TechCentralTechCentral
    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      Dimension Data to be renamed NTT Data

      27 October 2023

      DStv makes RWC final stream available for R19.95

      27 October 2023

      Karpowership gets green light for Richards Bay plant

      27 October 2023

      Why people wave on Zoom

      27 October 2023

      Microsoft gaining ground in cloud race with AWS, Google

      27 October 2023
    • World

      Intel beats expectations; manufacturing momentum builds

      27 October 2023

      Google CEO to testify on Monday in antitrust trial

      27 October 2023

      Huawei sees growth in cloud, digital power segments

      27 October 2023

      China rushes to swap Western tech for domestic options

      26 October 2023

      Alphabet, Meta deliver solid financial performances

      26 October 2023
    • In-depth

      Quantum computers in 2023: what they do and where they’re heading

      22 October 2023

      How did Stephen van Coller really do as EOH CEO?

      19 October 2023

      Risc-V emerges as new front in US-China tech war

      6 October 2023

      Get ready for a tidal wave of software M&A

      26 September 2023

      Watch | A tour of Vumatel’s Alexandra fibre roll-out

      19 September 2023
    • TCS

      TCS | Mesh.trade’s Connie Bloem on the future of finance

      26 October 2023

      TCS | Rahul Jain on Peach Payments’ big funding round

      23 October 2023

      TCS+ | How MiWay uses conversation analytics

      16 October 2023

      TCS+ | The story behind MTN SuperFlex

      13 October 2023

      TCS | The Information Regulator bares its teeth – an interview with Pansy Tlakula

      6 October 2023
    • Opinion

      Big banks, take note: PayShap should be free

      20 October 2023

      Eskom rolling out virtual wheeling – here’s how it works

      4 October 2023

      How blockchain can help defeat the scourge of counterfeit goods

      29 September 2023

      There’s more to the skills crisis than emigration

      29 September 2023

      The role of banks in Africa’s digital future

      22 August 2023
    • Company Hubs
      • 4IRI
      • Africa Data Centres
      • Altron Document Solutions
      • Altron Systems Integration
      • Arctic Wolf
      • AvertITD
      • CoCre8
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • E4
      • Entelect
      • ESET
      • Euphoria Telecom
      • iKhokha
      • Incredible Business
      • iONLINE
      • LSD Open
      • Maxtec
      • MiRO
      • NEC XON
      • Next DLP
      • Ricoh
      • Skybox Security
      • SkyWire
      • Velocity Group
      • Videri Digital
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud computing
      • Consumer electronics
      • Cryptocurrencies
      • E-commerce
      • Education and skills
      • Energy
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Metaverse and gaming
      • Motoring and transport
      • Open-source software
      • Public sector
      • Science
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » ESET: Ransomware, password guessing top security threats

    ESET: Ransomware, password guessing top security threats

    By ESET23 February 2022
    Facebook Twitter LinkedIn WhatsApp Telegram Email
    ESET Southern Africa’s Steve Flynn

    ESET Research has released its T3 Threat Report for the fourth quarter of 2021, summarising the key statistics from ESET detection systems between September and December 2021.

    • Ransomware surpassed the worst expectations in 2021, with attacks against critical infrastructure, outrageous ransom demands and over US$5-billion worth of potential bitcoin transactions in the first half of the year alone.
    • RDP (Remote Desktop Protocol) attack numbers from the last weeks of T3 2021 broke all previous records, amounting to a staggering yearly growth of 897%.
    • Android banking malware detections rose by 428% in 2021 compared to 2020.
    • ProxyLogon vulnerability was the second most frequent external attack vector in ESET’s 2021 statistics, right after password-guessing attacks.
    • Attacks exploiting the Log4Shell vulnerability were the fifth most common external intrusion vector in 2021.

    The ESET research reveals a rising scourge of e-mail threats towards the end of 2021 and a marked increase in threats exploiting customer excitement around cryptocurrency’s bull run at the end of the year. But it was the nearly 900% increase year on year of Remote Desktop Protocol (RDP) attacks, and a critical flaw in the Log4j utility, that was a great cause for concern in the latter part of the year.

    IT teams everywhere were sent scrambling, again, to locate and patch the Log4j flaw in their systems. “This vulnerability, scoring a 10 on the Common Vulnerability Scoring System, put countless servers at risk of a complete takeover – so it came as no surprise that cybercriminals instantly started exploiting it. Despite only being known for the last three weeks of the year, Log4j attacks were the fifth most common external intrusion vector in 2021 in our statistics, showing just how quickly threat actors are at taking advantage of newly emerging critical vulnerabilities,” explains Roman Kováč, chief research officer at ESET’s Slovakia-based research lab.

