In their Annual cybernetic threats report, the cybersecurity firm Symantec says that they’ve blocked almost 4 million attacks of this type over the last year.
The Hijacking of data or Ransomware and Cryptojacking or use of a third party’s computer to mine cryptocurrencies, considered as the main cyber threats in the last years, a new one joins, Formjacking.
This modality comes into play when infected web servers remove the billing information of customers. In fact, during each month of 2018, more than 4.800 web sites were compromised by a Formjacking code. The cybersecurity firm Symantec says that they’ve blocked almost 4 million attacks of this type.
How does it work
In their Annual threats report, the company explains that formjacking has shown an exponential growth (and possibly big earnings for the delinquents), projecting a possible increase this year.
“By using third-party apps to infiltrate in the websites more frequently, formjacking also illustrates even further the dangers of the supply chain attacks, a growing weakness highlighted in last year’s report,†the firm indicated.
The crime operates with just a few simple lines of code loaded in a website, representing a significant threat for online retailers or anyone who collects personal identity information of their clients through their website.
Even though authorities and cybersecurity companies have strongly attacked modalities like ransomware and cryptojacking, these haven’t disappeared.
The report reflects that with cryptocurrencies devaluation, becoming rich through cryptojacking isn’t as easy as before, and some attackers have switched to more lucrative activities.
However, according to Symantec, the attacks are easy to instigate and manage, which means that those criminals who participate in the game in the long term can still make money. That firm claims to have blocked four times more cryptojacking attacks last year than in 2017 and stresses that it continues to be an active threat in 2019.
On the other hand, ransomware continues to offer the opportunity to generate large sums of money. The SamSam gang is estimated to have made $ 6 million from such attacks.
These criminals are increasingly targeting companies, a high-value target. Ransomware infections grew in business environments by 12%, while consumer infections decreased.
Consumers likely benefited from their increasing use of mobile devices, as criminals prefer Office attachments in email messages and PowerShell scripts, which do not work as well on mobile devices, to carry out their attacks. Ransomware.
“Despite these discoveries, the threat landscape is not just about crime and the search for money. Governments quickly adopted the internet for espionage and have used it for destructive purposes. At the end of last year, Shamoon re-emerged remarkably after a two-year absence, deploying file-deleting malware on computers in specific organizations in the Middle East,†Symantec explained.
Almost one in ten targeted attack groups already use malware to destroy and disrupt business operations, up 25% from the previous year.
“As attackers continue to use our tools against us, detection must evolve from identifying malware to determining intent. Solutions based on machine learning and advanced artificial intelligence, such as TAA, are increasingly crucial to detect attacksâ€, said Daryan Reinoso, Engineering Manager for Latin America at Symantec.
According to Reinoso, “it seems that no one would voluntarily carry a device that allows someone to spy on every thought, conversation, and movement. But today’s headlines indicate that we do. That device is our smartphone, and it’s not just about spymasters looking for information about us. Even legitimate applications are spying on us.â€
Staying safe online
If you have any type of online shop or website that collects sensitive data from clients, a dedicated server is the safest option you have to keep your business and clients safe.
ServerPronto offers the best affordable and secure hosting service in all dedicated server packages.
Comments are closed.