Wednesday, 2 April 2025
24.1 C
Singapore
31.1 C
Thailand
21.9 C
Indonesia
26.8 C
Philippines

ESET reveals new threat report spotlighting sophisticated cyber threats

ESET's most recent Threat Report highlights emerging cyber threats like AI-impersonating infostealers and deepfake technologies, covering the period from December 2023 to May 2024.

ESET, a leading player in the cybersecurity industry, has released its latest Threat Report, which encompasses findings from December 2023 to May 2024. This extensive report details key trends in the cybersecurity landscape, observed through ESET’s comprehensive telemetry and expert analyses.

Escalating dangers: Infostealers and deepfake technologies

The report underscores an alarming escalation in infostealers that are masquerading as generative AI tools like OpenAI’s Sora and Google’s Gemini. These deceptive tactics lure individuals into downloading harmful software. Furthermore, a novel mobile malware known as GoldPickaxe has been discovered, which can pilfer facial recognition data to generate deepfake videos. These forgeries are subsequently utilised by fraudsters to authenticate illicit financial transactions. Notably, GoldPickaxe has victimised users across Southeast Asia through region-specific malicious applications affecting both Android and iOS devices.

Increased exploitation in gaming and WordPress

The gaming sector has also been compromised, with pirated video games and cheating aids found to harbour infostealer malware, including Lumma Stealer and RedLine Stealer. Notably, RedLine Stealer witnessed a significant spike in detections in the first half of 2024, particularly in Spain, Japan, and Germany, with activities exceeding those recorded in the second half of 2023 by a third.

The Balada Injector gang continues to exploit WordPress plugin vulnerabilities, affecting over 20,000 websites and generating over 400,000 hits as per ESET telemetry. This persistent exploitation underscores the ongoing vulnerability of web platforms.

The evolving ransomware landscape

The ransomware landscape has witnessed significant shifts, particularly with the disruption of LockBit, a previously dominant ransomware group. Following Operation Chronos, a global law enforcement operation carried out in February 2024, LockBit has been substantially weakened. Nonetheless, subsequent attacks have seen other groups using the leaked LockBit builder to perpetrate ransomware attacks, indicating that the threat from ransomware remains potent.

In-depth analysis of server-side attacks

Additionally, ESET researchers have conducted a thorough investigation into one of the most advanced server-side malware campaigns, involving the Ebury group. This malware, targeting servers operating Linux, FreeBSD, and OpenBSD, has compromised close to 400,000 servers, with more than 100,000 still affected as of late 2023.

Hot this week

Chinese EV makers urged to expand globally despite tariff challenges

Chinese EV makers are urged to expand globally despite rising tariffs. Industry experts stress the need for overseas production and strategic partnerships.

Google Pixel 9a arrives in Singapore this April for S$799

The Google Pixel 9a launches in Singapore in April 2025 with a Tensor G4 chip, 48MP camera, and seven years of updates, starting at S$799.

China-aligned hacker group FamousSparrow resurfaces in cyberattacks

ESET finds China-linked hacker group FamousSparrow still active with upgraded tools, targeting institutions in the US, Mexico and Honduras.

Apple has no plans for a small iPhone

Apple has no plans to make another iPhone Mini. Was it a missed opportunity, or was the compact iPhone just released at the wrong time?

Most consumers now back up their data, but cloud storage limits push shift to hybrid solutions

87% of people now back up their data, but cloud limits and rising costs are driving a shift to hybrid storage solutions.

These robot vacuums are getting smarter with Apple Home support

Appleโ€™s iOS 18.4 update adds Matter support for robot vacuums, enabling control via Apple Home. Roborock, iRobot, and Ecovacs are updating their devices.

Gmail introduces easier encryption for business emails

Google introduces a new encryption model for Gmail, making it easier for businesses to send secure emails without special software or certificates.

Nothing Phone (3a) Pro review: A mid-range marvel with standout zoom

Nothing Phone (3a) Pro blends standout design, powerful zoom camera, and smart features, making it a top choice in the mid-range segment.

Vivo challenges iPhone 16 Pro Max with X200 Ultraโ€™s video stability

Vivoโ€™s X200 Ultra teaser compares video stability with the iPhone 16 Pro Max, promising top-tier camera upgrades and advanced stabilisation.

Related Articles