Multi-Purpose Malware Surge Strikes Enterprises

A surge of malware attacks in the Ukraine and Japan have pushed a years-old malware loader onto the top 10 list of worldwide cyber-threats, according to researchers.

Check Point said Smoke Loader, a second-stage downloader, has been known to researchers since 2011.

But its recent activities meant it rose 11 places on the firm’s monthly threat index to ninth place.

Smoke Loader is mainly used to load other malware, including Trickbot Banker, AZORult Infostealer and Panda Banker, Check Point said.

Banking Trojans on the rise

The figures were released in the December rankings, published this week.

“December’s report saw SmokeLoader appearing in the top 10 for the first time,” said Check Point research group manager Maya Horowitz in an advisory.

“Its sudden surge in prevalence reinforces the growing trend towards damaging, multi-purpose malware.”

Half of the current top 10 list of threats was made up of malware that uses multiple methods to distribute numerous threats, with the other half composed of crypto-mining malware, she said.

Check Point also found banking Trojans rose in prominence, with Ramnit, which steals login credentials and other sensitive data, rising to eighth place.

The list was dominated, as it has been in recent months, by cryptomining malware, which uses systems’ computing resources to produce virtual currencies for the attackers.

Coinhive was the top threat for the thirteenth month in a row, affecting 12 percent of organisations worldwide, Check Point said.

Cryptomining malware dominates

It was followed by XMRig with a global reach of 8 percent and JSEcoin with 7 percent.

“Organisations continue to be targeted by cryptominers despite an overall drop in value across all cryptocurrencies in 2018,” Check Point noted.

The most exploited vulnerability worldwide in December was CVE-2017-7269, a bug affecting Microsoft Windows Server 2003 R2 that was disclosed in early 2017.

It was followed by a widespread OpenSSL TLS DTLS Heartbeat information disclosure bug and a code-injection flaw in PHPMyAdmin.

Horowitz said the wide range of threats means enterprises are well advised to use a multi-layered cybersecurity strategy.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago