Showing posts with label Kaspersky. Show all posts
Showing posts with label Kaspersky. Show all posts

Tuesday, December 31, 2019

Kaspersky Web Traffic Security now available in two deployment options to meet customer demands

Kaspersky released next version of Kaspersky Web Traffic Security, which now offers enhanced protection capabilities though integration with Kaspersky Anti Targeted Attack to improve early detection of sophisticated web threats. The product is now available in two deployment options, as a standalone application and a software appliance, to meet broader customer needs.


According to Kaspersky researchers, 717 million web attacks were revealed in the second quarter of this year. The attacks contain various kinds of malware including generic adware to ransomware and advanced threats that reach corporate networks through phishing, social engineering or unreliable web resource surfing.

Web gateway protection allows companies to block massive amounts of web threats before they reach endpoints. This decreases the number of alerts on endpoints that interrupt users and administrators, as well as ensures protection of devices which don’t have endpoint security product installed or updated.


To make the deployment and use of the product effective for companies with different needs, Kaspersky now offers two options: as a software appliance or a standalone application.

The software appliance is a ready-to-use solution for companies that need to quickly deploy and start using secure web gateway with a proxy server pre-configured. The appliance interface allows users to manage the incorporated proxy server, avoiding configuration hassle.

The Kaspersky Web Traffic Security standalone application allows resource economy and a more agile configuration for companies that need a more customized solution and careful integration of different cybersecurity products. The application does not necessarily demand a separate server, as the system requirements necessary to protect a particular bandwidth are met. It can be installed alongside other applications but configured separately from other gateway components.


The protection capabilities of Kaspersky Web Traffic Security are now empowered by two-way API-based integration with Kaspersky Anti Targeted Attack, which allows customers of both solutions to achieve earlier attack detection and automated responses to advanced web threats. 

Suspicious files are automatically sent to Kaspersky Anti Targeted Attack for analysis. The system reveals the nature and malicious activity that the advanced threat generates, including files, transmission of commands, payloads and stolen data, and blocks them at the early attack stage.


“Different deployment scenarios allow companies to choose the best way to secure corporate web traffic, depending on available resources or IT network architecture,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “It also brings new usage scenarios to our partners. For example, the new format of the all-in-one appliance can be used by managed service providers to add web traffic security to their portfolio. Thanks to the application’s ease of deployment, scalability and multi-tenancy, they can provide web traffic security as a service for additional protection to ever growing number of customers, without the hassle.”

Kaspersky Web Traffic Security is available in both deployment options as part of Kaspersky Security for Internet Gateway and Kaspersky Total Security for Business.

Friday, December 20, 2019

Kaspersky sees a sky-rise of droppers with phishing and malware attacks surface amid premiere of famous space saga

According to research from Kaspersky, the latest and final film of the trilogy has drawn the attention of attackers even before the premiere, with fraudulent websites and malicious files of the yet-to-be-released film flooding the web. Popular films are often used by cybercriminals as bait to distribute malware, and the latest movie saga from ‘a galaxy far, far away’ is no exception. 

Films are one of the main forms of entertainment users seek to access for free, which creates fertile soil for cyberattacks. Online streaming, torrents and other methods of digital distribution often infringe upon content copyright, and yet they remain popular as a source of free content. 


Torrent-trackers and illegal streaming platforms pose a threat to users’ cyber-safety, since they can host malicious files, masked behind the name of movie files. Given this tendency, Kaspersky studied how the sci-fi franchise’s name is being abused by cybercriminals in order to fool fans.

Public attention on “Star Wars: The Rise of Skywalker,” which premieres Dec. 19, is already attracting cybercriminals. Kaspersky researchers found over 30 fraudulent websites and social media profiles disguised as official movie accounts (the actual number of these sites may be much higher) that supposedly distribute free copies of the latest film in the franchise. These websites collect unwary users’ credit card data, under the pretense of necessary registration on the portal.


The domains of websites used for gathering personal data and spreading malicious files usually copy the official name of the film and provide thorough descriptions and supporting content, thereby fooling users into believing that the website is, in some way, connected to the official film. 

Such practice is called “black SEO,” which enables criminals to promote phishing websites high up in search engine results (such results often show up for search terms such as ‘name-of-the-film watch free’).

To further support the promotion of fraudulent websites, cybercriminals also set up Twitter and other social media accounts, where they distribute links to the content. Coupled with malicious files shared on torrents, this brings the criminals results. So far, 83 users have already been affected by 65 malicious files disguised as copies of the upcoming movie.

