2017年度金融网络威胁(英文版)-1mb
报告摘要
Summary of Financial Cyberthreats in 2017
Core Content
The year 2017 marked a significant evolution in the financial cyberthreat landscape. Cybercriminals increasingly targeted financial systems and services rather than just individual users, leveraging sophisticated techniques and exploiting vulnerabilities in both personal and corporate environments. The report highlights the growing prevalence of phishing attacks, banking malware, and supply chain threats, emphasizing the need for enhanced security measures and user awareness.
Main Points
1. Phishing Trends
- Increase in Financial Phishing: The share of financial phishing attacks increased from 47.5% to 54% of all phishing detections in 2017, the highest recorded by Kaspersky Lab.
- Banking Phishing Dominance: Banking phishing was the most common type, accounting for 53.8% of heuristic detections.
- Payment Systems and Online Shops: Phishing attacks against payment systems and online shops also increased, by 4.3% and 0.8% respectively.
- Mac Users at Risk: The share of financial phishing attacks targeting Mac users nearly doubled in 2017, reaching 55.6% from 31.4% in 2016.
- Targeted Brands: The most targeted brands for phishing included Apple, Amazon, PayPal, MasterCard, and Visa, with some attacks mimicking government and security-related entities.
2. Banking Malware Overview
- Decrease in Attacks: The number of users attacked by banking malware dropped by 30% in 2017 compared to 2016, from 1,088,900 to 767,072.
- Top Malware Families: Zbot remained the most widespread family, but Gozi gained significant ground, surpassing Zbot in the number of attacks.
- Corporate Targeting: Corporate users accounted for 19% of all banking malware attacks in 2017, showing a steady increase in targeted attacks against businesses.
- New Malware Family: Trickster emerged as a dominant player in unique attacks, surpassing Citadel due to its rapid growth and frequent updates.
3. Geographic Distribution
- Top Countries: In 2017, Germany and China were the top two countries in terms of users attacked by banking malware, following Russia in 2016.
- Regional Shifts: The shift was attributed to the adoption of two-factor authentication in Russia, making it a less attractive target for attackers.
4. New Threats and Actors
- Silence Group: A new group called Silence was identified for targeting financial organizations, using techniques similar to Carbanak and Metel.
- Lazarus Group: The Lazarus Group was linked to the 2016 Bangladesh Central Bank attack, and its affiliate, Bluenoroff, was responsible for financial-related attacks.
- Supply Chain Attacks: These attacks, such as ExPetr and ShadowPad, became more prevalent, with attackers compromising trusted software packages to distribute malware to large organizations.
5. Malware Techniques
- Fileless Malware: Used in ATM attacks, allowing for more stealthy operations.
- Phishing Pages: Often mimicked legitimate financial institutions, payment systems, and even government bodies to trick users.
- Social Engineering: Techniques such as impersonating security solutions or threatening account suspension were commonly used to lure victims.
Key Information
- Financial phishing became the most common type of cyberattack in 2017, with over half of all phishing attempts targeting financial services.
- Malware Families: Zbot and Gozi were the leading families in terms of user attacks, while Trickster led in unique attacks.
- Corporate Targets: The percentage of attacks targeting corporate users increased, indicating a strategic shift by cybercriminals.
- Supply Chain Vulnerabilities: These attacks are becoming more common, as seen with the CCleaner and Netsarang incidents.
- User Awareness: It is crucial for users to verify the legitimacy of websites and emails, especially when dealing with financial transactions.
Conclusion
2017 saw a shift in the financial cyberthreat landscape, with an increase in sophisticated attacks targeting both individuals and corporations. The rise in phishing attacks, especially those involving well-known financial brands, and the emergence of new malware families like Trickster, underscore the evolving nature of cybercrime. As a result, businesses and users must remain vigilant and adopt robust security measures to mitigate these threats.
试读结束,高清完整版pdf/doc/ppt,请点下载