The Cyber Security Review | Thursday, November 17, 2022
Check Point Software Technologies has published its latest Global Threat Index for October 2022, revealing the latest in cyber threat news.
FREMONT, CA: The most recent Global Threat Index from Check Point Software Technologies, which includes the most recent information on cyber threats, was released in October 2022. Keylogger AgentTesla, which affected 7 per cent of organisations globally, won the title of most prevalent malware. Attacks from the info stealer Lokibot significantly increased, moving up to third place for the first time in five months. Additionally, a new vulnerability affecting the Apache Commons Text library called Text4Shell was revealed.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
A common info thief, Lokibot is made to gather login information from programmes, including web browsers, email clients, and IT management tools. Its objective as a trojan is to enter a system covertly by pretending to be a trustworthy application. Phishing emails, fraudulent websites, SMS, and other messaging services can all be used to spread it.
Check Point claims that the surge in spam operations with themes based on online queries, orders, and payment confirmation messages can be attributed to its increased popularity. Additionally, in October, Text4Shell, a new critical vulnerability, was disclosed (CVE-2022-42889). This permits assaults over a network without special rights or user input because it is based on the Apache Commons Texts functionality.
The Log4Shell vulnerability, which is still one of the biggest dangers and is ranked second on the October list, is reminiscent of Text4Shell. Despite not being among the most widely used vulnerabilities this month, CheckPoint reports that Text4Shell has already affected more than eight per cent of organisations globally.
Consumers must be careful and watch out for odd emails that could carry harmful code as we move towards November, which is a busy buying month. Be on the lookout for warning indications such as links, an unusual sender, and requests for personal information. In cases when it is unsure, go to the websites directly, get the necessary contact information from reputable sources, and install malware protection.
Additionally, it was discovered that Apache Log4j Remote Code Execution, which has an impact on 41 per cent of organisations worldwide, and Web Server Exposed Git Repository Information Disclosure, which is the most often exploited vulnerability, both affect 43 per cent of organisations globally. In October, research and education continued to lead all other industries in global attacks. This month, Anubis continued to lead the list of the most common mobile malware, followed by Joker, Hydra, and Anubis.
Anubis: Anubis is an Android-compatible banking Trojan virus. Since it was first discovered, it has acquired new capabilities, including the ability to serve as a Remote Access Trojan (RAT), as a keylogger and an audio recorder, as well as a variety of ransomware features. It has been found in countless different Google Play Store applications.
Hydra: Hydra is a banking Trojan that asks victims to provide risky permissions to steal their financial information.
Joker: Joker is an Android spyware on Google Play that is made to steal contacts, SMS messages, and device data. Additionally, the malware can enrol the victim in premium-priced services without their knowledge or consent.
Check Point's ThreatCloud intelligence powers its ThreatCloud Map and Global Threat Impact Index. ThreatCloud offers real-time threat intelligence gleaned from hundreds of millions of sensors across networks, endpoints, and mobile devices worldwide. Check Point Research, the intelligence and research division of Check Point Software Technologies, provides research data and AI-based engines to the intelligence.
More in News