08/10/2022 | Press release | Distributed by Public on 08/10/2022 04:16
Check Point Research (CPR), the Threat Intelligence arm of Check Point® Software Technologies Ltd. (NASDAQ: CHKP), a leading provider of cyber security solutions globally, has published its latest Global Threat Index for July 2022. CPR reports that Emotet continues its reign as the most widely used malware, despite a 50% reduction in its global impact compared to the previous month.
After a peak in Emotet's global impact last month, Emotet is back to its global impact numbers and continues as the most widespread malware. Possibly the peak ended, due to summer vacations as was seen in the past. Nevertheless, new features and improvements in Emotet's capabilities are constantly discovered, such as its latest credit card stealer module developed, and adjustments done in its spreading systems.
July has also seen Snake Keylogger, a credential stealer, falling from third to eighth place. In June, Snake Keylogger was being spread via malicious Word documents so the decrease in its prevalence could be due in part to Microsoft's recent confirmation that it will block macros by default. Replacing it in third place is XMRig, an open-source CPU software used to mine cryptocurrency - this indicates that cybercriminals are fundamentally 'in it for the money' despite any higher motivations they may claim, such as hacktivism. Malibot, which was new to the report last month, remains a threat to users of mobile banking as it is still the third most prevalent mobile malware worldwide.
"Emotet continues to dominate our monthly top malware charts," said Maya Horowitz, VP Research at Check Point Software. "This botnet continually evolves to maintain its persistence and evasion. Its latest developments include a credit card stealer module, meaning that enterprises and individuals must take extra care when making any online purchases. In addition, with Microsoft now confirming that it will block macros by default, we await to see how malwares, such as Snake Keylogger, may change their tactics."
CPR also revealed this month that "Web Server Exposed Git Repository Information Disclosure" is the most commonly exploited vulnerability, impacting 42% of organizations worldwide, closely followed by "Apache Log4j Remote Code Execution" with an impact of 41%. "Web Servers Malicious URL Directory Traversal" has remained in third place, with a global impact of 39%.
Top Malware Families
*The arrows relate to the change in rank compared to the previous month.
Emotet continues to be the most widespread malware with a global impact of 7%. This is then followed by Formbook which impacts 3% of organizations worldwide, and then XMRig, with a 2% global impact.
The complete list of the top ten malware families in July can be found on the Check Point blog.
Top Attacked Industries Globally
Education/Research is still the most attacked industry globally, followed by Government/Military and Internet Service Providers/Managed Service Providers (ISP/MSP).
Top Exploited Vulnerabilities
Web Server Exposed Git Repository Information Disclosure" is the most commonly exploited vulnerability, impacting 42% of organizations globally. It is closely followed by "Apache Log4j Remote Code Execution" which dropped from first place to second with a slightly lower impact of 41%. "Web Servers Malicious URL Directory Traversal" has remained in third place, with a global impact of 39%.
Top Mobile Malwares
AlienBot is the most prevalent mobile malware, followed by Anubis and MaliBot.
Check Point's Global Threat Impact Index and its ThreatCloud Map is powered by Check Point's ThreatCloud intelligence. ThreatCloud provides real-time threat intelligence derived from hundreds of millions of sensors worldwide, over networks, endpoints and mobiles. The intelligence is enriched with AI-based engines and exclusive research data from Check Point Research, The Intelligence & Research Arm of Check Point Software Technologies.
The complete list of the top ten malware families in July can be found on the Check Point blog.
Follow Check Point Research via:
Blog: https://research.checkpoint.com/
Twitter: https://twitter.com/_cpresearch_
About Check Point Research
Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber-attack data stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcement and various CERTs.