Cyber Risk Leaders Magazine - Issue 6, 2021

Page 35

MySecurity Marketplace: Updates & Recent Highlights

New Insights into The Devilstongue Spyware Impacting Journalists, Human Rights Defenders and Politicians By MySecurity Media Courtesy of ESET

E

SET has released its T2 2021 Threat Report highlighting several concerning trends that were recorded by ESET telemetry, including increasingly aggressive ransomware tactics, intensifying brute-force attacks, and deceptive phishing campaigns. That is those targeting people working from home who have gotten used to performing many administrative tasks remotely. Ransomware, showing three major detection spikes during T2, saw the largest ransom demands to date. The attack shutting down the operations of Colonial Pipeline. That is the largest pipeline company in the US. As well as the supply-chain attack leveraging a vulnerability in the Kaseya VSA IT management software, sent shockwaves that were felt far beyond the cybersecurity industry. Both cases appeared to pursue financial gain rather than cyberespionage, with the perpetrators of the Kaseya attack setting a USD 70 million ultimatum. That is the heftiest known ransom demand so far. “Ransomware gangs may have overdone it this time: the involvement of law enforcement in these high-impact incidents forced several gangs to leave the field. The same can’t be said for TrickBot, which appears to have bounced back from last year’s disruption efforts, doubling in our detections and boasting new features,” explains Roman Kováč, chief research officer at ESET. On the other hand, the final shutdown of Emotet at the end of April 2021 saw downloader detections down by half compared to T1 2021 and a reshuffling of the whole threat landscape.

Password-guessing attacks, which often serve as a gateway for ransomware, saw further growth in T2. Between May and August 2021, ESET detected 55 billion new bruteforce attacks (+104% compared to T1 2021) against publicfacing Remote Desktop Protocol services. ESET telemetry also saw an impressive increase in the average number of daily attacks per unique client, which doubled from 1,392 attempts per machine per day in T1 2021 to 2,756 in T2 2021. The report also found highly targeted was DevilsTongue spyware (see page 12&13 of the report). It is used to spy on human rights defenders, dissidents, journalists, activists, and politicians; and a new spear phishing campaign by the Dukes APT group, which remains a prime threat to Western diplomats, NGOs, and think tanks. A separate section describes new tools employed by the highly active Gamaredon threat group targeting governmental organizations in Ukraine.

Cyber Risk Leaders Magazine | 35


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

ASITII FESTIVAL OF SPACE 2021

1min
pages 54-55

Cyber Risk Leaders - INTERVIEWS

1min
pages 47, 51, 57-58

AUDITING AI & EMERGING TECHNOLOGY

1min
page 33

6G A paradigm shift and physical layer security

1min
page 21

Lim Thian Chin

1min
page 20

SECURITY REIMAGINED- LEARN HOW TO IMPLEMENT ACTIONABLE INTELLIGENCE FOR EFFICIENT SAFE ENVIRONMENTS

1min
page 25

NOMINATIONS OPEN ON 8TH MARCH 2022*

1min
page 45

Group-IB Chief Executive Officer facing treason charge following arrest

2min
page 46

Facebook’s network backbone breaks, causing six hour outage

2min
page 44

President Biden Warns "Lock Your Digital Doors"

2min
page 42

Beware of the return to office: How organisations can protect against pandemic sleeper threats

5min
pages 40-41

How to empower your people to become your greatest risk management asset

3min
pages 38-39

Why organisational risk starts and ends with your people

4min
pages 36-37

New Insights into The Devilstongue Spyware Impacting Journalists, Human Rights Defenders and Politicians

1min
page 35

Market opportunities for 5G, IoT and edge compute

7min
pages 28-30

Network and Data Center Security

7min
pages 26-27

Singapore Cyber Landscape – highlights at ISACA Singapore Chapter’s GTACS 2021 conference

3min
pages 22-23

Deepening collaborations for cybersecurity - Highlights from the Singapore international cyber week 2021

8min
pages 16-19

Trusted third party risk management

7min
pages 12-15

Turning cyber health scare into digital trust

5min
pages 10-11

Cyber Risk Leaders Magazine - Issue 6, 2021

4min
pages 1, 9-14
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.