Press Release

Mar
24

New Security Report from WatchGuard Shows Explosion in Evasive Malware

Subhead
Report finds macOS adware and 2017 Excel exploit running rampant and includes analysis of keylogger malware used in coronavirus-related phishing attacks.

Body

24 March 2020WatchGuard® Technologies’ latest Internet Security Report shows that evasive malware has grown to record high levels, with over two-thirds of malware detected by its Firebox security appliances in Q4 2019 evading signature-based antivirus solutions. This is a dramatic increase from the year-long average of 35% for 2019 and points to the fact that obfuscated or evasive malware is becoming the rule, not the exception. Companies of all sizes need to deploy advanced anti-malware solutions that can detect and block these attacks.

In addition, WatchGuard found widespread phishing campaigns exploiting a Microsoft Excel vulnerability from 2017. This ‘dropper’ exploit was number seven on WatchGuard’s top ten malware list and heavily targeted the UK, Germany and New Zealand. It downloads several other types of malware onto victims’ systems, including a keylogger named Agent Tesla that was used in phishing attacks in February 2020 that preyed on early fears of the coronavirus outbreak.

“Our findings from Q4 2019 show that threat actors are always evolving their attack methods,” said Corey Nachreiner, chief technology officer at WatchGuard. “With over two-thirds of malware in the wild obfuscated to sneak past signature-based defenses, and innovations like Mac adware on the rise, businesses of all sizes need to invest in multiple layers of security. Advanced AI or behavioural-based anti-malware technology and robust phishing protection like DNS filtering will be especially crucial.”

WatchGuard’s Internet Security Report prepares businesses, service providers and end users with the data, trends, research and best practices they need to defend against today’s security threats. Other key findings from the Q4 2019 report include:

 

  • Mac adware jumps in popularity in Q4 – One of the top compromised websites WatchGuard detected in Q4 2019 hosts a macOS adware called Bundlore that masquerades as an Adobe Flash update. This lines up with a MalwareBytes report from February 2020 that showed a rise in Mac malware, particularly adware.
  • SQL injection attacks became the top network attack in 2019 – SQL injection attacks rose an enormous 8000% in total between 2018 and 2019, becoming the most common network attack of the year by a significant margin.
  • Hackers increasingly using automated malware distribution – Many attacks hit 70 to 80 percent of all Fireboxes in a single country, suggesting attackers are automating their attacks more frequently.

 

The findings included in WatchGuard’s Internet Security Report are drawn from anonymised Firebox Feed data from active WatchGuard UTM appliances whose owners have opted in to share data to support the Threat Lab’s research efforts. Today, over 40,000 appliances worldwide contribute threat intelligence data to the report. In Q4 2019, they blocked over 34,500,000 malware variants in total (859.5 samples per device) and approximately 1,879,000 network attacks (47 attacks per device).

The complete report also includes key defensive best practices that organisations of all sizes can use to protect themselves in today’s threat landscape and a detailed analysis the MageCart JavaScript malware used in the Macy’s payment card data breach in October 2019.

For more information, download the full report here.

About WatchGuard Technologies, Inc.

WatchGuard® Technologies, Inc. is a global leader in network security, secure Wi-Fi, multi-factor authentication, and network intelligence. The company’s award-winning products and services are trusted around the world by nearly 10,000 security resellers and service providers to protect more than 80,000 customers. WatchGuard’s mission is to make enterprise-grade security accessible to companies of all types and sizes through simplicity, making WatchGuard an ideal solution for midmarket businesses and distributed enterprises. The company is headquartered in Seattle, Washington, with offices throughout North America, Europe, Asia Pacific, and Latin America. To learn more, visit WatchGuard.com.

For additional information, promotions and updates, follow WatchGuard on Twitter, @WatchGuardUK on Facebook, or on the LinkedIn Company page. Also, visit our InfoSec blog, Secplicity, for real-time information about the latest threats and how to cope with them at www.secplicity.org. Subscribe to The 443 – Security Simplified podcast at Secplicity.org, or wherever you find your favorite podcasts.

WatchGuard is a registered trademark of WatchGuard Technologies, Inc. All other marks are property of their respective owners.

 

 

 

Media Contacts

Chris Warfield
WatchGuard Technologies
206.876.8380

Peter Rennison
PRPR
1442 245030

 


All Press Releases >