Phishing is not the only way cybercriminals tend to utilize popular film franchises. Just as with TV shows, they often disguise malicious programs as yet another episode of the story. In 2019, Kaspersky detected 285,103 attempts to infect 37,772 users seeking to watch movies of the renowned space-opera series, a 10 percent rise compared to last year. The number of unique files used to target the users amounted to 11,499, a 30 percent drop from last year.

“It is typical for fraudsters and cybercriminals to try to capitalize on popular topics, and ‘Star Wars’ is a good example of such a theme this month,” said Tatiana Sidorina, security researcher at Kaspersky. “As attackers manage to push malicious websites and content up in the search results, fans need to remain cautious at all times. We advise users to not fall for such scams and instead enjoy the end of the saga on the big screen.”


Users have been advised to take the following steps by paying attention to the official movie release dates in theaters, on streaming services, TV, DVD, or other sources; avoid clicking on suspicious links, such as those promising an early view of a new film; and paying special attention to the downloaded file extension. The file should have an .avi, .mkv or .mp4 extension, among other video formats, and not the suspicious .exe extension.

Consumers must check the website’s authenticity, and avoid visiting websites to watch a movie until they are sure that they are legitimate and start with ‘https.’ Confirm that the website is genuine by double-checking the format of the URL or the spelling of the company name, reading reviews about it and checking the domains’ registration data before starting downloads. It also uses reliable security solution, such as Kaspersky Security Cloud, for comprehensive protection from a range of threats.

Wednesday, December 18, 2019

Kaspersky’s IT Security Calculator reveals budgets lower than average in 45% of SMBs and 50% of enterprises

Data released by the Kaspersky IT Security Calculator shows that budgets at 45 percent of SMBs and 50 percent of enterprises are below the average spend at US$205,000 for small to medium, and $8 million for enterprise businesses. This is despite a Gartner report announcing cybersecurity spending is growing year-on-year with almost 9 percent growth this year.


The Kaspersky IT Security Calculator is a free web tool that allows IT security managers to view the average budget for cybersecurity in their region and industry, as well as to compare budgets within their organization. The tool is becoming increasingly important as it allows companies to understand their position in the market and also gives them the ability to compare their budget with competitors and improve planning.

Globally, IT security budgets are demonstrating positive dynamics with a number of analyst reports showing that budgets continue to grow year over year. 


Kaspersky’s own survey of almost five thousand organizations across the world confirms this trend with 70 percent of respondents showing they expect their IT security budget to increase in the next three years. However, statistics from usage of the Kaspersky IT Security Calculator in October 2018- 2019 revealed that some businesses are not keeping up with this trend, as their IT security spending is lower than average.

Overall, budgets for SMBs were reviewed more actively (46 percent) than for enterprises (38 percent) and very small companies (16 percent). For small and medium businesses, the budget issue proves to be complicated as it’s not only about finances but also the alignment of the budget planning process. Another challenge to consider is the demands on human resources to hire experts in relevant cybersecurity risks and the protection methods needed for different business services.


“Budget planning is a very important process for companies to carefully consider as the proper investments ensure a company is ready to meet current cybersecurity challenges and threats,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “Though it may be a complex task which demands a deep understanding of business needs towards cybersecurity, it is important to understand how to address them and how much it can cost. At Kaspersky, we do our best to give organizations insights to help them with this process. Along with the report on IT security economics we prepare annually, the IT Security Calculator gives a glance on average cybersecurity spending as well as specific threats and advice on protection measures.”

The Kaspersky IT Security Calculator website with threat statistics and recommended protection is available, and free to use.

Saturday, December 14, 2019

Kaspersky research finds 174 municipal institutions targeted with ransomware in 2019

According to Kaspersky security experts, 2019 has seen a significant spike of ransomware attacks on municipalities. This conclusion comes after the company’s researchers observed at least 174 municipal institutions with more than 3,000 subset organizations have been targeted by ransomware throughout the last year. This represents a 60 percent increase from the same figure in 2018.


Ransomware is notorious in the corporate sector for financial devastation and has affected businesses around the world for several years. This year has seen rapid development of an earlier trend where malware distributors have targeted municipal organizations. 

Researchers note that while these targets might be less capable of paying a large ransom, they are more likely to agree to cybercriminals’ demands. Blocking any municipal services directly affects the welfare of citizens in financial losses as well as other significant and sensitive consequences.

