CVE-2020-0986
published 2020-06-09CVE-2020-0986: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege…
PriorityP185high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
15.93%
96.5th percentile
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1903_for_32-bit_systems | — | — |
| microsoft | windows_10_version_1903_for_arm64-based_systems | — | — |
| microsoft | windows_10_version_1903_for_x64-based_systems | — | — |
| microsoft | windows_10_version_1909_for_32-bit_systems | — | — |
| microsoft | windows_10_version_1909_for_arm64-based_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·No operational IOCs, detection rules, or technical exploitation details for CVE-2020-0986 are present in the provided sources. The only reference to CVE-2020-0986 across all documents is a passing mention in a related-CVE list (DOC 1) and a hyperlinked article title 'Operation PowerFall: CVE-2020-0986 and variants' (DOC 3, DOC 7) — neither of which contains extractable verbatim technical content about the vulnerability. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9m7m-rrw7-f987: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1274 [HIGH] CWE-269 GHSA-9m7m-rrw7-f987: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-rxhf-h39p-vq9j: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1264 [HIGH] CWE-269 GHSA-rxhf-h39p-vq9j: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-jh7p-456p-4q3c: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1316 [HIGH] CWE-269 GHSA-jh7p-456p-4q3c: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307.
GHSA
GHSA-hcx5-24rg-5xcx: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1276 [HIGH] CWE-269 GHSA-hcx5-24rg-5xcx: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-j9vm-rq93-rmmr: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1262 [HIGH] CWE-269 GHSA-j9vm-rq93-rmmr: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-q6c4-7rr6-9mg4: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1273 [HIGH] CWE-269 GHSA-q6c4-7rr6-9mg4: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-rmg9-g6x4-vx5p: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1307 [HIGH] CWE-269 GHSA-rmg9-g6x4-vx5p: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1316.
GHSA
GHSA-gj7c-7r54-c65q: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1275 [HIGH] CWE-269 GHSA-gj7c-7r54-c65q: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-5wgx-4x92-f6pf: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-0986 [HIGH] CWE-269 GHSA-5wgx-4x92-f6pf: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-hj7x-99vw-89x3: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privileg
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1237 [HIGH] CWE-269 GHSA-hj7x-99vw-89x3: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privileg
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-v75v-vfwj-prp7: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1269 [HIGH] CWE-269 GHSA-v75v-vfwj-prp7: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-fhjp-896q-75gm: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1266 [HIGH] CWE-269 GHSA-fhjp-896q-75gm: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
GHSA
GHSA-445r-ccfr-pjc2: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1246 [HIGH] CWE-269 GHSA-445r-ccfr-pjc2: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
Project0
Déjà vu-lnerability - Project Zero
project_zero·2021-02-01
CVE-2014-9665 Déjà vu-lnerability - Project Zero
A Year in Review of 0-days Exploited In-The-Wild in 2020
Posted by Maddie Stone, Project Zero
2020 was a year full of 0-day exploits. Many of the Internet’s most popular browsers had their moment in the spotlight. Memory corruption is still the name of the game and how the vast majority of detected 0-days are getting in. While we tried new methods of 0-day detection with modest success, 2020 showed us that there is still a long way to go in detecting these 0-day exploits in-the-wild. But what may be the most notable fact is that 25% of the 0-days detected in 2020 are closely related to previously publicly disclosed vulnerabilities. In other words, 1 out of every 4 detected 0-day exploits could potentially have been avoided if a more thorough investigation and patching effort were explor
VulnCheck
Microsoft Windows Kernel Privilege Escalation Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-0986 [HIGH] CWE-787 Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://securelist.com/ie-and-windows-zero-day-operation-powerfall/97976/; https://decoded.avast.io/janvojtesek/magnitude-exploit-kit-still-alive-and-kicking/; https://securelist.com/apt-trends-report-q2-2021/103517/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-0
Project0
Project Zero RCA: CVE-2020-0986: Windows splwow64 Untrusted Pointer Dereference
project_zero·CVSS 7.8
CVE-2020-0986 [HIGH] Project Zero RCA: CVE-2020-0986: Windows splwow64 Untrusted Pointer Dereference
# CVE-2020-0986: Windows splwow64 Untrusted Pointer Dereference
*Maddie Stone, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2020-09-02)*
## The Basics
**Disclosure or Patch Date:**
* 19 May 2020 (ZDI Disclosure)
* 9 June 2020 (Microsoft Advisory/Patch)
* 12 Aug 2020 (Kaspersky blog post about in-the-wild exploitation)
**Product:** Microsoft Windows
**Advisory:**
* ZDI: https://www.zerodayinitiative.com/advisories/ZDI-20-663/
* Microsoft: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0986
* Kaspersky: https://securelist.com/ie-and-windows-zero-day-operation-powerfall/97976/
**Affected Versions:** For Windows 10 1909/1903, [KB4556799](https://support.microsoft.com/en-us/help/4556799/windows-10-u
Project0
Project Zero RCA: CVE-2020-1380: Internet Explorer JScript9 Use-after-Free
project_zero·CVSS 7.8
CVE-2020-1380 [HIGH] Project Zero RCA: CVE-2020-1380: Internet Explorer JScript9 Use-after-Free
# CVE-2020-1380: Internet Explorer JScript9 Use-after-Free
*Maddie Stone & Samuel Groß, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2020-08-24)*
## The Basics
**Disclosure or Patch Date:** 11 August 2020
**Product:** Microsoft Internet Explorer
**Advisory:** https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1380
**Affected Versions:** For Windows 10 2004, [KB4565503](https://support.microsoft.com/en-us/help/4565503/windows-10-update-kb4565503) and previous
**First Patched Version:** For Windows 10 2004, [KB4566782](https://support.microsoft.com/en-us/help/4566782/windows-10-update-kb4566782)
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Boris Larin (
CISA
Microsoft Windows Kernel Privilege Escalation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-0986 [HIGH] CWE-787 Microsoft Windows Kernel Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Kernel Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0986
Remediation Due Date: 2022-05-03
Microsoft
Windows Kernel Elevation of Privilege Vulnerability
vendor_msrc·2020-06-09·CVSS 7.8
CVE-2020-0986 [HIGH] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application to take control of an affected system.
The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory.
Microsoft Graphics Component: Microsoft Graphics Component
Microsoft: Microsoft
Impact: Elevation of Privilege
Ex
No detection rules found.
No public exploits indexed.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Securelist
APT trends report Q2 2021
blogs_securelist·2021-07-29
APT trends report Q2 2021
Table of Contents
The most remarkable findings
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For more than four years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q2 2021.
Readers who would like to learn
Securelist
APT trends report Q2 2021
blogs_securelist·2021-07-29
APT trends report Q2 2021
Table of Contents
- The most remarkable findings
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For more than four years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q2 2021.
Readers who would lik
Securelist
Kaspersky Security Bulletin 2020-2021. EU statistics
blogs_securelist·2021-05-26
Kaspersky Security Bulletin 2020-2021. EU statistics
Table of Contents
- Main figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
- Phishing in the EU
Authors
- Kaspersky
All statistics in this report are from the global cloud service Kaspersky Security Network (KSN), which receives information from components in our security solutions. The data was obtained from users who have given their consent to it being sent to KSN. Millions of Kaspersky users around the globe assist us in this endeavor to collect information about malicious activity. The statistics in this report cover the period from May 2020 to April 2021, inclusive.
