Monday, November 25, 2024
HomeComputer SecurityProofpoint Q2 Threat Report - Ransomware Returns, Growth in Social Engineering and...

Proofpoint Q2 Threat Report – Ransomware Returns, Growth in Social Engineering and Email Fraud

Published on

According to Proofpoint Q2 Threat Report, the malicious message volume increased by 36% in the second quarter of 2018 and the ransomware returns back with new versions of GandCrab, Sigma, and GlobeImposter campaigns. Banking Trojans remained the top payload in the second quarter of 2018

Social engineering schemes such as fake antivirus and browser plugins and cryptojacking spiked in the second quarter of 2018. Support fraud grows by 38% and 30% increase in phishing links on social media.

Threat Report

Email Based Threat Report

The Q2 report says the malicious email message volume increased by 36% when compared to Q1 of 2018, with the second quarter mostly the campaign relies on the URLs instead of attachments.

- Advertisement - SIEM as a Service

The return of ransomware which is absent in the Q1 of 2018 and returns to more regular campaign within the second quarter. The remote access Trojans doubled their footprints in the second quarter of 2018.

Banking trojans as the top payload accounted for around 42% and it has been decreased by 17% as the ransomware campaign picks up.

Email fraud campaigns increased over 87% in the second quarter and it targets industries such as industries such as retail, healthcare, and government.

Threat Report

Subject lines also have been changed with the recent campaigns by attackers to increase the click-through rate. In 2018 14.2 percent of spam that delivered in the inbox are clicked.

Web-based Threat Report

Neutrino and RIG exploit kits continue to dominate and the RIG kit started using combinations of both phishing and malware attack to infect machines.

Neutrino and RIG exploit kits continue to dominate and the RIG kit started using combinations of both phishing and malware attack to infect machines.

Threat Report

The fake antivirus and browser plugins continue to grow rapidly in the second quarter. Attackers continue to inject coinhive scripts into a number of websites to mine cryptocurrency.

Social Media Threat Report

Social media threats continue to grow rapidly in the second quarter, attackers attempt to insert themselves in legitimate conversations to pass spoofed links and the tech support scams. Support scam activities have grown by 38% in Q2, but starting from June there is a seasonal dip.

Proofpoint researchers also detected a 30% increase in phishing links on social media. Social media accounts continue to be propagation channel for these kinds of threats, for Worldcup itself more than 250 accounts created representing the brands.

Proofpoint published the report and you can access the threat report here.

Also Read

How To Respond Cyber Incident In your Organization

Most Important Steps to Prevent Your Organization From Identity Theft -Detailed Explanation

WhatsApp & Telegram Accounts Compromised By New Vulnerability that Allowed Hackers to Take over Hundreds of Millions of Accounts

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Russian TAG-110 Hacked 60+ Users With HTML Loaded & Python Backdoor

The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Hackers Using AV/EDR Bypass Tool From Cybercrime Forums To Bypass Endpoints

Researchers uncovered two previously unknown endpoints with older Cortex XDR agents that used to...