Trending...
- California: Governor Newsom signs new law to protect workers, require disclosures on AI-generated advertising - 165
- California: Governor Newsom expands film and TV tax credits with new legislation, creates tax credit to support post-production jobs - 118
- California: Governor Newsom issues legislative update 9.18.26 - 113
SAN JOSE, Calif.--(BUSINESS WIRE)--McAfee Corp. (Nasdaq: MCFE), the device-to-cloud cybersecurity company, today released its McAfee Threats Report: June 2021, examining cybercriminal activity related to malware and the evolution of cyber threats in the first quarter of 2021. The quarter saw cyber adversaries shift from low-return, mass-spread ransomware campaigns toward fewer, customized Ransomware-as-a-Service (RaaS) campaigns targeting larger, more lucrative organizations. A proliferation in 64-bit CoinMiner applications drove the growth of cryptocurrency-generating coin mining malware by 117%. Additionally, a surge in the growth of new Mirai-based malware variants drove increases in malware targeting Internet of Things (55%) and Linux (38%) systems.
"Criminals will always evolve their techniques to combine whatever tools enable them to best maximize their monetary gains with the minimum of complication and risk," said Raj Samani, McAfee fellow and chief scientist. "We first saw them use ransomware to extract small payments from millions of individual victims. Today, we see Ransomware as a Service supporting many players in these illicit schemes holding organizations hostage and extorting massive sums for the criminals."
Each quarter, McAfee assesses the state of the cyber threat landscape based on in-depth research, investigative analysis, and threat data gathered by the McAfee Global Threat Intelligence cloud from over a billion sensors across multiple threat vectors around the world.
Ransomware
Ransomware declined by 50% in Q1 due in part to a shift by attackers from broad campaigns attacking many targets with the same samples to campaigns attacking fewer, larger targets with unique samples. Campaigns using one type of ransomware to infect and extort payments from many victims are notoriously "noisy" in that hundreds of thousands of systems will, in time, begin to recognize and block these attacks. By allowing attackers to launch unique attacks, RaaS affiliate networks are allowing adversaries to minimize the risk of detection by large organizations' cyber defenses and then paralyze and extort them for large ransomware payments. This shift is reflected by the decline in prominent ransomware family types from 19 in January 2021 to 9 in March 2021.
More on The Californer
Despite the high profile attacks from the DarkSide RaaS group exposed in Q2 2021, REvil was the most detected in Q1, followed by the RansomeXX, Ryuk, NetWalker, Thanos, MountLocker, WastedLocker, Conti, Maze and Babuk strains.
Coin Miner Malware
While prominent ransomware attacks have focused attention on how criminals use ransomware to monetize their crimes with payments in cryptocurrency, a first quarter 117% surge in the spread of cryptocurrency-generating coin mining malware can be attributed to a sharp spike in 64-bit CoinMiner applications.
Rather than locking up victims' systems and holding them hostage until cryptocurrency payments are made, Coin Miner malware infects compromised systems and silently produces cryptocurrency using those systems' computing capacity for the criminals that designed and launched such campaigns. The advantage to cybercriminals is that there is zero interaction required of both the perpetrator and the victim. While the victim's computers may operate slower than usual due the coin miner's workload, victims may never become aware that their system is creating monetary value for criminals.
"The takeaway from the ransomware and coin miner trends shouldn't be that we need to restrict or even outlaw the use of cryptocurrencies," Samani continued. "If we have learned anything from the history of cybercrime, criminals counter defenders' efforts by simply improving their tools and techniques, sidestepping government restrictions, and always being steps ahead of defenders in doing so. If there are efforts to restrict cryptocurrencies, perpetrators will develop new methods to monetize their crimes, and they only need to be a couple steps ahead of governments to continue to profit."
Threats & Victims
Overall Malware Threats. The first quarter of 2021 saw the volume of new malware threats average 688 threats per minute, an increase of 40 threats per minute over Q4 2020.
IoT & Linux Devices. A variety of new Mirai malware variants drove increases on the Internet of Things (IoT) and Linux malware categories in Q1. The Moobot family (a Mirai variant) was observed to be mass-spread and accounted for multiple Mirai variants. These variants all exploit vulnerabilities in IoT devices like DVRs, webcams and internet routers. Once exploited, the malware is hidden on the system, downloads later stages of the malware and connects with the command-and-control server (C2). When the compromised IoT devices are connected to their botnet, they can be commandeered to participate in DDoS attacks.