## Main figures
- 70% of Internet user computers in the EU experienced at least
Securelist
Kaspersky Security Bulletin 2020-2021. EU statistics
blogs_securelist·2021-05-26
Kaspersky Security Bulletin 2020-2021. EU statistics
Table of Contents
Main figures
Financial threats
Number of users attacked by banking malware
Threat geography
Ransomware programs
Number of users attacked by ransomware Trojans
Threat geography
Top 10 most common families of ransomware Trojans
Miners
Number of users attacked by miners in the EU
Threat geography
Vulnerable applications used by cybercriminals
Attacks on macOS
Threat geography
IoT attacks
IoT threat statistics
Malware loaded into honeypots
Attacks via web resources
Countries that are sources of web-based attacks
Countries where users faced the greatest risk of online infection
Top 20 malicious programs most actively used in online attacks
Local threats
Countries where users faced the highest risk of local infection
Top 20 malicious objects detected on
Tenable
Microsoft’s January 2021 Patch Tuesday Addresses 83 CVEs
blogs_tenable·2021-01-12
Microsoft’s January 2021 Patch Tuesday Addresses 83 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
28th December – Threat Intelligence Report
blogs_checkpoint·2020-12-28
CVE-2020-29492 28th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Lazarus group, an APT affiliated with North Korea, has targeted two healthcare entities – Ministry of Health and a pharmaceutical company involved in a COVID-19 vaccine development, probably in order to collect information about the advancements in the pandemic research.
Microsoft software resellers have been leveraged
Securelist
ICS threat predictions for 2021
blogs_securelist·2020-12-02
ICS threat predictions for 2021
Authors
- Evgeny Goncharov
We present our vision of what challenges industrial cybersecurity will soon be (or already is) facing, and what to expect from cybercriminals in 2021.
## Random infections
1. Infections will tend to be less random or have non-random follow-ups, as cybercriminals have spent the past several years profiling randomly infected computers that are connected to industrial networks or have periodic access to them. Access to such computers will be — and is perhaps already being — resold to more sophisticated groups with specific schemes for monetizing attacks on industrial facilities already in place.
2. For several years now, various groups have specialized in attacks against industrial enterprises with the express aim to steal money — through BEC schemes or advanced
Securelist
Dox, steal, reveal. Where does your personal data end up?
blogs_securelist·2020-12-01
Dox, steal, reveal. Where does your personal data end up?
Table of Contents
- Unwanted spotlight: doxing
- The darknet database. How much do you cost?
- Key takeaways
- Protecting your data and yourself
- Know what they know
- Remove what you can
- Protect yourself
- When it is too late
- To sum up: take good care of yourself and your data
Authors
- Dmitry Galov
- Vladislav Tushkanov
- Leonid Bezvershenko
The technological shift that we have been experiencing for the last few decades is astounding, not least because of its social implications. Every year the online and offline spheres have become more and more connected and are now completely intertwined, leading to online actions having real consequences in the physical realm — both good and bad.
One of the most affected areas in this regard is communication and sharing of information, esp
Securelist
IT threat evolution Q3 2020
blogs_securelist·2020-11-20
IT threat evolution Q3 2020
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
## Targeted attacks
### MATA: Lazarus’s multi-platform targeted malware framework
The more sophisticated threat actors are continually developing their TTPs (Tactics, Techniques and Procedures) and the toolsets they use to compromise the systems of their targets. However, malicious toolsets used to target multiple platforms are rare, because they required significant investment to develop and maintain them. In July, we reported the use of an advanced, multi-purpose malware framework developed by the Lazarus group.
We discovered the first artefacts relating to this framework, dubbed ‘MATA’ (the authors named their infrastructure ‘MataNet’) in April 2018. Since then, Lazarus has further developed MATA; and there
Securelist
Targeted ransomware: it’s not just about encrypting your data!
blogs_securelist·2020-11-11
Targeted ransomware: it’s not just about encrypting your data!
Table of Contents
- Ragnar Locker
- Egregor
- Conclusions
- How to protect yourself
Authors
- Dmitry Bestuzhev
- Fedor Sinitsyn
## Part 1 - “Old and New Friends”
When we talk about ransomware, we need to draw a line between what it used to be and what it currently is. Why? Because nowadays ransomware is not just about encrypting data – it’s primarily about data exfiltration. After that, it’s about data encryption and leaving convincing proof that the attacker was in the network, and finally, it’s extortion. And again, it’s not about the data loss itself but about publishing stolen data on the internet. Let’s call it “Ransomware 2.0”.
Why is it so important to state this? Because many organizations still believe that it’s all about malware, and if your anti-malware protection is good
Securelist
APT trends report Q3 2020
blogs_securelist·2020-11-03
APT trends report Q3 2020
Table of Contents
- The most remarkable findings
- Europe
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For more than three years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2020.
Readers who
Securelist
APT trends report Q3 2020
blogs_securelist·2020-11-03
APT trends report Q3 2020
Table of Contents
The most remarkable findings
Europe
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For more than three years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2020.
Readers who would like
Securelist
Operation PowerFall: CVE-2020-0986 and variants
blogs_securelist·2020-09-02·CVSS 7.8
[HIGH] Operation PowerFall: CVE-2020-0986 and variants
Authors
Boris Larin
In August 2020, we published a blog post about Operation PowerFall . This targeted attack consisted of two zero-day exploits: a remote code execution exploit for Internet Explorer 11 and an elevation of privilege exploit targeting the latest builds of Windows 10. While we already described the exploit for Internet Explorer in the original blog post, we also promised to share more details about the elevation of privilege exploit in a follow-up post. Let’s take a look at vulnerability CVE-2020-0986, how it was exploited by attackers, how it was fixed and what additional mitigations were implemented to complicate exploitation of many other similar vulnerabilities.
## CVE-2020-0986
CVE-2020-0986 is an arbitrary pointer dereference vulnerability in GDI Print / Print Spoo
Securelist
Operation PowerFall: CVE-2020-0986 and variants
blogs_securelist·2020-09-02·CVSS 7.8
CVE-2020-0986 [HIGH] Operation PowerFall: CVE-2020-0986 and variants
Authors
- Boris Larin
In August 2020, we published a blog post about Operation PowerFall. This targeted attack consisted of two zero-day exploits: a remote code execution exploit for Internet Explorer 11 and an elevation of privilege exploit targeting the latest builds of Windows 10. While we already described the exploit for Internet Explorer in the original blog post, we also promised to share more details about the elevation of privilege exploit in a follow-up post. Let’s take a look at vulnerability CVE-2020-0986, how it was exploited by attackers, how it was fixed and what additional mitigations were implemented to complicate exploitation of many other similar vulnerabilities.
## CVE-2020-0986
CVE-2020-0986 is an arbitrary pointer dereference vulnerability in GDI Print/Print Spool
Securelist
Transparent Tribe: Evolution analysis, part 2 | Securelist
blogs_securelist·2020-08-26
Transparent Tribe: Evolution analysis, part 2 | Securelist
Authors
- Giampaolo Dedola
## Background + Key findings
Transparent Tribe, also known as PROJECTM or MYTHIC LEOPARD, is a highly prolific group whose activities can be traced as far back as 2013. In the last four years, this APT group has never taken time off. They continue to hit their targets, which typically are Indian military and government personnel.
This is the second of two articles written to share the results of our recent investigations into Transparent Tribe. In the previous article, we described the various Crimson RAT components and provided an overview of impacted users. Here are some of the key insights that will be described in this part:
- We found a new Android implant used by Transparent Tribe for spying on mobile devices. It was distributed in India disguised as a
Securelist
Internet Explorer and Windows zero-day exploits used in Operation PowerFall
blogs_securelist·2020-08-12·CVSS 7.5
[HIGH] Internet Explorer and Windows zero-day exploits used in Operation PowerFall
Authors
- Boris Larin
## Executive summary
In May 2020, Kaspersky technologies prevented an attack on a South Korean company by a malicious script for Internet Explorer. Closer analysis revealed that the attack used a previously unknown full chain that consisted of two zero-day exploits: a remote code execution exploit for Internet Explorer and an elevation of privilege exploit for Windows. Unlike a previous full chain that we discovered, used in Operation WizardOpium, the new full chain targeted the latest builds of Windows 10, and our tests demonstrated reliable exploitation of Internet Explorer 11 and Windows 10 build 18363 x64.
