WatchGuard Internet Security Insights Q1 2020 [Infographic]
WatchGuard Technologies has released its Internet Security Report for Q1 2020. The report compiles data drawn from anonymized Firebox Feed data from active WatchGuard appliances whose owners have opted in to share data. Over 44,000 appliances worldwide contribute threat intelligence data to the report through WatchGuard’s Threat Labs.
WatchGuard’s Internet Security Report prepares midmarket businesses, the service providers that support them, and the end users that work for them with data on the trends, research and best practices they need to defend against modern security threats. Here are the key findings from the Q1 2020 report:
- Monero cryptominers surge in popularity. Five of the top ten domains distributing malware in Q1 (identified by WatchGuard’s DNS filtering service DNSWatch) either hosted or controlled Monero cryptominers. This sudden jump in cryptominer popularity could simply be due to its utility; adding a cryptomining module to malware is an easy way for online criminals to generate passive income.
- Flawed-Ammyy and Cryxos malware variants join top lists. The Cryxos trojan was third on WatchGuard’s top-five encrypted malware list and also third on its top-five most widespread malware detections list, primarily targeting Hong Kong. It is delivered as an email attachment disguised as an invoice and will ask the user to enter their email and password, which it then stores. Flawed-Ammyy is a support scam where the attacker uses the Ammyy Admin support software to gain remote access to the victim’s computer.
- Three-year-old Adobe vulnerability appears in top network attacks. An Adobe Acrobat Reader exploit that was patched in Aug. 2017 appeared in WatchGuard’s top network attacks list for the first time in Q1. This vulnerability resurfacing several years after being discovered and resolved illustrates the importance of regularly patching and updating systems.
- Mapp Engage, AT&T and Bet365 targeted with spear phishing campaigns. Three new domains hosting phishing campaigns appeared on WatchGuard top-ten list in Q1 2020. They impersonated digital marketing and analytics product Mapp Engage, online betting platform Bet365 (this campaign was in Chinese) and an AT&T login page (this campaign is no longer active at the time of the report’s publication).
- Malware hits and network attacks decline. Overall there were 6.9% fewer malware hits and 11.6% fewer network attacks in Q1, despite a 9% increase in the number of Fireboxes contributing data. This could be attributed to fewer potential targets operating within the traditional network perimeter with worldwide work-from-home policies in full force during the COVID-19 pandemic.
- Great Britain and Germany heavily targeted by widespread malware threats. WatchGuard’s most widespread malware list showed Germany and Great Britain were top targets for almost all of the most prevalent malware in Q1.
The complete report includes key defensive best practices that organizations of all sizes can use to protect themselves in today’s threat landscape and a detailed analysis of how the COVID-19 pandemic and associated shift to working from home affected the cybersecurity landscape.