifying the individuals responsible for the botnet.

At the tail end of the quarter, an intriguing worm appeared on Twitter as a result of a Javascript vulnerability that enabled a cross-site scripting attack. In addition, 'Rainbow' or 'OnMouseOver' worms redirected users to Web pages or published Javascript in the user's Twitter stream without their permission or knowledge. Twitter was able to resolve the problem in just a few hours.

Over the past three months, PandaLabs also witnessed the beginning of a wave of threats targeting smart phones powered by Android, Google's mobile operating system. Two applications have been developed specifically for this platform: FakePlayer, which, under the guise of a video player, sends SMS messages that generate a hefty phone bill for unwitting victims; and TapSnake, an app disguised as a game which sends the geolocalization coordinates of the user to an espionage company. Legitimate Android apps are also being used as bait to infect computers with self-extracting files.

The full report can be downloaded from: http://press.pandasecurity.com/press-room/panda-white-paper/.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Surveillance Cameras Provide Peace of Mind for New Florida Homeowners

    Managing a large estate is never easy. Tack on 2 acres of property and keeping track of the comings and goings of family and visitors becomes nearly impossible. Needless to say, the new owner of a $10 million spec home in Florida was eager for a simple way to monitor and manage his 15,000-square-foot residence, 2,800-square-foot clubhouse and expansive outdoor areas. Read Now

  • Survey: 72% of CISOs Are Concerned Generative AI Solutions Could Result In Security Breach

    Metomic recently released its “2024 CISO Survey: Insights from the Security Leaders Keeping Critical Business Data Safe.” Metomic surveyed more than 400 Chief Information Security Officers (CISOs) from the U.S. and UK to gain deeper insights on the state of data security. The report includes survey findings on various cybersecurity issues, including security leaders’ top priorities and challenges, SaaS app usage across their organization, and biggest concerns with implementing generative AI solutions. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

Featured Cybersecurity

Webinars

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises. 3

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection. 3

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3