{"id":40266,"date":"2020-08-10T16:00:06","date_gmt":"2020-08-10T15:00:06","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2020\/08\/10\/mcafee-report-shows-threat-actor-evolution-during-pandemic\/"},"modified":"2020-08-18T11:27:54","modified_gmt":"2020-08-18T10:27:54","slug":"mcafee-report-shows-threat-actor-evolution-during-pandemic","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2020\/08\/10\/mcafee-report-shows-threat-actor-evolution-during-pandemic\/","title":{"rendered":"McAfee report shows threat actor evolution during pandemic"},"content":{"rendered":"\n<p>McAfee, the device-to-cloud cybersecurity company, has released its&nbsp;<em>McAfee COVID-19 Threat Report: July 2020<\/em>,&nbsp;examining cybercriminal activity related to COVID-19 and the evolution of cyberthreats in Q1 2020. McAfee Labs saw an average of 375 new threats per minute and a surge of cybercriminals exploiting the pandemic through COVID-19 themed malicious apps, phishing campaigns, malware and more. New PowerShell malware increased 688% over the course of the quarter, while total malware grew 1,902% over the past four quarters. Disclosed incidents targeting the public sector, individuals, education and manufacturing increased; nearly 47% of all publicly disclosed security incidents took place in the US.<\/p>\n\n\n\n<p>\u201cThus far, the dominant themes of the 2020 threat landscape have been cybercriminal\u2019s quick adaptation to exploit the pandemic and the considerable impact cyberattacks have had,\u201d said Raj Samani, McAfee Fellow and Chief Scientist. \u201cWhat began as a trickle of phishing campaigns and the occasional malicious app quickly turned into a deluge of malicious URLs and capable threat actors leveraging the world\u2019s thirst for more information on COVID-19 as an entry mechanism into systems across the globe.\u201d<\/p>\n\n\n\n<p>Each quarter, McAfee assesses the state of the cyberthreat landscape based on in-depth research, investigative analysis and threat data gathered by the McAfee Global Threat Intelligence cloud from over a billion sensors across multiple threat vectors around the world.<\/p>\n\n\n\n<p><strong>Capable threat actors exploit pandemic<\/strong><\/p>\n\n\n\n<p>McAfee researchers found it is typical of COVID-19 campaigns to use pandemic-related subjects including testing, treatments, cures and remote work topics to lure targets into clicking on a malicious link, downloading a file, or viewing a PDF. To track these campaigns, McAfee Advanced Programs Group (APG) has published a&nbsp;COVID-19 Threat Dashboard, which includes top threats leveraging the pandemic, most targeted verticals and countries and most utilised threat types and volume over time. The dashboard is updated daily at 4pmET.<\/p>\n\n\n\n<p>\u201cCybersecurity cannot be solved by cookie cutter approaches. Each organisation is unique and has specific intelligence requirements and objectives,\u201d said Patrick Flynn, Head of McAfee APG. \u201cThe McAfee COVID-19 Threat Dashboard utilises data to create true analysed intelligence, which allows users to understand the total threat environment, informing them of potential threats before they are weaponised.&#8221;<\/p>\n\n\n\n<p><strong>Data breaches: The new ransomware attack<\/strong><\/p>\n\n\n\n<p>Over the course of the first quarter of 2020, McAfee Advanced Threat Research (ATR) observed malicious actors focus on sectors where availability and integrity are fundamental, for example manufacturing, law and construction firms.<\/p>\n\n\n\n<p>\u201cNo longer can we call these attacks just ransomware incidents. When actors have access to the network and steal the data prior to encrypting it, threatening to leak if you don\u2019t pay, that is a data breach,\u201d said Christiaan Beek, Senior Principal Engineer and Lead Scientist. \u201cUsing either weakly protected Remote Desktop Protocol or stolen credentials from the underground, we have observed malicious actors moving at light speed to learn the network of their victims and effectively steal and then encrypt their data.\u201d<\/p>\n\n\n\n<p>New ransomware declined 12% in Q1; total ransomware increased 32% over the past four quarters.<\/p>\n\n\n\n<p><strong>Q1 2020 threat activity<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Malware overall.&nbsp;<\/strong>New malware samples slowed by 35%; total malware increased 27% over the past four quarters. New Mac OS malware samples increased by 51%.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Mobile malware.&nbsp;<\/strong>New mobile malware increased by 71%, with total malware growing nearly 12% over the past four quarters.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Regional Targets.