When considering publicly available information, ransom amounts have varied greatly with highs reaching up to $5,300,000 and $1,032,460 on average. Researchers note that these figures do not accurately represent the final costs of an attack, as the long-term consequences are far more devastating.

The malware that was most often observed were varied, yet three families were named as the most notorious by Kaspersky researchers: Ryuk, Purga and Stop. Ryuk appeared on the threat landscape more than a year ago and has since been active all over the world in public and in the private sector. Its distribution model usually involves delivery via backdoor malware which spreads by the means of phishing with a malicious attachment disguised as a financial document. 


Purga malware has been recognized since 2016, yet only recently municipalities have been discovered to fall victims to this Trojan having various attack vectors from phishing to brute force attacks. Stop cryptor is relatively new as it is only a year old. It propagates by hiding inside software installers. This malware continues to be prevalent, ranking at number seven in the top 10 most popular cryptors ranking of the third quarter this year.

“One must always keep in mind that paying extortionists is a short-term solution which only encourages criminals and keeps them funded to quite possibly repeat the same acts,” said Fedor Sinitsyn, a security researcher at Kaspersky. “In addition, once a city has been attacked, the whole infrastructure is compromised and requires an incident investigation and a thorough audit. This inevitably results in costs that are in addition to the ransom requested. Based on our observations, cities might be inclined to pay because they usually cover the cyber risks with help of insurance and allocating budgets for incident response. The better approach would be to invest in proactive measures like proven security and backup solutions as well as regular security audit. While the trend of attacks on municipalities is only growing, it can be stifled by adjusting the approach to cybersecurity and what is more important by the refusal to pay ransoms and broadcasting this decision as an official statement.”

Friday, December 13, 2019

Kaspersky reports that malware variety grew by 13.7 percent this year, driven by surge in web skimmers

The number of unique malicious objects detected by Kaspersky’s web antivirus solution rose by 13.7 percent this year, compared to last year, reaching 24,610,126. The growth was mainly influenced by a 187 percent rise in web skimmer files. 

Other threats, such as backdoors and banking Trojans detected in-lab, also grew, while the presence of miners dropped by more than half. These trends demonstrated a shift in the type of threats used by attackers on the web, who search for more effective ways to target users, according to the new Kaspersky Security Bulletin: Statistics of the Year report.


In 2018, unique malicious objects (including scripts, exploits and executable files) detected by Kaspersky’s web antivirus solution totaled 21,643,946, rising to 24,610,126 this year. The growth reflects an increase in the number and variety of HTML pages and scripts with hidden data loading – usually used by unscrupulous advertisers. Yet, most notably, the growth was also partially caused by online skimmers, sometimes referred to as sniffers, where scripts are embedded by attackers in online stores and used to steal users’ credit card data from websites.

The growth of online skimmers’ unique files (scripts and HTML) detected by Kaspersky web antivirus equaled 187 percent, reaching 510,000. At the same time, the number of threats detected by web antivirus has risen five-fold (by 523 percent), totaling 2,660,000 in 2019. 

Web skimmers also entered the top 20 malicious objects detected online, taking 10th place in the overall ranking. The share of new backdoors and banking Trojan files, among all types of threats detected in-lab, also grew by 134 percent and 61 percent to reach 7,644,402 and 739,551 respectively.

Nevertheless, the number of unique malicious URLs detected by Kaspersky web antivirus fell by half (50.5 percent) in comparison to 2018, from 554,159,621 to 273,782,113. This shift was largely caused by significant decrease of hidden web miners, even though several detections related to them (including Trojan.Script.Miner.gen, Trojan.BAT.Miner.gen, Trojan.JS.Miner.m), can still be seen in the top 20 web malware threats.


The presence of programs that secretly generate cryptocurrency on users’ computers (called ‘local’ miners) has also been steadily declining over the year. The number of users’ computers affected by attempts to install miners dropped by 59 percent, from 5,638,828 to 2,259,038.

Eighty-five percent of web threats were detected as malicious URL. This detection name is used to identify links from Kaspersky’s black list. It includes links to web pages containing redirects to exploits, sites with exploits and other malicious programs, botnet command and control centers, extortion websites, and others.

