ESET Threat Report T2 2022: RDP attacks see further drop; India among countries with the highest number of Android trojan detections

 ESET has released its T2 2022 Threat Report, summarizing key statistics from ESET detection systems, and highlighting notable examples of ESET’s cybersecurity research. The latest issue of the ESET Threat Report (covering May to August 2022) sheds light on the changes in ideologically motivated ransomware, spyware trojans, Emotet activity, the most-used phishing lures, how the plummeting cryptocurrency exchange rates affected online threats, and the continuation of the sharp decline of Remote Desktop Protocol (RDP) attacks. ESET analysts think these attacks continued to lose their steam due to the Russia-Ukraine war, along with the post-COVID return to offices and overall improved security of corporate environments.

Even with declining numbers, Russian IP addresses continued to be responsible for the largest portion of RDP attacks. “In T1 2022, Russia was also the country that was most targeted by ransomware, with some of the attacks being politically or ideologically motivated by the war. However, ESET Threat Report T2 2022 shows that this hacktivism wave has declined in T2, and ransomware operators turned their attention towards the United States, China, and Israel,” explains Roman Kováč, Chief Research Officer at ESET.

Android threat detections continued to grow in T2 2022 by 9.5%, with India named among countries with most detections of Android/Spy.Agent trojan with various spying capabilities, including secretly recording audio and video. Behind a large portion of Android spyware detection in the past four months was “GB WhatsApp” – a popular but cloned (and therefore unofficial) third-party version of WhatsApp. The cloned app is not available on Google Play and therefore there are no security checks in place compared with the legitimate WhatsApp, and versions available on various download websites are riddled with malware.

Further, the biggest zombie IoT botnet ‘Mozi’ saw the number of bots drop by 23% from 500,000 compromised devices in T1 to 383,000 in T2. However, China (53%) and India (35%) continued to have the highest number of IoT bots geolocated inside the respective countries. These statistics confirm the assumption that the Mozi botnet is on autopilot, running without human supervision since its reputed author was arrested in 2021.

According to ESET telemetry, August was a vacation month for the operators of Emotet, the most influential downloader strain. The gang behind it also adapted to Microsoft’s decision to disable VBA macros in documents originating from the internet and focused on campaigns based on weaponized Microsoft Office files and LNK files.

The report also examines threats mostly impacting home users. ESET phishing feeds showed a sixfold increase in shipping-themed phishing lures, most of the time presenting the victims with fake DHL and USPS requests to verify shipping addresses. “In terms of threats directly affecting virtual and physical currencies, a web skimmer known as Magecart remains the leading threat going after online shoppers’ credit card details. We also saw a twofold increase in cryptocurrency-themed phishing lures and a rising number of cryptostealers,” explains Kováč.

The ESET T2 2022 Threat Report also reviews the most important findings and achievements by ESET researchers. They uncovered a previously unknown macOS backdoor, and later attributed it to ScarCruft, discovered an updated version of the Sandworm APT group’s ArguePatch malware loader, uncovered Lazarus payloads in trojanized apps, and analyzed an instance of the Lazarus Operation In(ter)ception campaign targeting macOS devices while spearphishing in crypto-waters. ESET researchers also discovered buffer overflow vulnerabilities in Lenovo UEFI firmware and a new campaign using a fake Salesforce update as a lure.

Besides these findings, the report also summarizes the many talks given by ESET researchers in recent months, and introduces talks planned for AVAR, Ekoparty, and many other conferences.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More like this

ESET

ESET Threat Report details targeted attacks connected to the...

The number of RDP attacks dropped for the first time since the beginning of 2020 (-43%), with...
ESET launches a global search for ‘Heroes of Progress’, looking for the most progressive minds of the 21st century

ESET launches a global search for ‘Heroes of Progress’,...

Nominations are now open for people around the globe to nominate  their ‘Heroes of Progress’ New Delhi —...
ESET launches Safer Kids Online platform in India to safeguard children’s cyber safety

ESET launches Safer Kids Online platform in India to...

Mumbai, India – 18 April 2022 – ESET, a global leader in digital security, today launches its Safer Kids Online platform...

LATEST NEWS

BCCI New Contract Clause : BCCI Plans New Contract Clause to Stop Players Opting Out

BCCI New Contract Clause : BCCI Plans New Contract Clause to Stop Players Opting Out : The Board of Control for Cricket in India...

How to watch National Games 2025 on TV & Onlinr for Free?

National Games 2025 : The much awaited National Games 2025 has kicked off, bringing together some of India's top athletes in an intense battle...

Aston Villa’s Jhon Duran Set for €77m Move to Al Nassr: Medical Imminent

Aston Villa's Colombian forward, Jhon Duran, is on the verge of completing a €77 million transfer to Saudi Arabian giants Al Nassr. Set to...

iPhone 17’s Dynamic Island Revealed: No Size Change from iPhone 16

Hey there, Apple fans! If you’ve been keeping up with the latest iPhone rumors, you’ve probably heard some buzz about the iPhone 17 lineup....

Featured