On June 8, 2020, we reported our discoveries to Microsoft, and the company confirmed the vulnerabilities. At the time of our report, the security team at Mi
Securelist
Internet Explorer and Windows zero-day exploits used in Operation PowerFall
blogs_securelist·2020-08-12·CVSS 7.5
[HIGH] Internet Explorer and Windows zero-day exploits used in Operation PowerFall
Authors
Boris Larin
## Executive summary
In May 2020, Kaspersky technologies prevented an attack on a South Korean company by a malicious script for Internet Explorer. Closer analysis revealed that the attack used a previously unknown full chain that consisted of two zero-day exploits: a remote code execution exploit for Internet Explorer and an elevation of privilege exploit for Windows. Unlike a previous full chain that we discovered, used in Operation WizardOpium, the new full chain targeted the latest builds of Windows 10, and our tests demonstrated reliable exploitation of Internet Explorer 11 and Windows 10 build 18363 x64.
On June 8, 2020, we reported our discoveries to Microsoft, and the company confirmed the vulnerabilities. At the time of our report, the security team at Micr
Securelist
DDoS attacks in Q2 2020
blogs_securelist·2020-08-10
DDoS attacks in Q2 2020
Table of Contents
- News overview
- Quarter trends
- Quarter statistics
Authors
- Oleg Kupreev
- Ekaterina Badovskaya
- Alexander Gutnikov
## News overview
Not just one but two new DDoS amplification methods were discovered last quarter. In mid-May, Israeli researchers reported a new DNS server vulnerability that lurks in the DNS delegation process. The vulnerability exploitation scheme was dubbed “NXNSAttack”. The hacker sends to a legitimate recursive DNS server a request to several subdomains within the authoritative zone of its own malicious DNS server. In response, the malicious server delegates the request to a large number of fake NS servers within the target domain without specifying their IP addresses. As a result, the legitimate DNS server queries all of the suggested subdom
Securelist
Spam and phishing in Q2 2020
blogs_securelist·2020-08-07
Spam and phishing in Q2 2020
Table of Contents
- Quarterly highlights
- Statistics: spam
- Statistics: phishing
- Conclusion
Authors
- Tatyana Kulikova
- Tatyana Sidorina
- Tatyana Shcherbakova
## Quarterly highlights
### Targeted attacks
The second quarter often saw phishers resort to targeted attacks, especially against fairly small companies. To attract attention, scammers imitated email messages and websites of companies whose products or services their potential victims could be using.
The scammers did not try to make any of the website elements appear credible as they created the fake. The login form is the only exception. One of the phishing websites we discovered even used a real captcha on that form.
The main pretext that scammers use to prompt the target to enter their information is offering an onl
Securelist
GReAT thoughts: Awesome IDA Pro plugins
blogs_securelist·2020-07-21
GReAT thoughts: Awesome IDA Pro plugins
Authors
- Boris Larin
The Global Research & Analysis Team here at Kaspersky has a tradition of meeting up once a month and sharing cutting-edge research, interesting techniques and useful tools. We recently took the unprecedented decision to make our internal meetings public for a few months and present them as a series of talks called ‘GReAT Ideas. Powered by SAS’. In the second edition that takes place on July 22, 2020, I’ll be talking about awesome IDA Pro plugins that I regularly use. This article is a sneak peek into what I’ll be discussing.
## Highlighting control-flow transfer instructions
When you are reverse-engineering a binary it’s very important to follow control-flow transfer instructions and especially those instructions that are used to transfer the control flow to other
Securelist
The Tetrade: Brazilian banking malware goes global
blogs_securelist·2020-07-14
The Tetrade: Brazilian banking malware goes global
Table of Contents
- Introduction
- Guildma: full of tricks
- Javali: big and furious
- Melcoz, a worldwide operator
- El Gran Grandoreiro
- Conclusions
- MD5
Authors
- GReAT
## Introduction
Brazil is a well-known country with plenty of banking trojans developed by local crooks. The Brazilian criminal underground is home to some of the world’s busiest and most creative perpetrators of cybercrime. Like their counterparts’ in China and Russia, their cyberattacks have a strong local flavor, and for a long time, they limited their attacks to the customers of local banks. But the time has come when they aggressively expand their attacks and operations abroad, targeting other countries and banks. The Tetrade is our designation for four large banking trojan families created, developed and sp
Securelist
Explicit content and cyberthreats: 2019 report
blogs_securelist·2020-06-15
Explicit content and cyberthreats: 2019 report
Authors
- Kaspersky
‘Stay at home’ is the new motto for 2020 and it has entailed many changes to our daily lives, most importantly, in terms of our digital content consumption. With users opting to entertain themselves online, malicious activity has grown. Over the past two years we have reviewed how adult content has been used to spread malware and abuse users’ privacy. This is a trend that’s unlikely to go away, especially under current circumstances. While many pornography platforms are enjoying an influx of new users and providing legitimate and safe services, the security risks remain, if not increase.
One of the key concerns that arises when it comes to adult content is the risk to privacy. Every passing year shows privacy is becoming an ever scarcer resource, with mobile devices
Checkpoint
25th May – Threat Intelligence Bulletin
blogs_checkpoint·2020-05-25
CVE-2020-0915 25th May – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 25th May – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 25th May 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Thousands of Israeli websites have been defaced in an Anti-Israeli Campaign carried out by the “Hacker of Savior” group. All websites were hosted on a local Israeli hosting company called uPress, and the attackers centrally exploited a vulnerability in a WordPress plugin to publish an anti-Israeli message on the websites’
Securelist
IT threat evolution Q1 2020. Statistics
blogs_securelist·2020-05-20
IT threat evolution Q1 2020. Statistics
Table of Contents
- Quarterly figures
- Mobile threats
- Attacks on Apple macOS
- IoT attacks
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyberattacks
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Oleg Kupreev
- Evgeny Lopatin
- Alexey Kulaev
These statistics are based on detection verdicts for Kaspersky products received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network,
- Kaspersky solutions blocked 726,536,269 attacks launched from online resources in 203 countries across the globe.
- A total of 442,039,230 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infe
Securelist
APT trends report Q1 2020
blogs_securelist·2020-04-30
APT trends report Q1 2020
Table of Contents
- COVID-19 APT activity
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southеast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For more than two years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q1 2020.
Readers who would like to lea
Securelist
A look at the ATM/PoS malware landscape from 2017-2019
blogs_securelist·2020-04-23
A look at the ATM/PoS malware landscape from 2017-2019
Table of Contents
- The world of ATM/PoS malware
- ATM/PoS malware attacks: by the numbers
- A look towards the future
Authors
- Kaspersky
From remote administration and jackpotting, to malware sold on the Darknet, attacks against ATMs have a long and storied history. And, much like other areas of cybercrime, attackers only refine and grow their skillset for infecting ATM systems from year-to-year. So what does the ATM landscape look like as of 2020? Let’s take a look.
