According to a report by Check Point Software Technologies Limited, India stood at 26th rank for malware risk in October 2024. The report highlighted a concerning trend in the cyber security landscape, that is the rise of info stealers and sophistication of attack methods employed by cyber criminals.

In India, healthcare remained the most impacted industry in September 2024 followed by education/research and government/military. Meanwhile, in October 2024, education/research remained in the first place in the attacked industries globally, followed by government/military and communications.

As per the report, researchers have discovered an infection chain where fake CAPTCHA pages are being utilised to distribute Lumma Stealer malware, which has climbed to fourth place in monthly top malware rankings. This campaign is notable for its global reach, affecting multiple countries through two primary infection vectors: one involving cracked game download uniform resource locator (URLs) and the other through phishing emails targeting GitHub users as an innovative new means of attack vector. The infection process misleads victims into executing a malicious script that has been copied to their clipboard, showcasing the increasing prevalence of info stealers as an effective means for cyber criminals to exfiltrate credentials and sensitive data from compromised systems.

The report highlighted that in the mobile malware sphere, new version of Necro has emerged as a significant threat, ranking second among mobile malwares. Necro has infected various popular applications, including game mods available on Google Play, with a cumulative audience of over 11 million android devices. The malware employs obfuscation techniques to evade detection and utilises steganography, which is the practice of concealing information within another message or physical object to avoid detection, to conceal its payloads. Once activated, it can display advertisements in invisible windows, interact with them, and even subscribe victims to paid services, highlighting the evolving tactics used by attackers to monetise their operations.

Top malware families include:

  • FakeUpdates- It is the most prevalent malware in October 2024 with an impact of six per cent worldwide organisations, followed by Androxgh0st with a global impact of 5 per cent, and AgentTesla with a global impact of 4 per cent. It is a downloader written in JavaScript. It writes the payloads to disk prior to launching them. FakeUpdates led to further compromise via many additional malwares, including GootLoader, Dridex, NetSupport, DoppelPaymer, and AZORult.
  • Androxgh0st- It is a botnet that targets Windows, Mac, and Linux platforms. For initial infection, Androxgh0st exploits multiple vulnerabilities, specifically targeting PHPUnit, Laravel Framework, and Apache Web Server. The malware steals sensitive information such as Twilio account information, simple mail transfer protocol (SMTP) credentials, AWS key, etc. It uses Laravel files to collect the required information. It has different variants which scan for different information.
  • AgentTesla- It is an advanced remote access trojan (RAT) functioning as a keylogger and information stealer, which is capable of monitoring and collecting the victim’s keyboard input, system keyboard, taking screenshots, and exfiltrating credentials to a variety of software installed on a victim’s machine (including Google Chrome, Mozilla Firefox and the Microsoft Outlook email client).
  • Lumma Stealer- Also referred to as LummaC2, is a Russian-linked information-stealing malware that has been operating as a malware-as-a-service (MaaS) platform since 2022. This malware, discovered in mid-2022, is continuously evolving and actively distributed on Russian-language forums. As a typical information-stealer, LummaC2 focuses on harvesting various data from infected systems, including browser credentials and cryptocurrency account information.
  • Formbook- It is an Infostealer targeting the Windows OS and was first detected in 2016. It is marketed as MaaS in underground hacking forums for its strong evasion techniques and relatively low price. FormBook harvests credentials from various web browsers, collects screenshots, monitors and logs keystrokes, and can download and execute files according to orders from its command and control (C&C).
  • NJRat- NJRat is a remote accesses Trojan, targeting mainly government agencies and organisations in the Middle East. The Trojan has first emerged on 2012 and has multiple capabilities, capturing keystrokes, accessing the victim’s camera, stealing credentials stored in browsers, uploading and downloading files, performing process and file manipulations, and viewing the victim’s desktop. NJRat infects victims via phishing attacks and drive-by downloads, and propagates through infected USB keys or networked drives, with the support of C&C server software.
  • AsyncRat- Asyncrat is a Trojan that targets the Windows platform. This malware sends out system information about the targeted system to a remote server. It receives commands from the server to download and execute plugins, kill processes, uninstall/update itself, and capture screenshots of the infected system.
  • Remcos- It is a RAT that first appeared in the wild in 2016. Remcos distributes itself through malicious Microsoft Office documents, which are attached to spam emails, and is designed to bypass Microsoft Windowss user account control (UAC) security and execute malware with high-level privileges.
  • Glupteba- Known since 2011, Glupteba is a backdoor that gradually matured into a botnet. By 2019 it included a C&C address update mechanism through public Bitcoin lists, an integral browser stealer capability and a router exploiter.
  • Vidar- Vidar is an info stealer malware operating as MaaS that was first discovered in the wild in late 2018. The malware runs on Windows and can collect a wide range of sensitive data from browsers and digital wallets. Additionally, the malware is used as a downloader for ransomware.

