Thursday, 19 December 2024
25.7 C
Singapore

ESET reveals new threat report spotlighting sophisticated cyber threats

ESET's most recent Threat Report highlights emerging cyber threats like AI-impersonating infostealers and deepfake technologies, covering the period from December 2023 to May 2024.

ESET, a leading player in the cybersecurity industry, has released its latest Threat Report, which encompasses findings from December 2023 to May 2024. This extensive report details key trends in the cybersecurity landscape, observed through ESET’s comprehensive telemetry and expert analyses.

Escalating dangers: Infostealers and deepfake technologies

The report underscores an alarming escalation in infostealers that are masquerading as generative tools like OpenAI’s Sora and Google’s Gemini. These deceptive tactics lure individuals into downloading harmful software. Furthermore, a novel mobile malware known as GoldPickaxe has been discovered, which can pilfer facial recognition data to generate deepfake videos. These forgeries are subsequently utilised by fraudsters to authenticate illicit financial transactions. Notably, GoldPickaxe has victimised users across Southeast Asia through region-specific malicious affecting both Android and iOS devices.

Increased exploitation in gaming and WordPress

The gaming sector has also been compromised, with pirated video games and cheating aids found to harbour infostealer malware, including Lumma Stealer and RedLine Stealer. Notably, RedLine Stealer witnessed a significant spike in detections in the first half of 2024, particularly in Spain, Japan, and Germany, with activities exceeding those recorded in the second half of 2023 by a third.

The Balada Injector gang continues to exploit WordPress plugin vulnerabilities, affecting over 20,000 websites and generating over 400,000 hits as per ESET telemetry. This persistent exploitation underscores the ongoing vulnerability of web platforms.

The evolving ransomware landscape

The ransomware landscape has witnessed significant shifts, particularly with the disruption of LockBit, a previously dominant ransomware group. Following Operation Chronos, a global law enforcement operation carried out in February 2024, LockBit has been substantially weakened. Nonetheless, subsequent attacks have seen other groups using the leaked LockBit builder to perpetrate ransomware attacks, indicating that the threat from ransomware remains potent.

In-depth analysis of server-side attacks

Additionally, ESET researchers have conducted a thorough investigation into one of the most advanced server-side malware campaigns, involving the Ebury group. This malware, targeting servers operating Linux, FreeBSD, and OpenBSD, has compromised close to 400,000 servers, with more than 100,000 still affected as of late 2023.

Hot this week

Google unveils Android XR, its new OS for extended reality devices

Google announces Android XR, a new OS for AR, VR, and MR devices. It will launch with Samsung's headset in 2025, and feature Gemini AI features.

YouTube partners with CAA to help creators combat AI copies of their likeness

YouTube collaborates with CAA to develop tools that help creators and celebrities track and remove AI-generated copies of their likenesses.

Microsoft ends Skype credits and phone numbers in favour of subscriptions

Microsoft is discontinuing Skype Credits and Numbers and urging users to adopt subscriptions as it shifts focus from pay-as-you-go features.

Twilio leads in the 2024-2025 IDC MarketScape for B2C customer data platforms

Discover why Twilio Segment leads in the IDC MarketScape for B2C Customer Data Platforms, featuring innovative AI and data management solutions.

Intel highlights concerns over Qualcomm laptop return rates

Intel addresses Qualcomm laptop return concerns, emphasising x86's strength while forecasting more competition in 2025 at Barclay's Technology Conference.

Salesforce: How ASEAN businesses will lead the AI-driven future in 2025

Salesforce shares its 2025 predictions for ASEAN, highlighting AI-driven innovations like autonomous agents, robotics, and specialised models reshaping business.

Salesforce announces major hiring spree to boost AI sales

Salesforce plans to hire 2,000 sales reps to meet AI demand, marking growth despite recent layoffs, as it focuses on expanding its AI offerings.

Why human skills remain essential in software development’s AI era

Developers’ critical thinking and creativity remain essential as AI tools like GenAI assist in coding. Learn why human skills still matter in the AI era.

NVIDIA’s new compact generative AI supercomputer is its most affordable yet

NVIDIA unveils its Jetson Orin Nano Super Developer Kit, a compact AI supercomputer with enhanced performance and an affordable US$249 price tag.

Related Articles

Popular Categories