## The world of ATM/PoS malware
ATM attacks aren’t new, and that’s not surprising. After all, what is one of the primary motives driving cyber criminals? Money. And ATMs are cash hubs—one successful attack can net you hundreds of thousands of dollars. In the past, even high-profile threat actors have made ATMs their p
Securelist
Financial Cyberthreats in 2019
blogs_securelist·2020-04-16
Financial Cyberthreats in 2019
Authors
- Kaspersky
## Methodology
Financial cyberthreats are malicious programs that target users of services such as online banking, e-money, and cryptocurrency, or that attempt to gain access to financial organizations and their infrastructure. These threats are usually accompanied by spam and phishing activities, with malicious users creating fake financial-themed pages and emails to steal victims’ credentials.
In order to study the threat landscape of the financial sector, our researchers analyzed malicious activity on the devices of individual users of Kaspersky’s security solutions. Statistics for corporate users were collected from corporate security solutions, after the customers agreed to share their data with Kaspersky.
The information obtained was compared with data for th
Securelist
Loncom packer: from backdoors to Cobalt Strike
blogs_securelist·2020-04-02
Loncom packer: from backdoors to Cobalt Strike
Authors
- Anton Kuzmenko
The previous story described an unusual way of distributing malware under disguise of an update for an expired security certificate. After the story went out, we conducted a detailed analysis of the samples we had obtained, with some interesting findings. All of the malware we examined from the campaign was packed with the same packer, which we named Trojan-Dropper.NSIS.Loncom. The malware uses legitimate NSIS software for packing and loading shellcode, and Microsoft Crypto API for decrypting the final payload. Just as the earlier find, this one was not without its surprises, as one of the packaged samples contained software used by APT groups.
## Primary analysis
Loncom utilizes NSIS for running shellcode contained in a file with a name that consists of number
Securelist
iOS exploit chain deploys LightSpy feature-rich malware
blogs_securelist·2020-03-26
iOS exploit chain deploys LightSpy feature-rich malware
Authors
- Alexey Firsh
- Kurt Baumgartner
- Brian Bartholomew
A watering hole was discovered on January 10, 2020 utilizing a full remote iOS exploit chain to deploy a feature-rich implant named LightSpy. The site appears to have been designed to target users in Hong Kong based on the content of the landing page. Since the initial activity, we released two private reports exhaustively detailing spread, exploits, infrastructure and LightSpy implants.
Landing page of watering hole site
We are temporarily calling this APT group “TwoSail Junk”. Currently, we have hints from known backdoor callbacks to infrastructure about clustering this campaign with previous activity. And we are working with colleagues to tie LightSpy with prior activity from a long running Chinese-speaking APT group, pre
Securelist
Cookiethief: a cookie-stealing Trojan for Android
blogs_securelist·2020-03-12
Cookiethief: a cookie-stealing Trojan for Android
Authors
- Anton Kivva
- Igor Golovin
We recently discovered a new strain of Android malware. The Trojan (detected as: Trojan-Spy.AndroidOS.Cookiethief) turned out to be quite simple. Its main task was to acquire root rights on the victim device, and transfer cookies used by the browser and Facebook app to the cybercriminals’ server. This abuse technique is possible not because of a vulnerability in Facebook app or browser itself. Malware could steal cookie files of any website from other apps in the same way and achieve similar results.
How can stealing cookies be dangerous? Besides various settings, web services use them to store on the device a unique session ID that can identify the user without a password and login. This way, a cybercriminal armed with a cookie can pass himself off
Securelist
Roaming Mantis, part V
blogs_securelist·2020-02-27
Roaming Mantis, part V
Table of Contents
- Distribution of Wroba.g via SMiShing with impersonated brands
- Allowlist feature of Wroba.g landing page for Korea only
- Multidex obfuscation trick in a loader module of Wroba.g
- Wroba.g is targeting carrier billing and online banks in Japan
- Wroba.j and Fakecop discovered in 2019
- Conclusion
- Further reading
- Example of md5 hashes for each APK
Authors
- Suguru Ishimaru
## Distributed in 2019 using SMiShing and enhanced anti-researcher techniques
Kaspersky has continued to track the Roaming Mantis campaign. The group’s attack methods have improved and new targets continuously added in order to steal more funds. The attackers’ focus has also shifted to techniques that avoid tracking and research: allowlist for distribution, analysis environment detection and
Securelist
KBOT: sometimes they come back
blogs_securelist·2020-02-10
KBOT: sometimes they come back
Authors
- Anna Malina
Although by force of habit many still refer to any malware as a virus, this once extremely common class of threats is gradually becoming a thing of the past. However, there are some interesting exceptions to this trend: we recently discovered malware that spread through injecting malicious code into Windows executable files; in other words, a virus. It is the first “living” virus in recent years that we have spotted in the wild.
We named it KBOT, and Kaspersky solutions detect the malware and its components as Virus.Win32.Kpot.a, Virus.Win64.Kpot.a, Virus.Win32.Kpot.b, Virus.Win64.Kpot.b, and Trojan-PSW.Win32.Coins.nav.
## What does KBOT do
KBOT penetrates users’ computers via the Internet or a local network, or from infected external media. After the infected fi
Securelist
Story of the year 2019: Cities under ransomware siege
blogs_securelist·2019-12-11
Story of the year 2019: Cities under ransomware siege
Table of Contents
- The besiegers
- Conclusion and recommendations
Authors
- Kaspersky
Ransomware has been targeting the private sector for years now.
Overall awareness of the need for security measures is growing, and cybercriminals are increasing the precision of their targeting to locate victims with security breaches in their defense systems. Looking back at the past three years, the share of users targeted with ransomware in the overall number of malware detections has risen from 2.8% to 3.5%. While this might seem like a modest amount, ransomware is capable of causing extensive damage in the affected systems and networks, which means this threat should never be overlooked. The proportion of ransomware targets among all users attacked with malware has been fluctuating, yet appea
Securelist
Windows 0-day exploit CVE-2019-1458 used in Operation WizardOpium
blogs_securelist·2019-12-10·CVSS 7.8
CVE-2019-1458 [HIGH] Windows 0-day exploit CVE-2019-1458 used in Operation WizardOpium
Authors
- AMR
- GReAT
In November 2019, Kaspersky technologies successfully detected a Google Chrome 0-day exploit that was used in Operation WizardOpium attacks. During our investigation, we discovered that yet another 0-day exploit was used in those attacks. The exploit for Google Chrome embeds a 0-day EoP exploit (CVE-2019-1458) that is used to gain higher privileges on the infected machine as well as escaping the Chrome process sandbox.
The EoP exploit consists of two stages: a tiny PE loader and the actual exploit. After achieving a read/write primitive in the renderer process of the browser through vulnerable JS code, the PE exploit corrupts some pointers in memory to redirect code execution to the PE loader. This is done to bypass sandbox restrictions because the PE exploit canno
Securelist
Biometric data processing and storage system threats
blogs_securelist·2019-12-02
Biometric data processing and storage system threats
Table of Contents
- Biometric data processing and storage
- Threats blocked on biometric data processing and storage systems
- Conclusion
Authors
- Kirill Kruglov
Initially, digital biometric data processing systems were used primarily by government agencies and special services (police, customs, etc.). However, the rapid evolution of information technology has made biometric systems accessible for ‘civil’ use. They are increasingly becoming part of our everyday lives, augmenting and replacing traditional authentication methods, such as those based on logins and passwords. Indeed, identifying people using characteristics that are unique to each person, such as fingerprints, voices, facial shapes or their distinctive eye structure, seems an obvious and incredibly convenient method.
To
Securelist
IT threat evolution Q3 2019. Statistics
blogs_securelist·2019-11-29
IT threat evolution Q3 2019. Statistics
Table of Contents
- Quarterly figures
- Mobile threats
- Attacks on Apple macOS
- IoT attacks
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyber attacks
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Boris Larin
- Oleg Kupreev
- Evgeny Lopatin
These statistics are based on detection verdicts of Kaspersky products received from users who consented to provide statistical data.