    According to ESET telemetry, the end of the year was also turbulent for RDP attacks, which escalated throughout 2020 and 2021. RDP attacks exploit the fact that many work from home environments leave enterprise networks vulnerable if organisations fail to secure end-points due to the rapid adoption of work from home working policies.

    Numbers from the final weeks of 2021 broke all previous records, amounting to a staggering yearly growth of 897% in total attack attempts blocked.

    Ransomware threats continue unabated

    But it has been a monumental rise in ransomware attacks that continues to be one of the most significant concerns even into 2022. “Since 2020, ransomware threats have been more aggressive than ever,” says Steve Flynn, sales and marketing director for ESET Southern Africa.

    “Ransomware surpassed the worst expectations in 2021 with attacks on critical infrastructure, even here in South Africa, crippling many institutions both public and private,” he says.

    Ransom demands and over $5-billion worth of bitcoin transactions tied to potential ransomware payments were identified in the first half of 2021 alone. As the bitcoin exchange rate reached its highest point in November, ESET experts observed an influx of cryptocurrency-targeting threats, further boosted by the popularity of non-fungible tokens (NFTs).

    Android banking malware shows an alarming increase

    In the world of mobile, ESET noted an alarming upsurge in Android banking malware detections, which rose by 428% in 2021 compared to 2020. Banking malware threats are almost as prevalent as adware, a common nuisance on the Android platform.

    Phishing remains a problem

    E-mail threats, the door to myriad attacks, saw their yearly detection numbers more than double. This trend was mainly driven by a rise in phishing e-mails, which more than compensated for the rapid decline in Emotet’s signature malicious macros in e-mail attachments. Emotet, an infamous trojan inactive for most of the year, as illustrated in the report, came back in the last quarter of the year.

    No platform is immune to threats.

    The ESET T3 2021 Threat Report also reviews the most important research findings, with ESET Research uncovering: FontOnLake, a new malware family targeting Linux; a previously undocumented real-world UEFI boot-kit named ESPecter; FamousSparrow, a cyberespionage group targeting hotels, governments, and private companies worldwide; and many others. The full report contains an analysis from ESET researchers on all 17 malicious frameworks known to have been used to attack air-gapped networks.

    Rounding out the report is news that ProxyLogon vulnerability was the second most frequent external attack vector in ESET’s 2021 statistics, right after password-guessing attacks.

    Microsoft Exchange servers fell under siege again in August 2021, with ProxyLogon’s “younger sibling”, named ProxyShell, which has been exploited worldwide by several threat groups.

    “The move online has made everyone’s life much easier during the pandemic. Organisations and their people have been quick to adapt, but this brought levels of threats we have never seen before. Cybercriminals are more determined than ever to exploit any vulnerability, and users are going to have to take cybersecurity seriously if we are to get on top of these threats in any meaningful way in the future,” concludes Flynn.

    For more information, check out ESET Threat Report T3 2021 on WeLiveSecurity or follow ESET’s social media pages on LinkedIn, Facebook and Instagram.

    About ESET
    For more than 30 years, ESET has been developing industry-leading IT security software and services to protect businesses, critical infrastructure and consumers worldwide from increasingly sophisticated digital threats.

    From endpoint and mobile security to endpoint detection and response, encryption and multifactor authentication, ESET’s high-performing, easy-to-use solutions unobtrusively protect and monitor 24/7, updating defences in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company that enables the safe use of technology. This is backed by ESET’s R&D centres worldwide, working in support of our shared future. For more information, visit www.eset.com/za or follow us on LinkedIn, Facebook and Instagram.

    • This promoted content was paid for by the party concerned
    ESET Steve Flynn
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email
    Previous ArticleInvestec seeks to double its South African client base
    Next Article Closing the gap between vulnerability discovery and remediation

    Related Posts

    Dimension Data to be renamed NTT Data

    27 October 2023

    DStv makes RWC final stream available for R19.95

    27 October 2023

    Karpowership gets green light for Richards Bay plant

    27 October 2023
    Add A Comment

    Comments are closed.

    Promoted

    Acsa aims for carbon neutrality by 2050

    27 October 2023

    iKhokha, Shopstar pave the way for simpler e-commerce

    27 October 2023

    Flutter vs React Native: a comprehensive comparison

    27 October 2023
    Opinion

    Big banks, take note: PayShap should be free

    20 October 2023

    Eskom rolling out virtual wheeling – here’s how it works

    4 October 2023

    How blockchain can help defeat the scourge of counterfeit goods

    29 September 2023

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2023 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.