More on The Californer
Industry Sectors. McAfee tracked a 54% increase in publicly reported cyber incidents targeting the technology sector during the first quarter of 2021. The Education and Financial/Insurance sectors followed with 46% and 41% increases respectively, whereas reported incidents in Wholesale/Retail and Public Sector declined by 76% and 39% respectively.
Regions. These incidents surged in 54% in Asia and 43% in Europe, but declined 13% in North America. While reported incidents actually declined 14% in the United States, these incidents grew 84% in France and 19% in the United Kingdom.
Resources:
About McAfee Labs and Advanced Threat Research
McAfee Labs and McAfee Advanced Threat Research are a leading source for threat research, threat intelligence, and cybersecurity thought leadership. With data from over a billion sensors across key threats vectors—file, web, message, and network— McAfee Labs and McAfee Advanced Threat Research deliver real-time threat intelligence, critical analysis, and expert thinking to improve protection and reduce risks.
About McAfee
McAfee Corp. (Nasdaq: MCFE) is the device-to-cloud cybersecurity company. Inspired by the power of working together, McAfee creates consumer and business solutions that make our world a safer place. www.mcafee.com
McAfee® and the McAfee logo are trademarks of McAfee, LLC or its subsidiaries in the United States and other countries. Other marks and brands may be claimed as the property of others.
"Criminals will always evolve their techniques to combine whatever tools enable them to best maximize their monetary gains with the minimum of complication and risk," said Raj Samani, McAfee fellow and chief scientist. "We first saw them use ransomware to extract small payments from millions of individual victims. Today, we see Ransomware as a Service supporting many players in these illicit schemes holding organizations hostage and extorting massive sums for the criminals."
Each quarter, McAfee assesses the state of the cyber threat landscape based on in-depth research, investigative analysis, and threat data gathered by the McAfee Global Threat Intelligence cloud from over a billion sensors across multiple threat vectors around the world.
Ransomware
Ransomware declined by 50% in Q1 due in part to a shift by attackers from broad campaigns attacking many targets with the same samples to campaigns attacking fewer, larger targets with unique samples. Campaigns using one type of ransomware to infect and extort payments from many victims are notoriously "noisy" in that hundreds of thousands of systems will, in time, begin to recognize and block these attacks. By allowing attackers to launch unique attacks, RaaS affiliate networks are allowing adversaries to minimize the risk of detection by large organizations' cyber defenses and then paralyze and extort them for large ransomware payments. This shift is reflected by the decline in prominent ransomware family types from 19 in January 2021 to 9 in March 2021.
More on The Californer
- Pervaziv AI Advances Cortex with 3-Tier Inference Cache Architecture for Faster, Trusted AI Workflows
- ClearSight Therapeutics Receives NIH SBIR Phase I Award for Conjunctivitis and EKC Research
- California: National leaders and lawmakers celebrate Governor Newsom's signature on the most comprehensive data center laws in the nation
- Stockdale Capital Partners Announces Strategic Partnership in AI Platform Zinq AI
- Lunai Bioworks (N A S D A Q: LNAI) Takes Parkinson's Discovery to the Next Level With Exclusive Tanaist Agreement
Despite the high profile attacks from the DarkSide RaaS group exposed in Q2 2021, REvil was the most detected in Q1, followed by the RansomeXX, Ryuk, NetWalker, Thanos, MountLocker, WastedLocker, Conti, Maze and Babuk strains.
Coin Miner Malware
While prominent ransomware attacks have focused attention on how criminals use ransomware to monetize their crimes with payments in cryptocurrency, a first quarter 117% surge in the spread of cryptocurrency-generating coin mining malware can be attributed to a sharp spike in 64-bit CoinMiner applications.
Rather than locking up victims' systems and holding them hostage until cryptocurrency payments are made, Coin Miner malware infects compromised systems and silently produces cryptocurrency using those systems' computing capacity for the criminals that designed and launched such campaigns. The advantage to cybercriminals is that there is zero interaction required of both the perpetrator and the victim. While the victim's computers may operate slower than usual due the coin miner's workload, victims may never become aware that their system is creating monetary value for criminals.
"The takeaway from the ransomware and coin miner trends shouldn't be that we need to restrict or even outlaw the use of cryptocurrencies," Samani continued. "If we have learned anything from the history of cybercrime, criminals counter defenders' efforts by simply improving their tools and techniques, sidestepping government restrictions, and always being steps ahead of defenders in doing so. If there are efforts to restrict cryptocurrencies, perpetrators will develop new methods to monetize their crimes, and they only need to be a couple steps ahead of governments to continue to profit."