## Quarterly figures
According to Kaspersky Security Network:
- Kaspersky solutions blocked 989,432,403 attacks launched from online resources in 203 countries across the globe.
- 560,025,316 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infections by malware designed to steal money v
Securelist
Spam and phishing in Q3 2019
blogs_securelist·2019-11-26
Spam and phishing in Q3 2019
Table of Contents
- Quarterly highlights
- Statistics: spam
- Statistics: phishing
- Conclusion
Authors
- Maria Vergelis
- Tatyana Sidorina
- Tatyana Shcherbakova
## Quarterly highlights
### Amazon Prime
In Q3, we registered numerous scam mailings related to Amazon Prime. Most of the phishing emails with a link to a fake Amazon login page offered new prices or rewards for buying things, or reported problems with membership, etc. Against the backdrop of September’s Prime Day sale, such messages were plausible.
Scammers also used another fraudulent scheme: An email informed victims that their request to cancel Amazon Prime had been accepted, but if they had changed their mind, they should call the number in the message. Fearing their accounts may have been hacked, victims phoned the
Securelist
Advanced threat predictions for 2020
blogs_securelist·2019-11-20
Advanced threat predictions for 2020
Authors
- GReAT
Nothing is more difficult than making predictions. Rather than trying to gaze into a crystal ball, we will be making educated guesses based on what has happened during the last 12 months, to see where we can see trends that might be exploited in the near future.
This is what we think might happen in the coming months, based on the knowledge of experts in this field and our observation of APT attacks – since APT threat actors have historically been the center of innovation.
## The next level of false flag attacks
The use of false flags has become an important element in the playbook of several APT groups. In the past, this has generally involved trying to deflect attention away from those responsible for the attack – for instance, the usage of Russian words in Lazarus g
Securelist
Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium
blogs_securelist·2019-11-01·CVSS 8.8
CVE-2019-13720 [HIGH] Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium
Authors
- AMR
- GReAT
## Executive summary
Kaspersky Exploit Prevention is a component part of Kaspersky products that has successfully detected a number of zero-day attacks in the past. Recently, it caught a new unknown exploit for Google’s Chrome browser. We promptly reported this to the Google Chrome security team. After reviewing of the PoC we provided, Google confirmed there was a zero-day vulnerability and assigned it CVE-2019-13720. Google has released Chrome version 78.0.3904.87 for Windows, Mac, and Linux and we recommend all Chrome users to update to this latest version as soon as possible! You can read Google’s bulletin by clicking here.
Kaspersky endpoint products detect the exploit with the help of the exploit prevention component. The verdict for this attack is Exploit.Wi
Securelist
Steam-powered scammers
blogs_securelist·2019-10-28
Steam-powered scammers
Table of Contents
- It all starts with an online store
- Other varieties
- How to stay protected
Authors
- Mikhail Sytnik
Digital game distribution services have not only simplified the sale of games themselves, but provided developers with additional monetization levers. For example, in-game items, such as skins, equipment, and other character-enhancing elements as well as those that help one show up, can be sold for real money. Users themselves can also sell items to each other, with the rarest fetching several thousand dollars. And where there’s money, there’s fraud. Scammers try to get hold of login details to “strip” the victim’s characters and sell off their hard-earned items for a juicy sum.
Steam phishing attacks, January 2019 – September 2019
## It all starts with an online
Securelist
Hello! My name is Dtrack
blogs_securelist·2019-09-23
Hello! My name is Dtrack
Authors
- Konstantin Zykov
Our investigation into the Dtrack RAT actually began with a different activity. In the late summer of 2018, we discovered ATMDtrack, a piece of banking malware targeting Indian banks. Further analysis showed that the malware was designed to be planted on the victim’s ATMs, where it could read and store the data of cards that were inserted into the machines. Naturally, we wanted to know more about that ATM malware, so we used YARA and Kaspersky Attribution Engine to uncover more interesting material: over 180 new malware samples of a spy tool that we now call Dtrack.
All the Dtrack samples we initially found were dropped samples, as the real payload was encrypted with various droppers — we were able to find them because of the unique sequences shared by ATMDtra
Securelist
An advertising dropper in Google Play
blogs_securelist·2019-08-27
An advertising dropper in Google Play
Authors
- Igor Golovin
- Anton Kivva
Recently, the popular CamScanner – Phone PDF creator app caught our attention. According to Google Play, it has been installed more than 100 million times. The developers position it as a solution for scanning and managing digitized documents, but negative user reviews that have been left over the past month have indicated the presence of unwanted features.
After analyzing the app, we saw an advertising library in it that contains a malicious dropper component. Previously, a similar module was often found in preinstalled malware on Chinese-made smartphones. It can be assumed that the reason why this malware was added was the app developers’ partnership with an unscrupulous advertiser.
Kaspersky solutions detect this malicious component as Trojan-Dro
Securelist
IT threat evolution Q2 2019
blogs_securelist·2019-08-19
IT threat evolution Q2 2019
Table of Contents
- Targeted attacks and malware campaigns
- Other security news
Authors
- David Emm
## Targeted attacks and malware campaigns
### More about ShadowHammer
In March, we published the results of our investigation into a sophisticated supply-chain attack involving the ASUS Live Update Utility, used to deliver BIOS, UEFI and software updates to ASUS laptops and desktops. The attackers added a backdoor to the utility and then distributed it to users through official channels.
ASUS was not the only company used by the attackers. Other targets included several gaming companies, a conglomerate holding company and a pharmaceutical company – all located in South Korea. Either the attackers had access to the source code of the victims’ projects or they injected malware at the t
Securelist
IT threat evolution Q2 2019. Statistics
blogs_securelist·2019-08-19
IT threat evolution Q2 2019. Statistics
Table of Contents
- Quarterly figures
- Mobile threats
- Attacks on Apple macOS
- IoT attacks
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyber attacks
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Boris Larin
- Oleg Kupreev
- Evgeny Lopatin
These statistics are based on detection verdicts of Kaspersky products received from users who consented to provide statistical data.
## Quarterly figures
According to Kaspersky Security Network,
- Kaspersky solutions blocked 717,057,912 attacks launched from online resources in 203 countries across the globe.
- 217,843,293 unique URLs triggered Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to bank accounts were
Securelist
DDoS attacks in Q2 2019
blogs_securelist·2019-08-05
DDoS attacks in Q2 2019
Table of Contents
- News overview
- Quarter trends
- Statistics
- Conclusion
Authors
- Oleg Kupreev
- Ekaterina Badovskaya
- Alexander Gutnikov
## News overview
The second quarter of 2019 turned out to be richer than the first in terms of high-profile DDoS attacks. True, most of the campaigns that attracted media attention appeared to be politically, rather than commercially, motivated — and that despite the fact that some security experts discern a clear fall in hacktivism in recent years.
Let’s begin with an attack that is technically outside the chronological framework of this report, since it took place on March 5 (but was reported in early May). It was targeted against a computer system regulating the supply of electricity to various districts of Los Angeles and Salt Lake City.
Securelist
On the IoT road: perks, benefits and security of moving smartly
blogs_securelist·2019-07-22
On the IoT road: perks, benefits and security of moving smartly
Authors
- Kaspersky
Kaspersky has repeatedly investigated security issues related to IoT technologies (for instance, here, or here). Earlier this year our experts have even gained foothold in the security of biomechanical prosthetic devices. The same implies to smart car security: our own research has indicated that there are number of issues—look here or here.
