The Times Australia
The Times Technology News

.
Beatbot

.

New RAT Variants Running Rampant, Threat Report Reveals

  • Written by AVAST

Avast (LSE:AVST), a global leader in digital security and privacy, today released its Q3/2021 Threat Report. In the third quarter of the year, the Avast Threat Labs have seen an increased risk of businesses and consumers being attacked by ransomware and remote access trojans (RATs). RATs can be used for industry espionage, credentials theft, stalking, and even distributed denial of service (DDoS) attacks. The threat researchers also observed innovation in the ever-evolving cybercrime space, with new mechanisms used by exploit kits, and by the mobile banking Trojan Flubot.

Ransomware and RATs putting businesses at risk

In the beginning of Q3 2021, the world witnessed a massive supply chain attack on IT management software provider Kaseya and its customers, with Sodinokibi/REvil ransomware. The Avast Threat Labs noticed and blocked this attack on more than 2.4k endpoints. Following the involvement of politics, the ransomware operators released the decryption key, and Sodinokibi’s infrastructure went down, with no new variants seen in the wild until September 9th, when Avast detected and blocked a new variant. Overall, in Q3, the Avast Threat Labs saw the risk ratio of ransomware attacks go up by 5% vs. Q2, and even up by 22% vs. Q1 2021.

RATs were also a dangerous threat for businesses and consumers, which spread further in Q3 than in the previous quarters. Avast spotted three new RAT variants, including FatalRAT with anti-VM capabilities, VBA RAT, which exploits the Internet Explorer vulnerability CVE-2021-26411, and a new version of Reverse RAT with build number 2.0 which added web camera photo taking, file stealing and anti-AV capabilities. “RATs can be a fundamental threat for businesses, as they can be used for industry espionage,” said Jakub Kroustek, Avast Malware Research Director. “However, RATs can also be used against consumers, for example to steal their credentials, to add their computers to a botnet to drive DDoS attacks, and unfortunately, for cyberstalking, which can do massive harm to an individual’s privacy and wellbeing.”

Growing distribution of rootkits, and innovation in exploit kits and mobile banking trojans
The Avast Threat Labs also recorded a significant increase in rootkit activity at the end of Q3, which was one of the most significant increases in activity in the quarter. A rootkit is malicious software designed to give unauthorised access to cybercriminals, with the highest system privileges. Rootkits commonly provide services to other malware in the user mode.

Another malware category that appears to be returning are Exploit Kits, with notable new innovations occurring, including the targeting of Google Chrome vulnerabilities. The most active exploit kit was PurpleFox, against which Avast protected over 6,000 users per day on average. Rig and Magnitude were also prevalent throughout the whole quarter. The Underminer exploit kit woke up after a long period of inactivity and started sporadically serving HiddenBee and Amadey. Some exploit kits, especially PurpleFox and Magnitude, are under heavy development, regularly receiving new features and exploitation capabilities.

The Avast Threat Labs also monitored new tactics on the mobile front, with FluBot, an Android SMS banking threat, changing its social engineering approach. Jakub Kroustek said, “Flubot first spread posing as delivery services to lure the victims into downloading a “tracking app” for a parcel they recently missed or should be expecting. In Q3, Avast has seen novel scenarios in spreading this malware. One example is posing as voicemail recorders. Another is fake claims of leaked personal photos. The most extreme of these variants would even lure the victim to a fake page that would claim the victim has already been infected by FluBot when they probably weren’t yet and trick them into installing a “cure” for the “infection”. This “cure” would in fact be the FluBot malware itself.

Flubot continued to expand from where initially it was targeting Europe in Q2 - Spain, Italy, Germany, to later spread throughout the rest of Europe and other countries like Australia and New Zealand.

For more detailed information visit the full report: https://decoded.avast.io/threatresearch/avast-q321-threat-report/

The Times Features

LaManna at Essendon Fields is transforming into a festive wonderland

This festive season, LaManna is decking its halls with an incredible range of goodies to meet all your Christmas needs and ensure your next holiday feast is one to remember.  Wit...

'Big school ready’ before 2025

Rebecca Suseno, a mother from Croydon, NSW, shares her excitement and preparation for her daughter Chiara’s big leap into kindergarten in 2025. As a mother, there’s nothing...

ADHD medications affect children’s appetites. Here’s how to manage this

Attention deficit hyperactivity disorder (ADHD) impacts the ability to maintain attention to tasks. Often, it also involves impulsive behaviour – saying or doing things without...

For the foodie or home chef, look no further than premium pizza oven brand, Gozney

Founder and designer, Tom Gozney, wanted to bring a different way of cooking to as many people as possible and has led a movement of unforgettable cooking experiences inspired ...

Beyond bricks and mortar: Building socially connected communities is Australia’s next big challenge

As state governments rush to deliver thousands of homes across the major capitals,1 one of the nation’s leading urban planners warns we must build transit based, mixed-use, w...

New research shows how long, hard and often you need to stretch to improve your flexibility

Can you reach down and touch your toes without bending your knees? Can you reach both arms overhead? If these sound like a struggle, you may be lacking flexibility. Flexibilit...

Times Magazine

Truck Dealers Sales and Service: Get the Best Deals on Trucks Here

Looking for the best deals on trucks near you? Truck repair shops in Australia offer a range of services and sales options that can help you get the perfect truck for your needs.  Whether you're looking for a new or used one, these professional ...

Eliud Kipchoge signs with Shokz as global ambassador

Shokz, the consumer electronics brand, known for its open-ear headphones and technology, have today announced the current, two-time Olympic marathon champion, Eliud Kipchoge, as a global ambassador. As part of the partnership, Kipchoge and Shokz wi...

Faultless Journeys: Exploring the Benefits of Bus Charter Services in Brisbane

Brisbane is a city full of lights, diversity, change and colours. It is populated with cultural differences and multiple businesses that offer a bundle of opportunities for interaction. There are multiple places to visit and explore in cases wher...

Holiday Home Hacks: 5 Tips for Beautifying Your Outdoor Living Spaces

Aussie summers are all about time spent outdoors, especially if you're lucky enough to have a holiday home in the family. With the right design choices and professional assistance for the bigger tasks, you can turn your outdoor living space into an...

Swimming with whales: you must know the risks and when it’s best to keep your distance

Three people were injured last month in separate humpback whale encounters off the Western Australia coast. The incidents happened during snorkelling tours on Ningaloo Reef when swimmers came too close to a mother and her calf. Swim encounter...

Temporary Solar Lights: A Portable and Eco-Friendly Lighting Solution for Outdoor Events

Organizing outdoor events in Australia often involves considering various aspects, including logistics, safety, and environmental impact. One crucial element that can be easily overlooked is the lighting solution. Traditionally, outdoor events have...

LayBy Shopping