This page was machine-translated and may differ from the original. View original
Over 1/4 of Enterprises Have "Experienced Mobile Malware Attacks" – What Are the Solutions?
FortiGuard Labs Announces 2018 Q3
Global Security Threat Landscape Report
2018 Q3 Global Threat Landscape Report
Fortinet announced on the 28th the '2018 Q3 Global Threat Landscape Report' published by FortiGuard Labs, its security research division.
The report once again emphasizes that cyber threats are becoming more sophisticated and evolving. Additionally, it revealed that unique security threat groups and variants are increasing, and botnets are continuously infiltrating enterprise organizations, causing infection incidents.
Cybercriminals Focused on Continuously Developing Threats
Cybercriminals are not only expanding their attack arsenal but are also continuously developing new strategies to bypass defense systems. Unique malware variants increased by 43%, while malware families during the same period increased by approximately 32%.
Daily malware detections per enterprise also increased by 62%. Following this trend, unique exploits increased by approximately 10%, while exploit detections per enterprise increased by 37%.
Changes in Q3 Cyber Threat Volume
Cybercriminals are continuously evolving threats by creating unique malware variants and families. Consequently, the importance of cyber security threat intelligence and assessment tools is being increasingly emphasized.
Target: Mobile Devices
Over 1/4 of organizations experienced mobile malware attacks, with the majority using the Android operating system. 14% of all malware alerts were related to Android. In comparison, only 0.000311% of all threats targeted Apple iOS.
As the large-scale end-of-year shopping season approaches, mobile threats are emerging as a security threat that must be addressed. These threats serve as a gateway through which corporate networks can be exploited. Cybercriminals are well aware that mobile devices are easy targets for infiltrating networks and are exploiting this fact.
Another Gateway to Attack: Cryptojacking
The scope of cryptojacking continues to expand. Last year, platforms affected by cryptojacking increased by 38%, and the number of unique signatures nearly doubled. This includes both sophisticated new platforms for skilled attackers as well as "as-a-service" platforms for novice attackers.
IoT botnets are increasingly utilizing cryptojacking exploits for their attack strategies. While this can be viewed as a nuisance threat that simply hijacks unused CPU cycles, security leaders must recognize that cryptojacking can also serve as a gateway to additional attacks. Underestimating the impact of cryptojacking can increase organizational risk.
Malicious Network Traffic Ratio Higher on Weekends and Holidays
According to the report, business traffic significantly decreases on weekends and holidays, while malicious network traffic accounts for a higher proportion. This is because most organizations have fewer employees working on weekends and holidays, resulting in reduced business traffic volume.
As the overall traffic volume decreases, the probability of detecting malicious attacks becomes much higher. This can be an opportunity to increase visibility into cybercrime using more automated and sophisticated techniques.
Botnets: Detection and Removal Becoming More Difficult
Infection days per enterprise increased from 7.6 days to 10.2 days, a 34% increase, while the botnet detection index rose by only 2%. This demonstrates that botnets are becoming more sophisticated and are harder to detect and remove. Additionally, it shows that some organizations are not properly practicing cybersecurity hygiene.
'Security hygiene' plays an important role in thoroughly understanding the full scope of these attacks. While botnets may temporarily suspend activity, if the root cause or 'patient zero' is not identified, the botnet can resume activity after business operations restart.
Growth in Encrypted Traffic
Encrypted traffic accounted for over 72% of total network traffic. This is a significant increase from 55% a year ago.
Encryption plays a definitive role in data protection as data moves between core, cloud, and endpoint environments. However, on the other hand, it presents challenges for traditional security solutions.
Due to IPS performance limitations and critical firewalls in some legacy security solutions, enterprises face restrictions in thoroughly inspecting encrypted data. Because malicious activities in this traffic are not analyzed, it ultimately serves as a mechanism for cybercriminals to distribute malware or exfiltrate data.
Digital Transformation Should Accompany Security Transformation
This quarter's threat landscape report once again emphasizes various threat trends that FortiGuard Labs' global research team has announced over time.
Various Q3 Threat Statistics
Enterprises must also transform their security strategy as part of digital transformation.
Isolated legacy security devices and weak security hygiene do not provide adequate visibility or control, increasing risk in today's threat environment. Instead, a 'security fabric' that encompasses the extended entire network environment with integrated security elements is critical to meet the needs of today's threat environment and protect the expanded attack surface.
This approach enables rapid and accurate sharing of actionable cyber security threat intelligence, reduces critical detection windows, and is an automated remediation method capable of effectively responding to today's multi-vector exploits.
Phil Quade, Chief Information Security Officer at Fortinet, stated, "Not long ago, ransomware was rampant, and recently, cryptojacking, mobile malware, and cyber attacks on business-critical supply chains are spreading," adding that "cyber attackers are continuously integrating new threats and are leveraging automation technologies for malicious activities, segmentation, and integration in faster and more scalable ways."
He further added, "Defending against this has become an important security strategy for today's IT and OT environments."
Global Security Threat Landscape Report