This year, we decided to continue our tradition of small-scale experiments with security of connected devices but focused on the automotive-related topic. The topic has retained its importance through the years, and as our own research into the subject has revealed, there are security issues in the market, since the vehicles are becoming smarter and more connected—and more exposed. But apart from that, there is a whole industry o
Securelist
Criminals, ATMs and a cup of coffee
blogs_securelist·2019-06-27
Criminals, ATMs and a cup of coffee
Authors
- Konstantin Zykov
In spring 2019, we discovered a new ATM malware sample written in Java that was uploaded to a multiscanner service from Mexico and later from Colombia. After a brief analysis, it became clear that the malware, which we call ATMJaDi, can cash out ATMs. However, it doesn’t use the standard XFS, JXFS or CSC libraries. Instead, it uses the victim bank’s ATM software Java proprietary classes: meaning the malware will only work on a small subset of ATMs. It makes this malware very targeted.
Kaspersky products detect the sample as Trojan.Java.Agent.rs
## Technical Details
First, as with most other ATM malware, the attackers must find a way to install the malware on the target ATMs. The malware can’t be controlled via the ATM keyboard or touchscreen, because it runs
Securelist
Riltok mobile Trojan: A banker with global reach
blogs_securelist·2019-06-25
Riltok mobile Trojan: A banker with global reach
Table of Contents
- Infection
- Communication with C&C
- Trojan anatomy
- Conclusion
- IoCs
Authors
- Tatyana Shishkova
Riltok is one of numerous families of mobile banking Trojans with standard (for such malware) functions and distribution methods. Originally intended to target the Russian audience, the banker was later adapted, with minimal modifications, for the European “market.” The bulk of its victims (more than 90%) reside in Russia, with France in second place (4%). Third place is shared by Italy, Ukraine, and the United Kingdom.
Geographic spread of the Riltok banking Trojan
We first detected members of this family back in March 2018. Like many other bankers, they were disguised as apps for popular free ad services in Russia. The malware was distributed from infected device
Securelist
Plurox: Modular backdoor
blogs_securelist·2019-06-18
Plurox: Modular backdoor
Authors
- Anton Kuzmenko
In February this year, a curious backdoor passed across our virtual desk. The analysis showed the malware to have a few quite unpleasant features. It can spread itself over a local network via an exploit, provide access to the attacked network, and install miners and other malicious software on victim computers. What’s more, the backdoor is modular, which means that its functionality can be expanded with the aid of plugins, as required. Post-analysis, the malware was named Backdoor.Win32.Plurox.
## Key features
Plurox is written in C and complied with Mingw GCC, and judging by the presence of debug lines, the malware was at the testing stage when detected.
Debug lines in the samples we found
The backdoor uses the TCP protocol to communicate with the C&C serve
Securelist
Zebrocy’s Multilanguage Malware Salad
blogs_securelist·2019-06-03
Zebrocy’s Multilanguage Malware Salad
Authors
- GReAT
Zebrocy is Russian speaking APT that presents a strange set of stripes. To keep things simple, there are three things to know about Zebrocy
- Zebrocy is an active sub-group of victim profiling and access specialists
- Zebrocy maintains a lineage back through 2013, sharing malware artefacts and similarities with BlackEnergy
- The past five years of Zebrocy infrastructure, malware set, and targeting have similarities and overlaps with both the Sofacy and
Zebrocy shares data points and crosses lines with other clusters of activity in unique and unexpected ways. Zebrocy initially shared limited infrastructure, targets, and interests with Sofacy. Zebrocy also shared malware code with past BlackEnergy/Sandworm; and targeting, and later very limited infrastructure with more re
Securelist
Spam and phishing in Q1 2019
blogs_securelist·2019-05-15
Spam and phishing in Q1 2019
Table of Contents
- Quarterly highlights
- Statistics: spam
- Statistics: phishing
- Conclusion
Authors
- Maria Vergelis
- Tatyana Shcherbakova
- Tatyana Sidorina
## Quarterly highlights
### Valentine’s Day
As per tradition, phishing timed to coincide with lovey-dovey day was aimed at swindling valuable confidential information out of starry-eyed users, such as bank card details. The topics exploited by cybercriminals ranged from online flower shops to dating sites.
But most often, users were invited to order gifts for loved ones and buy medications such as Viagra. Clicking/tapping the link in such messages resulted in the victim’s payment details being sent to the cybercriminals.
### New Apple products
Late March saw the unveiling of Apple’s latest products, which fraudsters wer
Securelist
FIN7.5: the infamous cybercrime rig “FIN7” continues its activities
blogs_securelist·2019-05-08
FIN7.5: the infamous cybercrime rig “FIN7” continues its activities
Authors
- Yury Namestnikov
- Félix Aime
On August 1, 2018, the US Department of Justice announced that it had arrested several individuals suspected of having ties to the FIN7 cybercrime rig. FIN7 operations are linked to numerous intrusion attempts having targeted hundreds of companies since at least as early as 2015. Interestingly, this threat actor created fake companies in order to hire remote pentesters, developers and interpreters to participate in their malicious business. The main goal behind its malicious activities was to steal financial assets from companies, such as debit cards, or get access to financial data or computers of finance department employees in order to conduct wire transfers to offshore accounts.
In 2018-2019, researchers of Kaspersky Lab’s Global Research and
Securelist
New win32k zero day: CVE-2019-0859
blogs_securelist·2019-04-15·CVSS 7.8
CVE-2019-0859 [HIGH] New win32k zero day: CVE-2019-0859
Authors
- Vasily Berdnikov
- Boris Larin
- Anton Ivanov
In March 2019, our automatic Exploit Prevention (EP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. It was the fifth consecutive exploited Local Privilege Escalation vulnerability in Windows that we have discovered in recent months using our technologies. The previous ones were:
- Zero-day exploit (CVE-2018-8453) used in targeted attacks
- A new exploit for zero-day vulnerability CVE-2018-8589
- Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
- The fourth horseman: CVE-2019-0797 vulnerability
On March 17, 2019 we reported our discovery to Microsoft; the company confirmed the
Securelist
Project TajMahal – a sophisticated new APT framework | Securelist
blogs_securelist·2019-04-10
Project TajMahal – a sophisticated new APT framework | Securelist
Authors
- AMR
- GReAT
## Executive summary
‘TajMahal’ is a previously unknown and technically sophisticated APT framework discovered by Kaspersky Lab in the autumn of 2018. This full-blown spying framework consists of two packages named ‘Tokyo’ and ‘Yokohama’. It includes backdoors, loaders, orchestrators, C2 communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers, and even its own file indexer for the victim’s machine. We discovered up to 80 malicious modules stored in its encrypted Virtual File System, one of the highest numbers of plugins we’ve ever seen for an APT toolset.
Just to highlight its capabilities, TajMahal is able to steal data from a CD burnt by a victim as well as from the printer queue. It can also request to ste
Securelist
Digital Doppelgangers
blogs_securelist·2019-04-09
Digital Doppelgangers
Authors
- GReAT
## Cybercriminals cash out money using stolen digital identities
Carding exists for over 20 years. And it is not dead yet. It is alive, and even more – it is being actively developed by cybercriminals. The “good” old method of entering stolen credit card information into online store forms to buy goods and services or using online payment system accounts for the same purpose still works like a charm. Of course, the process has become more sophisticated, and it is certainly not so easy to do as it used to be 10 years ago, but unfortunately it is still possible.