The report also mentioned some top exploited vulnerabilities including:

  • Web servers malicious URL directory traversal (CVE-2010-4598, CVE-2011-2474, CVE-2014-0130, CVE-2014-0780, CVE-2015-0666, CVE-2015-4068, CVE-2015-7254, CVE-2016-4523, CVE-2016-8530, CVE-2017-11512, CVE-2018-3948, CVE-2018-3949, CVE-2019-18952, CVE-2020-5410, CVE-2020-8260)- There exists a directory traversal vulnerability on different web servers. The vulnerability is due to an input validation error in a web server that does not properly sanitise the URI for the directory traversal patterns. Successful exploitation allows unauthenticated remote attackers to disclose or access arbitrary files on the vulnerable server.
  • Command injection over hypertext transfer protocol (HTTP) (CVE-2021-43936, CVE-2022-24086) – A command injection over HTTP vulnerability has been reported. A remote attacker can exploit this issue by sending a specially crafted request to the victim. Successful exploitation would allow an attacker to execute arbitrary code on the target machine.
  • Zyxel ZyWALL command injection (CVE-2023-28771)- A command injection vulnerability exists in Zyxel ZyWALL. Successful exploitation of this vulnerability would allow remote attackers to execute arbitrary operating system (OS) commands in the effected system.

Further, report mentioned that in October 2024, Joker in the first place in the most prevalent mobile malware, followed by Necro and Anubis:

  • Joker- An android Spyware in Google Play, designed to steal SMS messages, contact lists and device information. Furthermore, the malware signs the victim silently for premium services in advertisement websites.
  • Necro- Necro is an android trojan dropper. It is capable of downloading other malware, showing intrusive advertisments and stealing money by charging paid subscriptions.
  • Anubis- Anubis is a banking Trojan malware designed for android mobile phones. Since it was initially detected, it has gained additional functions including RAT functionality, keylogger, audio recording capabilities and various ransomware features. It has been detected on hundreds of different applications available in the Google Store.

Furthermore, the data is based on insights from ransomware ‘shame sites’ run by double-extortion ransomware groups which posted victim information. RansomHub is the most prevalent ransomware group in October 2024, responsible for 17 per cent of the published attacks, followed by Play with 10 per cent and Meow with five per cent.

  • RansomHub- RansomHub is a ransomware-as-a-service (RaaS) operation that emerged as a rebranded version of the previously known knight ransomware. Surfacing prominently in early 2024 in underground cybercrime forums, RansomHub has quickly gained notoriety for its aggressive campaigns targeting various systems including Windows, macOS, Linux, and particularly VMware ESXi environments. This malware is known for employing sophisticated encryption methods.
  • Play- Play ransomware, also referred to as PlayCrypt, is a ransomware that first emerged in June 2022. This ransomware has targeted a broad spectrum of businesses and critical infrastructure across North America, South America, and Europe, affecting approximately 300 entities by October 2023. Play Ransomware typically gains access to networks through compromised valid accounts or by exploiting unpatched vulnerabilities, such as those in Fortinet secure sockets layer virtual private networks (SSL VPNs). Once inside, it employs techniques like using living-off-the-land binaries (LOLBins) for tasks such as data exfiltration and credential theft.
  • Meow- Meow ransomware is a variant based on the conti ransomware, known for encrypting a wide range of files on compromised systems and appending the ‘MEOW’ extension to them. It leaves a ransom note named ‘readme.txt’, instructing victims to contact the attackers via email or Telegram to negotiate ransom payments. Meow Ransomware spreads through various vectors, including unprotected remote desktop protocol (RDP) configurations, email spam, and malicious downloads, and uses the ChaCha20 encryption algorithm to lock files, excluding ‘.exe’ and text files.

Commenting on the report, Maya Horowitz, vice president, research, Check Point Software, said, “The rise of sophisticated info stealers underscores a growing reality. Cyber criminals are evolving their methods and leveraging innovative attack vectors. Organisations must go beyond traditional defenses, adopting proactive and adaptive security measures that anticipate emerging threats to counter these persistent challenges effectively.”