This page was machine-translated and may differ from the original. View original
Utilization of Exploit Attacks, Rising Botnet Recurrence Rates and Automated Malware Growth
Fortinet Korea has released the '2017 Q3 Global Threat Outlook Report' recently published by FortiGuard Labs, its security research division.
The report explains that cybercriminals are leveraging known exploit attacks combined with automated attack methods at an unprecedented pace and scale, leading to high botnet recurrence rates and an increase in automated malware.
Phil Quade, CISO (Chief Information Security Officer) at Fortinet, stated: "As exemplified by WannaCry and Apache Struts cases, vulnerabilities that have been known for a long time but remain unpatched continue to serve as a gateway for persistent attacks. It is critical to maintain vigilance against new threats and vulnerabilities, and to continuously monitor changes in security events occurring within organizational environments. It is urgent to prioritize maintaining security hygiene and adopt a fabric-based security approach utilizing automation, integration, and strategic segmentation. Since threat actors are adopting automated scripting technologies, there is a need for smarter and more solid investment in detecting and neutralizing new attacks today."
Attack severity demands urgency: In Q3 2017, 79% of enterprises experienced serious attacks. The complete Q3 survey data identified 5,973 exploits, 14,904 malware variants derived from 2,466 distinct malware variant families, and 245 unique botnets. Additionally, Fortinet has identified 185 zero-day vulnerabilities through this year.
Botnet recurrence: Notably, many organizations experienced intrusions from the same botnet multiple times. This occurs when organizations fail to comprehensively understand the full scope of intrusion, when botnets temporarily cease activity after business operations return to normal and then resume attacks, or when root causes are not identified, resulting in reinfection with the same malware.
Swarming Vulnerabilities: The application exploit used by attackers against U.S. credit reporting agency Equifax was detected 6,000 times in the previous quarter and identified as the most prevalent exploit. It was also recorded as the most prevalent attack this quarter. In fact, three exploits targeting the Apache Struts framework filled the top 10 most prevalent attacks. This is a clear example of how attackers target broadly distributed and vulnerable targets.
Mobile threats: Mobile malware was detected in one out of every four enterprises. Four specific mobile malware families received attention for the first time due to their high prevalence. This demonstrates that attackers are targeting mobile devices and that threats are becoming automated and polymorphic. Greater vigilance is required as the holiday shopping season approaches, when mobile purchases will increase and IoT devices become popular gifts.
Widespread malware with evasion capabilities: The most common functionality in top malware families is the ability to download, upload, and remove malware based on infected systems. Additionally, malware capable of establishing remote access connections, capturing user input, and collecting system information has been frequently discovered. These advanced techniques have become recent standards, all demonstrating how modern malware strengthens its intelligent and automated characteristics.
Ransomware remains active: Following a halt in activity during the first half of the year, Locky ransomware has been steadily increasing, with approximately 10% of enterprises reporting it. Additionally, during Q3, at least 22% of organizations detected multiple types of ransomware.
Cybercriminals target organizations of all sizes: Small and medium-sized enterprises showed high botnet infection rates. Cybercriminals target SMEs that possess high-value data assets but lack the same level of security resources and technology as large enterprises. Simultaneously, the attack surface for SMEs is expanding rapidly as cloud adoption rates increase.
Critical SCADA systems: Beyond large-scale attacks such as those involving Apache Struts, some threats either went undetected by organizations or caused severe damage. Of the exploits tracked across various types of SCADA (Supervisory Control and Data Access) systems, only one exceeded the 1/1000 prevalence threshold, with nothing observed in over 1% of enterprises. These statistics are highly significant because attacks on SCADA infrastructure can cause severe damage.
Countering Automated Attacks Through Actionable Intelligence and Automated Security
The Q3 results are largely consistent with the 2018 Threat Outlook that FortiGuard Labs will announce soon. Both trend and threat data predict new types of attacks that may emerge in the future. The cybercrime community is rapidly adopting automation as the latest technology to create diverse attacks exploiting vulnerabilities.
Only a security framework that automates security and networking components based on advanced threat intelligence sharing and open architecture, and combines them into proactive defense and response systems, can take responsibility for future security. To defend against an ever-evolving threat landscape, flexibility is required to rapidly implement the latest security strategies and solutions based on the ability to seamlessly apply cutting-edge technologies while maintaining existing infrastructure.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
김지혜 Reporter

.png)