The modern financial cyberfrauds, sophisticated targeted attacks on banks like Carbanak and Silence, hundreds of families of banking Trojans, etc. It had all started with carding forums many years ago. Carding is
Securelist
Game of Threats | Securelist
blogs_securelist·2019-04-01
Game of Threats | Securelist
Table of Contents
- Introduction
- Methodology and key findings
- General Overview: malware is coming
- The M-files: most often infected series
- Threat Anatomy: attack vectors and types of threats
- Danger Things: how to stay safe
Authors
- Kaspersky
## How cybercriminals use popular TV shows to spread malware
## Introduction
While the way we consume TV content is rapidly changing, the content itself remains in high demand, and users resort to any means available to get at it – including illegal and non-ethical ones like the use of pirated stuff. The world is embracing the idea of paying for entertainment more and more with the development of paid subscription networks like Netflix or Apple Music. Yet many countries are still fighting the battle against illegally distributed conten
Securelist
The return of the BOM | Securelist
blogs_securelist·2019-03-28
The return of the BOM | Securelist
Authors
- GReAT
## Because sometimes you can't teach an old malware developer new tricks
There’s nothing new in Brazilian cybercriminals trying out new ways to stay under the radar. It’s just that this time around the bad guys have started using a method that was reported in the wild years ago.
Russian gangs used this technique to distribute malware capable of modifying the hosts file on Windows systems. Published by McAfee in 2013, the UTF-8 BOM (Byte Order Mark) additional bytes helped these malicious crews avoid detection.
Since these campaigns depended on spear phishing to increase the victim count, the challenge was to fool email scanners and use a seemingly corrupted file that lands in the victim’s inbox.
The first indicator appears when the user tries to open the ZIP file with
Securelist
Hacking microcontroller firmware through a USB
blogs_securelist·2019-03-21
Hacking microcontroller firmware through a USB
Table of Contents
- Who hacks video game consoles?
- Protection scheme of DualShock 4
- Rumors of super counterfeit DualShock 4
- Basics of embedded firmware analysis
- In the shadow of colossus
- Revelations
- Hacking microcontroller firmware through a USB
- Exploitation
- Crypto fail
- Conclusion
Authors
- Boris Larin
In this article, I want to demonstrate extracting the firmware from a secure USB device running on the Cortex M0.
## Who hacks video game consoles?
The manufacture of counterfeit and unlicensed products is widespread in the world of video game consoles. It’s a multi-billion dollar industry in which demand creates supply. You can now find devices for almost all the existing consoles that allow you to play copies of licensed video game ‘backups’ from flash drives, coun
Securelist
The fourth horseman: CVE-2019-0797 vulnerability | Securelist
blogs_securelist·2019-03-13·CVSS 7.8
CVE-2019-0797 [HIGH] The fourth horseman: CVE-2019-0797 vulnerability | Securelist
Authors
- Vasily Berdnikov
- Boris Larin
## The new zero-day in the Windows OS exploited in targeted attacks
In February 2019, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. We reported it to Microsoft on February 22, 2019. The company confirmed the vulnerability and assigned it CVE-2019-0797. Microsoft have just released a patch, crediting Kaspersky Lab researchers Vasiliy Berdnikov and Boris Larin with the discovery:
This is the fourth consecutive exploited Local Privilege Escalation vulnerability in Windows we have discovered recently using our technologies. Just like with CVE-2018-8589, we believe this
Securelist
A predatory tale: Who’s afraid of the thief? | Securelist
blogs_securelist·2019-03-11
A predatory tale: Who’s afraid of the thief? | Securelist
Authors
- GReAT
In mid-February, Kaspersky Lab received a request for incident response from one of its clients. The individual who initially reported the issue to our client refused to disclose the origin of the indicator that they shared. What we do know is that it was a screenshot from one of the client’s internal computers taken on February 11 while an employee was apparently browsing through his emails. In addition, the anonymous source added that the screenshot was transferred to a C2 using a stealer dubbed ‘Predator’.
As soon as the client contacted us, we started conducting a full investigation into the infected machine, including memory dumps, event logs, environment indicators from the network and so on and so forth. Finding very little information about this tool, we decided
Securelist
How to Attack and Defend a Prosthetic Arm
blogs_securelist·2019-02-26
How to Attack and Defend a Prosthetic Arm
Authors
- Vladimir Dashchenko
## All your arm are belong to us
The IoT world has long since grown beyond the now-ubiquitous smartwatches, smartphones, smart coffee machines, cars capable of sending tweets and Facebook posts and other stuff like fridges that send spam. Today’s IoT world now boasts state-of-the-art solutions that quite literally help people. Take, for example, the biomechanical prosthetic arm made by Motorica Inc. This device helps people who have lost their limb to restore movement.
Via dedicated sensors, the biomechanical prosthetic arm reads the muscle contraction parameters and analyzes them to produce movements with the robotic fingers. The arm takes little time to get used to standard movements, after which it becomes a full-fledged assistant.
Like other IoT devic
Securelist
A Zebrocy Go Downloader
blogs_securelist·2019-01-11
A Zebrocy Go Downloader
Authors
- GReAT
## Adding Original Findings to the Discussion
Last year at SAS2018 in Cancun, Mexico, “Masha and these Bears” included discussion of a subset of Sofacy activity and malware that we call “Zebrocy”, and predictions for the decline of SPLM/XAgent Sofacy activity coinciding with the acceleration of Zebrocy activity and innovation. Zebrocy was initially introduced as a Sofacy backdoor package in 2015, but the Zebrocy cluster has carved a new approach to malware development and delivery to the world of Sofacy. In line with this approach, we will present more on this Zebrocy innovation and activity playing out at SAS 2019 in Singapore.
Our colleagues at Palo Alto recently posted an analysis of Zebrocy malware. The analysis is good and marked their first detection of a Zebrocy
Securelist
DarkVishnya: Banks attacked through direct connection to local network
blogs_securelist·2018-12-06
DarkVishnya: Banks attacked through direct connection to local network
Authors
- Sergey Golovanov
While novice attackers, imitating the protagonists of the U.S. drama Mr. Robot, leave USB flash drives lying around parking lots in the hope that an employee from the target company picks one up and plugs it in at the workplace, more experienced cybercriminals prefer not to rely on chance. In 2017-2018, Kaspersky Lab specialists were invited to research a series of cybertheft incidents. Each attack had a common springboard: an unknown device directly connected to the company’s local network. In some cases, it was the central office, in others a regional office, sometimes located in another country. At least eight banks in Eastern Europe were the targets of the attacks (collectively nicknamed DarkVishnya), which caused damage estimated in the tens of millions of
Securelist
KoffeyMaker: notebook vs. ATM | Securelist
blogs_securelist·2018-12-04
KoffeyMaker: notebook vs. ATM | Securelist
Authors
- Sergey Golovanov
Despite CCTV and the risk of being caught by security staff, attacks on ATMs using a direct connection — so-called black box attacks — are still popular with cybercriminals. The main reason is the low “entry requirements” for would-be cyber-robbers: specialized sites offer both the necessary tools and how-to instructions.
Kaspersky Lab’ experts investigated one such toolkit, dubbed KoffeyMaker, in 2017-2018, when a number of Eastern European banks turned to us for assistance after their ATMs were quickly and almost freely raided. It soon became clear that we were dealing with a black box attack — a cybercriminal opened the ATM, connected a laptop to the cash dispenser, closed the ATM, and left the crime scene, leaving the device inside. Further investigation r
Securelist
Kaspersky Security Bulletin 2018. Story of the year: miners
blogs_securelist·2018-11-28
Kaspersky Security Bulletin 2018. Story of the year: miners
Authors
- Evgeny Lopatin
- Kaspersky Security Bulletin 2018. Statistics
- Kaspersky Security Bulletin 2018. Top security stories
- Kaspersky Security Bulletin 2018. Threat Predictions for 2019
Cryptocurrency miners that infect the computers of unsuspecting users essentially operate according to the same business model as ransomware programs: the victim’s computing power is harnessed to enrich the cybercriminals. Only in the case of miners, it might be quite a while before the user notices that 70–80% of their CPU or graphics card power is being used to generate virtual coins. Encrypted documents and ransomware messages are far harder to miss.