&nbsp;<\/strong>Disclosed incidents targeting the Americas increased 60%, incidents targeting Asia-Pacific increased 27%, while Europe decreased 7%.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Security incidents.&nbsp;<\/strong>McAfee Labs counted 458 publicly disclosed security incidents, an increase of 41% from Q4. A total of 50% of all publicly disclosed security incidents took place in North America, followed 9% in Europe. Nearly 47% of all publicly disclosed security incidents took place in the US.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Vertical industry targets.&nbsp;<\/strong>Disclosed incidents targeting the public sector increased 73% individuals increased 59%, education increased 33%, and manufacturing increased 44%.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Attack vectors.&nbsp;<\/strong>Overall, malware-led disclosed attack vectors, followed by account hijacking and targeted attacks.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Cryptomining.&nbsp;<\/strong>New coinmining malware increased 26%. Total coinmining malware samples increased nearly 97% over the past four quarters.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Fileless malware.&nbsp;<\/strong>New JavaScript malware declined nearly 38%, while total malware grew nearly 24% over the past four quarters. New PowerShell malware increased 689%; total malware grew 1,902% over the past four quarters.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>IoT.<\/strong>\u00a0New malware samples increased nearly 58%; total IoT malware grew 82% over the past four quarters.<\/li><\/ul>\n\n\n\n<p><em>We spoke to Raj Samani, McAfee Fellow and Chief Scientist, to gather his thoughts on the findings<\/em>.<\/p>\n\n\n\n<p><strong>Were you surprised by the threat activity figures from Q1 2020?<\/strong><\/p>\n\n\n\n<p>The slow pick up was perhaps a little surprising, but really, from about mid-March, I don\u2019t think the volume was that unexpected.\u00a0Perhaps more surprising was the geographies that were targeted \u2014 for some time, the most targeted country for malicious files, using COVID as a lure, was Spain and that was unexpected.<\/p>\n\n\n\n<p><strong>Was there anything that could have been done differently to avoid victims\u2019 data being stolen?<\/strong><\/p>\n\n\n\n<p>Well, all of the metrics we presented were stopped.\u00a0In fact, on malicious files alone, we stopped well over a million files that were intended to infect\/defraud its victims.\u00a0<\/p>\n\n\n\n<p><strong>Why do you think attacks in the Americas increased, while those in Europe decreased?<\/strong><\/p>\n\n\n\n<p>In part, the US generally is one of the territories that is targeted more often.\u00a0However, we also have to consider that unlike many other countries, it does have relatively mature reporting, so any attacks\/breaches themselves can be identified and counted.<\/p>\n\n\n\n<p><strong>How do you predict the findings to change, moving forward?<\/strong><\/p>\n\n\n\n<p>The use of COVID as a lure is already fragmenting.&nbsp;We are now seeing attackers take advantage of some of the indirect consequence of the pandemic. For example, attackers are using the economic situation to bait individuals into clicking on links to malicious sites, under the guise that they will be able to claim stimulus cheques. Also, with more of us streaming content to our homes, we are seeing an uptick in phishing lures claiming that accounts have been suspended.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>McAfee, the device-to-cloud cybersecurity company, has released its&nbsp;McAfee COVID-19 Threat Report: July 2020,&nbsp;examining cybercriminal activity related to COVID-19 and the evolution of cyberthreats in Q1 2020. McAfee Labs saw an average of 375 new threats per minute and a surge of cybercriminals exploiting the pandemic through COVID-19 themed malicious apps, phishing campaigns, malware and more. [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":40407,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,93],"tags":[7053,15067,4704,1268],"class_list":["post-40266","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-cyberthreat","tag-mcafee-advanced-programs-group","tag-phishing","tag-ransomware"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/40266","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=40266"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/40266\/revisions"}],"predecessor-version":[{"id":40406,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/40266\/revisions\/40406"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/40407"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=40266"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=40266"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=40266"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}