“The volume of online attacks has been growing for years, but in 2019 we saw a clear shift from certain types of attacks that are becoming ineffective, to the ones focused on gaining clear profit from users,” said Vyacheslav Zakorzhevsky, head of anti-malware research at Kaspersky. “This is partly due to users becoming more aware of the threats and how to avoid them, and organizations steadily becoming more responsible. A good example is miners, which have lost their popularity due to lower profitability and cryptocurrencies’ fight against covert mining. This year we also witnessed growth in zero-day exploits, showing products remain vulnerable and are used by attackers for sophisticated attacks, and this trend is likely to continue in the future.”

Thursday, December 12, 2019

Kaspersky finds zero-day exploit in Windows OS used in targeted attack, part of malicious WizardOpium operation

Kaspersky automated detection technologies have found a Windows zero-day vulnerability. The exploit based on this vulnerability allowed attackers to gain higher privileges on the attacked machine and avoid protection mechanisms in the Google Chrome browser. The newly discovered exploit was used in the malicious WizardOpium operation.

Zero-day vulnerabilities are previously unknown bugs in software, which, if found by criminals first, enable them to operate unnoticed for an extended period of time, inflicting serious and unexpected damage. Regular security solutions do not identify the system infection nor can they protect users from a yet-to-be-recognized threat.


The new Windows vulnerability was found by Kaspersky researchers as a result of a separate zero-day exploit. In Nov 2019, Kaspersky’s Exploit Prevention technology, which is embedded in most of the company’s products, detected a zero-day exploit in Google Chrome. 

This exploit allowed attackers to execute arbitrary code on a victim’s machine. Upon further research of this operation, which the experts called ‘WizardOpium,’ another vulnerability was discovered, this time in Windows OS.


It emerged that the newly discovered Windows zero-day elevation of privileges (EoP) exploit, CVE-2019-1458, was embedded into a previously discovered Google Chrome exploit. It was used to gain higher privileges in the infected machine as well as to escape the Chrome process sandbox – a component built to protect the browser and the victim’s computer from malicious attacks.
  
Detailed analysis of the EoP exploit showed that the abused vulnerability belongs to the win32k.sys driver. The vulnerability could be abused on the latest patched versions of Windows 7 and even on a few builds of Windows 10 (new versions of Windows 10 have not been affected).


“This type of attack requires vast resources. However, it gives significant advantages to the attackers and, as we can see, they are happy to exploit it,” said Anton Ivanov, security expert at Kaspersky. “The number of zero-days in the wild continues to grow and this trend is unlikely to go away. Organizations need to rely on the latest threat intelligence available at hand and have protective technologies that can proactively find unknown threats such as zero-day exploits.”

Friday, December 6, 2019

Kaspersky shockingly finds that ransomware is now targeting back-up data

Kaspersky researchers identified on Thursday a new type of ransomware attack, Network Attached Storage (NAS), which is actively growing in popularity. Targeting NAS poses new risks for back-up data usually stored on devices. With NAS largely perceived as a secure technology, users often remain unprepared for the possibility of infection, putting their data at higher risk.

Encryption ransomware is a malware that applies advanced encryption methods so files cannot be decrypted without a unique key. This leaves the infected device owner stuck with a locked device and a demand to pay a ransom in order to regain access to files. 


While users are typically infected with ransomware via email or exploit-kits planted on websites, the new type of attacks on NAS devices use a different vector. Ransomware operators scan ranges of IP addresses looking for NAS devices accessible via the web. 

Although only web interfaces protected with authentication are accessible, a number of devices have integrated software with vulnerabilities in it. This allows attackers to install a Trojan using exploits, which will then encrypt all data on the devices connected to the NAS.


During the third quarter this year, Kaspersky products detected and repelled encryption ransomware attacks on 229,643 Kaspersky products users, which is 11 percent less than during the same period last year. Although the total number of affected users slightly decreased, the report shows that the number of new encryption ransomware modifications grew from 5,195 in the third quarter of last year to 13,138 in the third quarter this year marking 153 percent growth. This development signals cybercriminal interest in this type of malware as means of enrichment.

At the same time, the infamous WannaCry Trojan family retained first place among the most popular Trojans with over a fifth of attacked users having been targeted with malware identified as belonging to this group. 


The top three most popular verdicts that account for almost half of users attacked by cryptors were Trojan-Ransom.Win32.Wanna (20.96 percent users attacked), Trojan-Ransom.Win32.Phny (20.01 percent) and Trojan-Ransom.Win32.GandCrypt (8.58 percent).

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...