2024-01-06-卡巴斯基-2023年安全报告_20页_6mb
报告摘要
Report Summary
Introduction: This report outlines cybersecurity threats observed during the period November 2022 to October 2023, based on data from Kaspersky's Security Network (KSN). The statistics are derived from Kaspersky security solutions used by consenting users worldwide.
Key Findings & Threat Landscape Overview:
- During the period, Kaspersky solutions blocked:
- Over
437 millionmalware-related attacks from online resources. 106 millionunique malicious URLs.112 millionunique malicious objects via Web Anti-Virus.193 thousanduser computers from ransomware attacks.1.14 millionusers from miner infections.325 thousanduser computers from financial malware attacks.
- Over
Deeper Analysis by Threat Category:
-
Financial Threats:
- Kaspersky blocked financial malware attacks targeting
325,225unique users. - Geographically, the highest percentage of users attacked by financial malware (relative to other malware) was observed in countries like
Afghanistan(6.2%),Turkmenistan(5.4%),Tajikistan(4.0%),China(3.3%),Sudan(2.6%),Mauritania(2.6%),Switzerland(2.5%),Yemen(2.4%),Egypt(2.2%), andParaguay(2.2%). - The most prevalent families of financial malware were Ramnit/Nimnul (30.4%), Zbot/Zeus (18.9%), Emotet (16.1%), CliptoShuffler (6.1%), RTM (2.2%), Danabot (1.9%), Qbot/Qakbot (1.8%), IcedID (1.3%), Tinba/TinyBanker (1.2%), and BitStealer (1.0%).
- Kaspersky blocked financial malware attacks targeting
-
Ransomware:
- Ransomware Trojan attacks impacted
193,662unique users (including52,999corporate users and6,351SME users). - Azerbaijan had the highest absolute number of victims, while
Taiwan(2.41%),Yemen(1.85%),South Korea(1.47%),Sudan(1.15%), andMozambique(1.09%) showed the highest victim load relative to their user base. - Common ransomware families included Magniber (17.14%), generic verdicts (making up roughly half the threats -
12.39%,9.43%,5.69%,2.91%), WannaCry (11.46%), Stop/Djvu (6.39%), and PhNy (5.69%).
- Ransomware Trojan attacks impacted
-
Miners:
- Attempts to install miners resulted in attempts against
1.14 millionunique users (accounting for3.12%of all attacks). - The most often blocked miner was Trojan.Win32.Miner.gen (25.12%).
- Geographically, attacks were most prevalent in
Turkmenistan(10.38%),Afghanistan(7.67%),Kazakhstan(3.77%),Tajikistan(3.33%),Uzbekistan(2.92%), andMozambique(2.82%).
- Attempts to install miners resulted in attempts against
-
Attacks on macOS:
- Observed threats included spyware stealing Keychain data, infostealers disguised as games, infected development projects, backdoor sales, compromised software supply chains, and Rust-written backdoors.
- macOS threats were dominated by adware (
AdWare.OSX.Pirrit.ac,AdWare.OSX.Agent.ai, etc.), InfoStealers, and Monitor Malware.
-
IoT Attacks:
- Attackers predominantly targeted IoT devices via
Telnet(83.85% of exploited services detected) andSSH(16.15%). - Honeypot data revealed attack sessions overwhelmingly used
Telnet(98.60%of active sessions). - The top malware found on compromised IoT honeypots were NyaDrop, Mirai variants (multiple), Agent.nx, Gafgyt, Shell.Agent.p, and Mirai variants.
- Attackers predominantly targeted IoT devices via
-
Attacks via Web Resources:
- Kaspersky blocked
437 millionattacks originating from malicious online resources (80.49%from 10 nations). - Countries significantly contributing included
Taiwan(24.41%risk level ranking),Greece,Belarus,Algeria,Turkey,Serbia,Tunisia,Moldova,Nepal, andBangladesh. - The most common Malware-class objects encountered via the web were malicious URLs (47.62%), followed by generic Trojan scripts (
26.21%).
- Kaspersky blocked
-
Local Threats (File-based/Malware Detection):
- On average,
32.44%of Kaspersky user computers/systems devices/hardware faced local infection risk (at least one malware detected). - Geographically, high risks were noted in
Yemen,Turkmenistan,Afghanistan,Bangladesh,Myanmar,Algeria,Benin,Rwanda,Uzbekistan, andGuinea. - The most common local threats detected on user computers included Generic Malicious Objects (
17.87%), BroSubsc, Misslink, GenAutorunReg, Script.Generic, Agent.gen, etc.
- On average,
See accompanying sections in the report for detailed breakdowns by threat verdict category and methodology context.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载