sb-nz logo
Story image

Cybercrime tools and services becoming increasingly democratised

07 Feb 2019

Cybercrime is becoming increasingly democratised - and not in a good way.

According to the second instalment of Check Point’s 2019 Security Report, the tools and services used to commit cybercrime have become well-managed with advanced attack methods now readily available to anyone willing to pay for them as part of the surging ‘malware-as-a-service’ industry.

“The second instalment of our 2019 Security Report shows how cyber-criminals are successfully exploring stealthy new approaches and business models, such as malware affiliate programs, to maximise their illegal revenues while reducing their risk of detection,” says Check Point Software Technologies chief marketing officer Peter Alexander.

“But out-of-sight shouldn’t mean out-of-mind: Even though cyberattacks during 2018 have been lower-profile, they are still damaging and dangerous.”

There were many highlights of the report, which included:

  • Cryptominers have been actively digging undetected on networks, having infected 10x more organisations than ransomware in 2018. However, only one in five IT security professionals were aware their company’s networks had been infected by mining malware. 37 percent of organisations around the world were affected by cryptominers in 2018, while 20 percent continue be hit every weel despite an 80 percent decline in cryptocurrency values.

  • Organisations are underestimating the threat risk of cryptominers, as just 16 percent stated cryptomining when asked what they rated as the biggest threat to their organisation - compared with phishing with 66 percent, ransomware with 54 percent, data breaches with 53 percent, and DDoS attacks with 34 percent. Check Point says this is concerning as cryptominers can easily act as stealth backdoors to download and launch other types of malware.

  • There has been a significant rise of malware-as-a-service, as the GandCrab Ransomware-as-a-Service affiliate program shows how amateurs can now profit from the ransomware extortion business as well. Users are able to keep up to 60 percent of the ransoms collected from victims, while the developers keep up to 40 percent. GandCrab has over 80 active affiliates, and within two months in 2018 had infected over 50,000 victims and claimed between US$300,000 and $600,000 in ransoms.

“By reviewing and highlighting these developments in the Report, organizations can get a better understanding of the threats they face, and how they prevent them impacting on their business.”

Story image
Fortinet promises free cybersecurity training until skills gap trend reverses
"We are committed to continue offering the entire catalogue of self-paced Network Security Expert training at no cost until we see the skills gap trend reverse."More
Story image
Dark net vendors wanting Bitcoin payments for unverified COVID-19 vaccines
As the medicines are being offered on the dark net, purchasers have no way of knowing whether they are genuine, according to Check Point.More
Story image
Entrust acquires HyTrust, with aim to improve data encryption solutions
Entrust says the acquisition will bolster its effort to deliver data protection and compliance solutions to its customers, while accelerating their digital transformations.More
Story image
APAC secure content management market to hit $2.2 billion by 2024
The proliferation of cloud-based deployments will largely drive this, the report says, as the COVID-19 pandemic motivates more enterprises to move their workloads to the cloud and rely more on the internet. More
Story image
Red Hat to acquire Kubernetes-native security provider StackRox
Red Hat will further expand its security offering, adding StackRox's complementary capabilities to strengthen integrated security across its open hybrid cloud portfolio.More
Story image
IronNet expands Asia Pacific presence with new strategic partnership
“The combination of M.Tech’s extensive network in Asia Pacific and our unparalleled expertise in threat intelligence and detection will help more enterprises across the region to proactively identify and take down known and unknown threats before they happen.”More