sb-nz logo
Story image

Attacks targeting Cisco Webex extension explode in popularity - WatchGuard

22 Mar 2019

Network security solutions provider WatchGuard Technologies has issued its quarterly Internet Security Report for Q4 2018. 

It found that network attacks targeting a vulnerability in the Cisco Webex Chrome extension increased in popularity dramatically, rising to be the second-most common network attack after being almost non-existent in early 2018.

Phishing campaigns showed a dangerous increase in sophistication in Q4, with new attacks utilising advanced methods such as threatening to release recordings of users visiting adult content online, customising emails for specific targets and creating fake banking login web pages.

Based on data from tens of thousands of active WatchGuard Firebox appliances around the world, the report examines the top malware and network attacks targeting mid-market businesses and distributed enterprises today.

''There was a noticeable increase in advanced phishing attacks targeting high-value information this quarter,'' says WatchGuard Technologies CTO Corey Nachreiner.

''Now more than ever, it’s vital for businesses to take the layered approach to security, and deploy solutions that offer DNS-level filtering designed to detect and block potentially dangerous connections and automatically refer employees to resources that bolster phishing awareness and prevention.

“A combination of security controls and human training will help businesses avoid becoming hooked by phishing attacks.''

The insights, research and security best practices included in WatchGuard’s quarterly Internet Security Report aim to help organisations of all sizes understand the current cybersecurity landscape and better protect themselves, their partners and customers from emerging security threats.

The top takeaways from the Q4 2018 report include:

New network attack targets Cisco Webex Chrome extension

A new network attack targeting a remote code execution vulnerability in the Chrome extension for Cisco Webex exploded in popularity last quarter.

This vulnerability was disclosed and patched in 2017, but WatchGuard detected almost no network attacks targeting it until now.

Detections grew by 7,016 percent from Q3 to Q4.

This spike shows just how important it is to install security patches as soon as they are available.

New customised 'sextortion' phishing campaign on the rise  

A new 'sextortion' phishing attack was the second-most common attack that our malware engines detected in Q4 2018, mainly targeting APAC.

It accounts for almost half of all of the unique malware hashes detected in Q4 because the email phishing message is tailored to each recipient.

The message claims the sender has infected the victim's computer with a trojan and recorded them visiting adult websites.

It threatens to send these compromising images to their email contacts unless they pay a ransom. WatchGuard saw a significant amount of this malware in Q4 and all users should be on the lookout for these fake emails. 

16.5 percent of all Fireboxes were targeted by CoinHive cryptominer 

The most widespread malware variant in Q4 came from the popular CoinHive cryptominer family, showing that cryptomining remains a popular attack type.

Two of the top ten most common pieces of malware detected in Q4 were also cryptominers, carrying over from past quarters.

A major phishing attack leverages a fake bank page

Another widespread piece of malware in Q4 sent a phishing email with a fake, but highly realistic Wells Fargo login page to capture victim emails and passwords. Overall, WatchGuard saw a rise in sophisticated phishing attacks targeting banking credentials in Q4.

One ISP's filtering error routed Google traffic through Russia and China for 74 minutes  

The report includes technical analysis of a Border Gateway Protocol (BGP) hijack in November 2018 that inadvertently sent most of Google's traffic through Russia and China for a short time.

WatchGuard found that a Nigerian ISP called MainOne made a mistake in their routing filters, which then spread to Russian and Chinese ISPs and caused much of Google's traffic to be routed through these ISPs unnecessarily.

This accidental hijack highlights how insecure many of the underlying standards that the internet is based on are.

A sophisticated attack targeting these flaws could have potentially catastrophic consequences.

Network attacks rise after historic lows in mid-2018  

Network attacks rose 46 percent by volume and 167 percent in terms of unique signature hits in Q4 compared to Q3.

This follows a trend seen in previous years with attacks ramping up during the holiday season.

The Q4 ISR also includes a granular analysis of source code for the Exobot banking trojan.

This highly sophisticated malware attempts to steal banking and financial information from Android devices.

The WatchGuard Threat Lab's analysis includes a list of the 150 sites such as Amazon, Facebook Paypal and Western Union that Exobot can automatically target, as well as a detailed look at the UI an attacker using Exobot would use to push commands to infected devices.

These findings are based on anonymised Firebox Feed data from over 42,000 active WatchGuard UTM appliances worldwide.

In total, these Fireboxes blocked over 16 million malware variants (382 per device) and approximately 1,244,000 network attacks (29 per device) in Q4 2018.

Story image
Remote work continues, and endpoint security cited as a must
Nearly half of workers will stay remote after the pandemic ends, and two out of three IT professionals are concerned with endpoint misuse, according to Prey Software's new study.More
Story image
WatchGuard uncovers top cyber threat trends of Q4 2020
“The rise in sophisticated, evasive threat tactics last quarter and throughout 2020 showcases how vital it is to implement layered, end-to-end security protections."More
Story image
Hybrid IAM solutions are the way of the future, study states
“As this first-of-its-kind research shows, while IT leaders are faced with unique criteria and conditions that shape their IT strategy, hybrid IAM has emerged as a necessity."More
Story image
From Me to We: Partnerships & multiparty systems in the post-COVID-19 age
MPS is all about sharing data infrastructure between people and organisations - think along the lines of blockchain, distributed databases and ledgers.More
Story image
Kroll completes Redscan acquisition, expands cyber risk portfolio
With the addition of Redscan and its extended detection and response (XDR) enabled security operations centre (SOC) platform, Kroll expands its Kroll Responder capabilities to support a wider array of cloud and on-premise telemetry sources.More
Story image
AvePoint brings Salesforce Cloud Backup to channel partners
The product adds to the AvePoint suite of trusted Cloud Backup for Microsoft 365 and Dynamics 365 to provide managed service providers with backup and restore capabilities across multiple, popular SaaS providers.More