Lokibot, AgentTesla Grow in January 2023’s Most Wanted Malware List

Checkpoint announced Global Threat Index The January 2023 report shows that AgentTesla is back at #3 on the Most Wanted Malware list for January 2023 (up from #9 in December 2022).of lokibot infostealer also grew significantly, going from not being on the top 10 list to number two.

In addition, infostealer further away It’s back on the Top 10 list after an uptick in “brandjacking” cases. It was also observed spreading via a fake domain claiming to be associated with the remote desktop software company AnyDesk.

“This malware used URL jacking of various popular applications to redirect people to a single IP address that claimed to be the official website of AnyDesk. Steals sensitive information by impersonating a malicious installer,” wrote Check Point.

According to the latest edition of the company’s Global Threat Index, A major campaign called “Earthbogle”It relied on the njRAT malware and targeted entities in North Africa and the Middle East.

“The attackers used phishing emails with geopolitical themes to trick users into opening malicious attachments,” the report states. “Once downloaded and opened, a Trojan can infect a device and allow an attacker to carry out numerous intrusive activities to steal sensitive information.”

Qbot remains the most-wanted malware in January 2023, and the industries targeted by threat actors (education/research, government/military, healthcare) are: December 2022.

Web server flaw Public GitHub repository information October was the top most exploited vulnerability in January, followed by the HTTP Header Remote Code Execution (RCE) flaw and the MVPower DVR RCE bug.

“Malware groups continue to use trusted brands to spread viruses and steal personally identifiable information,” said Maya Horowitz, vice president of research at Check Point Software.

“Watch out for security padlocks that indicate your SSL certificate is up-to-date, and watch out for hidden typos that could suggest the website is malicious.”

A good example is a malicious package using the typosquatting technique Recently discovered by ReversingLabs On the open source JavaScript npm repository.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *