Security Focus Africa April 2020

Page 26

CYBERSECURITY

Over a third of banking malware attacks in 2019 targeted corporate users Banking Trojans or ‘bankers’ are one of the most widespread tools for cybercriminals as they focus on stealing money.

I

n 2019, 773,943 users of Kaspersky solutions globally were attacked by banking Trojans. Of those users, a third (35.1 per cent) were in the corporate sector. African countries were affected too: almost every hundredth user (varying from 0,9 to 1 per cent) in South Africa, Ethiopia, Nigeria and Kenya was attacked by banking Trojans at least once during the past year, yet the share of affected corporate users varied greatly in these countries. This is among the findings from Kaspersky's analysis of the financial threat landscape. Banking Trojans or ‘bankers’ are one of the most widespread tools for cybercriminals as they focus on stealing money. Bankers usually search for users’ credentials for e-payment and online banking systems, hijacking onetime passwords, and then passing that data to the attackers. A third of these attacks in 2019 targeted corporate users, an increase from the figure (24-25 per cent) that has remained fairly consistent for the previous three years. According to experts, the rationale of this is clear: attacks on the B2B sector could not only provide access to banking or payment system accounts, but, through employee exposure, could also compromise a company’s financial resources. The collected data also shows that Ethiopia has the largest share of corporate users among those who are targeted by banking malware in African regions – it reached 71 per cent in 2019, which means that almost two thirds of banking malware attacks in the country were aimed at the corporate sector. It is followed by South Africa, where this figure is significantly smaller and can be compared to the global number, reaching 30 per cent. Kenya and Nigeria, however, saw this parameter being lower than average, with approximately a fifth (22.5 per cent) of banking malware attacks in Kenya targeting corporate devices, compared to 13 per cent in Nigeria. “While the overall number of attacks with bankers decreased in 2019, the growing interest for corporate users’ credentials indicates we are not yet seeing respite from

24

SECURITY FOCUS AFRICA APRIL 2020

financial threats. We therefore ask everyone to stay cautious when conducting financial operations online from PCs. While we are in the current peak of remote working during the Coronavirus pandemic, it is especially important to not underestimate criminals’ desire for stealing money,” said Oleg Kupreev, security expert at Kaspersky.

The key findings of the report Phishing • In 2019, the share of financial phishing increased from 44.7 per cent of all phishing detections to 51.4 per cent. • Almost every third attempt to visit a phishing page blocked by Kaspersky products was related to banking phishing (27 per cent). • The share of phishing-related attacks on payment systems and online stores accounted for almost 17 per cent and over 7.5 per cent respectively in 2019. This is more or less the same as 2018 levels. • The share of financial phishing encountered by Mac users fell slightly, accounting for 54 per cent.

Banking malware (Windows) • In 2019, the number of users attacked with banking Trojans was 773,943 – a decrease compared to the 889,452 attacked in 2018. • 35.1 per cent of users attacked with banking malware were corporate users – an increase from 24.1 per cent in 2018. • Users in Russia, Germany, and China were attacked most frequently by banking malware.

Android banking malware • In 2019, the number of users that encountered Android banking malware dropped to just over 675,000 from around 1.8 million.

• Russia, South Africa, and Australia were the countries with the highest percentage of users attacked by Android banking malware. Threats targeting businesses, such as banking Trojans and financial phishing, can and should be detected and blocked on a network level – even before they reach employee’s endpoints. In particular, the use of a secure Internet gateway solution like Kaspersky Security for Internet Gateway, ensures secure Internet traffic and transactions and prevents many types of malware and threats. Kaspersky solution has received positive honest customer feedback and been named a 2020 ‘Customers’ Choice for Secure Web Gateways’ , according to Gartner Peer Insights Customers’ Choice. In addition to this, Kaspersky experts advise businesses take the following measures against financial threats: • Invest in regular cybersecurity awareness training for employees to educate them not to click on links or open attachments received from untrusted sources. Conduct a simulated phishing attack to ensure that they know how to distinguish phishing emails. • Leverage advanced detection and response technologies, such as Kaspersky Endpoint Detection and Response – part of the Threat Management and Defense solution. It makes it possible to catch even unknown banking malware and gives security operation teams full visibility over the network and response automation. • Use mobile protection solutions or corporate Internet traffic protection to ensure employees’ devices are not exposed to financial and other threats. The last one helps protect even those devices for which an anti-virus is not available • Provide your security operation center team with access to Threat Intelligence so it remains up to date with the latest tactics and tools used by cybercriminals.

securityfocusafrica.com


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

Going into level 4

6min
pages 32-33

316-grade stainless steel turnstiles for KZN factory

2min
page 31

Kyocera awarded ISO 27001 accreditation

1min
page 30

Cyber Security South Africa appoints Simon Perry as CTO

1min
page 30

MyCyberCare bundles provide total cybersecurity protection

3min
page 29

FLIR launches smart thermal sensor solution

1min
page 28

MorphoWave Compact Delivering frictionless access everywhere

1min
page 28

Taking the guesswork out of tracking your guards

1min
page 27

Over a third of banking malware attacks in 2019 targeted corporate users

4min
page 26

Four ways to keep your remote workforce safe

4min
pages 24-25

Digital document revolution: A cautionary note

7min
pages 22-23

Security Focus Africa April 2020

6min
pages 20-21

In conversation with... Dilnaaz Ally

6min
pages 18-19

Banking security Trends and technology in Covid-19 times and beyond

8min
pages 15-17

The global cash industry Trends and warnings as CIT heists spiked again in SA in early 2020 

9min
pages 12-14

IziCash Solutions

4min
pages 10-11

Of character, courage and reinvention

5min
page 6
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.