sb-au logo
Story image

2018 sees 1,500% increase in coinmining malware - report

19 Dec 2018

Managed detection and response (MDR) provider eSentire has released its Annual Threat Report, which found that the cryptocurrency craze of 2018 helped drive a 1,500 percent increase in coinmining malware compared to 2017.

Coinmining malware mines cryptocurrency (typically Monero) directly on infected endpoint devices (CoinMiner) or in web browsers (Coinhive) when a user visits a website running malicious code.

Once infected, the coinmining malware silently mines cryptocurrency while consuming a significant amount of processor cycles, resulting in devices with sluggish performance and reduced battery life.

With the recent decline in the value of cryptocurrencies, the computing, power and cooling costs to legitimately mine cryptocurrencies now exceeds their value on the open market.

Monero-based malware does not face these same economic challenges as all of the mining costs are absorbed by the device owner, while all of the profit goes to the threat actor.

eSentire Threat Intelligence also observed that activity from botnets saw a 500% increase over 2017.

New exploits for multiple Internet of Things (IoT) devices including door controllers, security cameras, and digital video recorders (DVRs) helped massive global botnets such as Mirai and Satori to add even more compromised devices to their arsenal. 

This issue will only continue to grow as IoT forms the foundation of connected devices and smart city grids.

eSentire CEO Kerry Bailey says, “The exponential growth of cybersecurity threats each year represents a new normal that organisations must be prepared to deal with, as sophisticated tools like machine learning and artificial intelligence (AI) make it easier and more profitable for threat actors to execute attacks.”

“Staying ahead of emergent threats like botnets and coinmining malware presents significant financial, operational and personnel challenges for organisations, and underscores how crucial adopting emerging technologies such as AI blended with Managed Detection and Response (MDR) are to protecting assets."

Additional 2018 Annual Threat Report Findings:

  • The five most targeted industries are education, accounting, construction, real estate and biotechnology
  • Tuesday is the most popular day of the week for phishing attempts; with DocuSign, Office 365, and OneDrive the most popular lures used
  • DNS spoofing, when an attacker tries to reconfigure devices to trust a malicious DNS server, saw a 500% increase over 2017
  • Devices manufactured by 3COM and Cisco received the largest number of brute force attack attempts

Report methodology The eSentire Threat Intelligence team used data gathered from over 2,000 proprietary network and host-based detection sensors distributed globally across multiple industries.

Raw data was normalised and aggregated using automated machine-based processing methods.

Processed data was reviewed by a visual data analyst applying quantitative analysis methods.

Quantitative intelligence analysis results were further processed by a qualitative intelligence analyst resulting in a written analytical product.

eSentire’s 2018 Threat Report provides a yearlong overview, analysing all cyber threat events investigated by the eSentire security operations centre (SOC), while addressing three key areas: threat types, threat volume and attack types.

Each topic is divided into multiple sections, including visual data analysis, written analytical analysis, practical recommendations and key assumptions.

Story image
Video: 10 Minute IT Jams - The benefits of converged cloud security
Today, Techday speaks to Forcepoint senior sales engineer and solutions architect Matthew Bant, who discusses the benefits of a converged cloud security model, and the pandemic's role in complicating the security stack in organisations around the world.More
Link image
Put the pedal to the metal on the road to automation
Forrester data indicates that process automation was a strategic initiative for many organizations before COVID and remains so after. Catch this webinar to learn more about automation.More
Story image
Kaspersky releases new report on consumer’s approach to digital services
COVID-19 related restrictions and the necessity to stay indoors has influenced the way people approach digital services, making them more aware of how securely both they, and their housemates, use the internet.More
Story image
Plugging the gaps: Australian organisations are leaving their defence barriers wide open
Cybercriminals are are walking through the gaping holes in Australia’s organisational defences – gaps that leadership teams don’t even realise are there.More
Story image
Commvault launches Metallic in A/NZ region for first global expansion
The Australia and New Zealand region continues to be a priority market for Commvault, as cloud adoption across the region leads global averages, the company states.More
Story image
Fortinet SOARs to new heights of protection on the wings of AI & automation
Jon McGettigan, Fortinet A/NZ Regional Director, talks about SOAR (security orchestration, automation and response) and explains that effective SOAR starts with your security policy.More