2018 Q3 Global Threat Landscape Report
Fortinet announced on the 28th the '2018 Q3 Global Threat Landscape Report' published by FortiGuard Labs, its security research division.
The report once again emphasizes that cyber threats are becoming more sophisticated and evolving. Additionally, it revealed that unique security threat groups and variants are increasing, and botnets are continuously infiltrating enterprise organizations, causing infection incidents.
Cybercriminals Focused on Continuously Developing Threats
Cybercriminals are not only expanding their attack arsenal but are also continuously developing new strategies to bypass defense systems. Unique malware variants increased by 43%, while malware families during the same period increased by approximately 32%.
Daily malware detections per enterprise also increased by 62%. Following this trend, unique exploits increased by approximately 10%, while exploit detections per enterprise increased by 37%.

Changes in Q3 Cyber Threat Volume
Cybercriminals are continuously evolving threats by creating unique malware variants and families. Consequently, the importance of cyber security threat intelligence and assessment tools is being increasingly emphasized.
Target: Mobile Devices
Over 1/4 of organizations experienced mobile malware attacks, with the majority using the Android operating system. 14% of all malware alerts were related to Android. In comparison, only 0.000311% of all threats targeted Apple iOS.
As the large-scale end-of-year shopping season approaches, mobile threats are emerging as a security threat that must be addressed. These threats serve as a gateway through which corporate networks can be exploited. Cybercriminals are well aware that mobile devices are easy targets for infiltrating networks and are exploiting this fact.
Another Gateway to Attack: Cryptojacking
The scope of cryptojacking continues to expand. Last year, platforms affected by cryptojacking increased by 38%, and the number of unique signatures nearly doubled. This includes both sophisticated new platforms for skilled attackers as well as "as-a-service" platforms for novice attackers.
IoT botnets are increasingly utilizing cryptojacking exploits for their attack strategies. While this can be viewed as a nuisance threat that simply hijacks unused CPU cycles, security leaders must recognize that cryptojacking can also serve as a gateway to additional attacks. Underestimating the impact of cryptojacking can increase organizational risk.
Malicious Network Traffic Ratio Higher on Weekends and Holidays
According to the report, business traffic significantly decreases on weekends and holidays, while malicious network traffic accounts for a higher proportion. This is because most organizations have fewer employees working on weekends and holidays, resulting in reduced business traffic volume.
As the overall traffic volume decreases, the probability of detecting malicious attacks becomes much higher. This can be an opportunity to increase visibility into cybercrime using more automated and sophisticated techniques.
Botnets: Detection and Removal Becoming More Difficult
Infection days per enterprise increased from 7.6 days to 10.2 days, a 34% increase, while the botnet detection index rose by only 2%. This demonstrates that botnets are becoming more sophisticated and are harder to detect and remove. Additionally, it shows that some organizations are not properly practicing cybersecurity hygiene.
'Security hygiene' plays an important role in thoroughly understanding the full scope of these attacks. While botnets may temporarily suspend activity, if the root cause or 'patient zero' is not identified, the botnet can resume activity after business operations restart.
Growth in Encrypted Traffic
Encrypted traffic accounted for over 72% of total network traffic. This is a significant increase from 55% a year ago.
Encryption plays a definitive role in data protection as data moves between core, cloud, and endpoint environments. However, on the other hand, it presents challenges for traditional security solutions.
Due to IPS performance limitations and critical firewalls in some legacy security solutions, enterprises face restrictions in thoroughly inspecting encrypted data. Because malicious activities in this traffic are not analyzed, it ultimately serves as a mechanism for cybercriminals to distribute malware or exfiltrate data.
Digital Transformation Should Accompany Security Transformation
This quarter's threat landscape report once again emphasizes various threat trends that FortiGuard Labs' global research team has announced over time.

Various Q3 Threat Statistics
Enterprises must also transform their security strategy as part of digital transformation.
Isolated legacy security devices and weak security hygiene do not provide adequate visibility or control, increasing risk in today's threat environment. Instead, a 'security fabric' that encompasses the extended entire network environment with integrated security elements is critical to meet the needs of today's threat environment and protect the expanded attack surface.
This approach enables rapid and accurate sharing of actionable cyber security threat intelligence, reduces critical detection windows, and is an automated remediation method capable of effectively responding to today's multi-vector exploits.
Phil Quade, Chief Information Security Officer at Fortinet, stated, "Not long ago, ransomware was rampant, and recently, cryptojacking, mobile malware, and cyber attacks on business-critical supply chains are spreading," adding that "cyber attackers are continuously integrating new threats and are leveraging automation technologies for malicious activities, segmentation, and integration in faster and more scalable ways."
He further added, "Defending against this has become an important security strategy for today's IT and OT environments."
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
이수민 Reporter