Threats & Victims
Overall Malware Threats. The first quarter of 2021 saw the volume of new malware threats average 688 threats per minute, an increase of 40 threats per minute over Q4 2020.
IoT & Linux Devices. A variety of new Mirai malware variants drove increases on the Internet of Things (IoT) and Linux malware categories in Q1. The Moobot family (a Mirai variant) was observed to be mass-spread and accounted for multiple Mirai variants. These variants all exploit vulnerabilities in IoT devices like DVRs, webcams and internet routers. Once exploited, the malware is hidden on the system, downloads later stages of the malware and connects with the command-and-control server (C2). When the compromised IoT devices are connected to their botnet, they can be commandeered to participate in DDoS attacks.
More on The Californer
- OakBloomIQ Launches Free AI Visibility Score, Reveals How AI Rates You
- Revenue Optics Names Prat Patibandla Director of Growth Marketing
- California: Governor Newsom delivers $886 million in utility bill relief, with millions of households receiving an average of $75 this summer
- Independent Autopsies Are Changing Civil Cases: Kansas City Forensic Explains Why Families Are Seeking Second Opinions
- JEGS Launches Transformed Digital Commerce Platform Powered by PhaseZero
Industry Sectors. McAfee tracked a 54% increase in publicly reported cyber incidents targeting the technology sector during the first quarter of 2021. The Education and Financial/Insurance sectors followed with 46% and 41% increases respectively, whereas reported incidents in Wholesale/Retail and Public Sector declined by 76% and 39% respectively.
Regions. These incidents surged in 54% in Asia and 43% in Europe, but declined 13% in North America. While reported incidents actually declined 14% in the United States, these incidents grew 84% in France and 19% in the United Kingdom.
Resources:
About McAfee Labs and Advanced Threat Research
McAfee Labs and McAfee Advanced Threat Research are a leading source for threat research, threat intelligence, and cybersecurity thought leadership. With data from over a billion sensors across key threats vectors—file, web, message, and network— McAfee Labs and McAfee Advanced Threat Research deliver real-time threat intelligence, critical analysis, and expert thinking to improve protection and reduce risks.
About McAfee
McAfee Corp. (Nasdaq: MCFE) is the device-to-cloud cybersecurity company. Inspired by the power of working together, McAfee creates consumer and business solutions that make our world a safer place. www.mcafee.com
McAfee® and the McAfee logo are trademarks of McAfee, LLC or its subsidiaries in the United States and other countries. Other marks and brands may be claimed as the property of others.
Filed Under: Business
0 Comments
Latest on The Californer
- Ventura College Foundation Accepting Scholarship Applications for 2027-28 School Year
- What they are saying: Strong support for California's new laws to expand EV access, consumer choice, and cut dependence on oil
- Las Vegas Attorney Thomas Boley Publishes Free Plain-English Guide to 100 Nevada Criminal Laws, in English and Spanish
- Ahead of Climate Week NYC, Governor Newsom announces California cut climate pollution again as economy keeps growing
- Scale Your Side Hustle Overnight: Why Smart Creators Are Ditching Traditional Livestreaming
- California: Governor Newsom signs most comprehensive data center laws in the nation, providing communities more control on water, electricity, and land use
- Explosive New Book Warns Toxic Peril to Black and Brown Communities in America
- Bank Statement Loans Up to $30 Million: Lendmire Announces High-Net-Worth Financing
- Marc Yaffee Returns to Rolling Hills Casino Saturday, October 3
- Governor Newsom proclaims state of emergency to bolster statewide El Nino preparedness, protect California
- NYC Big Book Award Celebrates 10th Anniversary with Announcement of 2026 Winners
- Things to Do in Temecula This Weekend: Free Wellness Event Sept. 26
- Countrywide Rental Provides Reliable Portable Restroom Solutions in Bynum, Alabama
- Repair Shop Solutions Launches Most Comprehensive Photo Editing for Digital Vehicle Inspections
- California: Governor Newsom issues legislative update 9.20.2026
- 12 Simple Practices Proven to Switch on Your Body's "Happy Genes"
- California establishes Dolly Parton Day
- California: Governor Newsom signs bills as Los Angeles readies for 2028 Olympic and Paralympic Games
- Governor Gavin Newsom signs legislation to accelerate California's EV future, expand consumer choice, and strengthen energy independence
- Best Dodge Lemon Law Attorney in Los Angeles County