Cryptominers usually find their way onto user computers and corporate machines along with adware, hacked games, and other pirated content. What’s
Securelist
A new exploit for zero-day vulnerability CVE-2018-8589
blogs_securelist·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] A new exploit for zero-day vulnerability CVE-2018-8589
Authors
- Boris Larin
- Anton Ivanov
- Vladislav Stolyarov
Yesterday, Microsoft published its security bulletin, which patches a vulnerability discovered by our technologies. We reported it to Microsoft on October 17, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8589.
In October 2018, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in Microsoft’s Windows operating system. Further analysis revealed a zero-day vulnerability in win32k.sys. The exploit was executed by the first stage of a malware installer in order to gain the necessary privileges for persistence on the victim’s system. So far, we have detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East.
Kasper
Securelist
IT threat evolution Q3 2018 | Securelist
blogs_securelist·2018-11-12
IT threat evolution Q3 2018 | Securelist
Authors
- David Emm
## Targeted attacks and malware campaigns
### Lazarus targets cryptocurrency exchange
Lazarus is a well-established threat actor that has conducted cyber-espionage and cybersabotage campaigns since at least 2009. In recent years, the group has launched campaigns against financial organizations around the globe. In August we reported that the group had successfully compromised several banks and infiltrated a number of global cryptocurrency exchanges and fintech companies. While assisting with an incident response operation, we learned that the victim had been infected with the help of a Trojanized cryptocurrency trading application that had been recommended to the company over email.
An unsuspecting employee had downloaded a third-party application from a legitimate
Securelist
IT threat evolution Q3 2018. Statistics
blogs_securelist·2018-11-12
IT threat evolution Q3 2018. Statistics
Table of Contents
- Q3 figures
- Mobile threats
- Attacks on IoT devices
- Financial threats
- Cryptoware programs
- Cryptominers
- Vulnerable apps used by cybercriminals
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Oleg Kupreev
- Evgeny Lopatin
- Alexander Liskin
These statistics are based on detection verdicts of Kaspersky Lab products received from users who consented to provide statistical data.
## Q3 figures
According to Kaspersky Security Network:
- Kaspersky Lab solutions blocked 947,027,517 attacks launched from online resources located in 203 countries.
- 246,695,333 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to
Securelist
Spam and phishing in Q2 2018
blogs_securelist·2018-08-14
Spam and phishing in Q2 2018
Table of Contents
- Quarterly highlights
- Distribution channels
- Spammer tricks
- Statistics: spam
- Statistics: phishing
- Conclusion
Authors
- Maria Vergelis
- Nadezhda Demidova
- Tatyana Shcherbakova
## Quarterly highlights
### GDPR as a phishing opportunity
In the first quarter, we discussed spam designed to exploit GDPR (General Data Protection Regulation), which came into effect on May 25, 2018. Back then spam traffic was limited to invitations to participate in workshops and other educational events and purchase software or databases. We predicted that fraudulent emails were soon to follow. And we found them in the second quarter.
As required by the regulation, companies notified email recipients that they were switching to a new GDPR-compliant policy and asked them to con
Securelist
Netkids
blogs_securelist·2018-06-01
Netkids
Table of Contents
- How statistics are collected
- Global picture
- Regional variations
- Differences by country and language
- Other interests
- Conclusion
Authors
- Anna Larkina
Children today are completely at home in the digital space. They use digital diaries and textbooks at school, communicate via instant messaging, play games on mobile devices (not to mention PCs and consoles), and create mini masterpieces on tablets and laptops. This total immersion in the digital universe is a concern for many parents, but if they want their child to spend time online safely and usefully, they must not only understand the basic concepts of digital security and have a grasp of the threats, but also be able to explain them to their kid.
The Parental Control module in Kaspersky Lab products an
Securelist
Connected Medicine and Its Diagnosis
blogs_securelist·2017-09-13
Connected Medicine and Its Diagnosis
Authors
- Denis Makrushin
Medical data is slowly but surely migrating from paper mediums to the digital infrastructure of medical institutions. Today, the data is “scattered” across databases, portals, medical equipment, etc. In some cases, the security of the network infrastructure of such organizations is neglected, and resources that process medical information are accessible from outside sources.
Results that had been obtained during research that we discussed in a previous article called for a more detailed analysis of the security problem, but now from within medical institutions (with the consent of their owners, of course). The analysis allowed us to work on mistakes and give a series of recommendations for IT experts who service medical infrastructure.
## Incorrect diagnosis i
Securelist
How to hunt for rare malware
blogs_securelist·2017-01-09
How to hunt for rare malware
Table of Contents
- Why YARA training?
- Giveaways
- What are the requirements for participation?
- Catching a 0-day with YARA
- If you’re a scholar…
Authors
- GReAT
## YARA training on St. Maarten from the big names of Kaspersky Lab’s GReAT
At SAS 2017, on April 1st and 2nd on St. Maarten, Global Director of GReAT Costin Raiu and Principal Security Researchers Vitaly Kamluk and Sergey Mineev will provide YARA training for incident response specialists and malware researchers, who need an effective arsenal for finding malware. During the training, the experts will give participants access to some of Kaspersky Lab internal systems, which are otherwise closed to the public, to demonstrate how the company’s malware analysts catch rare samples. After two days, even being a newcomer, you’
Securelist
Spam and phishing in Q3 2016 | Securelist
blogs_securelist·2016-11-09
Spam and phishing in Q3 2016 | Securelist
Table of Contents
- Spam: quarterly highlights
- Statistics
- Malicious email attachments
- Phishing
- Conclusion
Authors
- Darya Gudkova
- Maria Vergelis
- Nadezhda Demidova
Download the full report (PDF)
## Spam: quarterly highlights
### Malicious spam
Throughout 2016 we have registered a huge amount of spam with malicious attachments; in the third quarter, this figure once again increased significantly. According to KSN data, in Q3 2016 the number of email antivirus detections totaled 73,066,751. Most malicious attachments contained Trojan downloaders that one way or another loaded ransomware onto the victim’s computer.
Number of email antivirus detections, Q1-Q3 2016
The amount of malicious spam reached its peak in September 2016. According to our estimates, the number of mas
Securelist
Spam and phishing in Q2 2016
blogs_securelist·2016-08-18
Spam and phishing in Q2 2016
Table of Contents
- Spam: quarterly highlights
- Statistics
- Malicious email attachments
- Phishing
- Conclusion
Authors
- Darya Gudkova
- Maria Vergelis
- Nadezhda Demidova
- Tatyana Shcherbakova
Download the full report (PDF)
## Spam: quarterly highlights
### The year of ransomware in spam
Although the second quarter of 2016 has only just finished, it’s safe to say that this is already the year of ransomware Trojans. By the end of Q2 there was still a large number of emails with malicious attachments, most of which download ransomware in one way or other to a victim’s computer. However, in the period between 1 June and 21 June the proportion of these emails decreased dramatically.
The majority of malicious attachments were distributed in ZIP archives. The decline can therefore
http://packetstormsecurity.com/files/160698/Microsoft-Windows-splWOW64-Privilege-Escalation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0986http://packetstormsecurity.com/files/160698/Microsoft-Windows-splWOW64-Privilege-Escalation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0986https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0986
2020-06-09
Published
2021-11-03
Added to CISA KEV
Exploited in the wild