Sunday, 23 February 2025
28.8 C
Singapore
32 C
Thailand
23.4 C
Indonesia
26.6 C
Philippines

ESET reveals new threat report spotlighting sophisticated cyber threats

ESET's most recent Threat Report highlights emerging cyber threats like AI-impersonating infostealers and deepfake technologies, covering the period from December 2023 to May 2024.

ESET, a leading player in the cybersecurity industry, has released its latest Threat Report, which encompasses findings from December 2023 to May 2024. This extensive report details key trends in the cybersecurity landscape, observed through ESET’s comprehensive telemetry and expert analyses.

Escalating dangers: Infostealers and deepfake technologies

The report underscores an alarming escalation in infostealers that are masquerading as generative AI tools like OpenAI’s Sora and Google’s Gemini. These deceptive tactics lure individuals into downloading harmful software. Furthermore, a novel mobile malware known as GoldPickaxe has been discovered, which can pilfer facial recognition data to generate deepfake videos. These forgeries are subsequently utilised by fraudsters to authenticate illicit financial transactions. Notably, GoldPickaxe has victimised users across Southeast Asia through region-specific malicious applications affecting both Android and iOS devices.

Increased exploitation in gaming and WordPress

The gaming sector has also been compromised, with pirated video games and cheating aids found to harbour infostealer malware, including Lumma Stealer and RedLine Stealer. Notably, RedLine Stealer witnessed a significant spike in detections in the first half of 2024, particularly in Spain, Japan, and Germany, with activities exceeding those recorded in the second half of 2023 by a third.

The Balada Injector gang continues to exploit WordPress plugin vulnerabilities, affecting over 20,000 websites and generating over 400,000 hits as per ESET telemetry. This persistent exploitation underscores the ongoing vulnerability of web platforms.

The evolving ransomware landscape

The ransomware landscape has witnessed significant shifts, particularly with the disruption of LockBit, a previously dominant ransomware group. Following Operation Chronos, a global law enforcement operation carried out in February 2024, LockBit has been substantially weakened. Nonetheless, subsequent attacks have seen other groups using the leaked LockBit builder to perpetrate ransomware attacks, indicating that the threat from ransomware remains potent.

In-depth analysis of server-side attacks

Additionally, ESET researchers have conducted a thorough investigation into one of the most advanced server-side malware campaigns, involving the Ebury group. This malware, targeting servers operating Linux, FreeBSD, and OpenBSD, has compromised close to 400,000 servers, with more than 100,000 still affected as of late 2023.

Hot this week

DJI launches Osmo Mobile 7 series with smarter stabilisation and tracking

DJI unveils the Osmo Mobile 7 Series, featuring smarter tracking, stabilisation, and hands-free controls for professional-quality smartphone videos.

Google Play Books introduces direct purchases on iOS

Google Play Books now allows direct purchases on iOS, bypassing Appleโ€™s fees. A new โ€œGet bookโ€ button links users to Google Play for payments.

LG expands its gaming portal to more screens in 2025

LG is expanding its Gaming Portal to more screens in 2025, offering seamless access to cloud and webOS games across Smart TVs, monitors, and StanbyME screens.

Pop Mart and CapitaLand launch love-themed CryBaby collaboration

Pop Mart and CapitaLand are bringing love to the malls with a CryBaby-themed collaboration that will run until March 14.

DJIโ€™s RS 4 Mini stabiliser now features advanced subject tracking

DJIโ€™s RS 4 Mini stabiliser introduces subject tracking, improved battery life, and better handling, making it an excellent tool for content creators.

BT and Equinix expand partnership to enhance global interconnectivity

BT and Equinix expand their partnership to boost interconnectivity for multinational businesses, deploying BTโ€™s Global Fabric NaaS in 40+ Equinix data centres worldwide.

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

LG unveils advanced laundry solutions at KBIS 2025

LG unveils its latest heat pump washer and dryer lineup at KBIS 2025, featuring AI-driven efficiency, ventless design, and smart connectivity.

The Vision Pro is now easier to share, and getting a new iPhone app

Appleโ€™s Vision 2.4 update makes sharing the Vision Pro easier, introduces a new iPhone app for content discovery, and adds the Spatial Gallery app.

Related Articles