Trend Micro Stops 82 Billion Threats as Ransomware Soars in 2016

Exterminator

Level 85
Thread author
Verified
Top Poster
Well-known
Oct 23, 2012
12,527
Trend Micro blocked nearly 82 billion threats in 2016, with ransomware and Business Emil Compromise (BEC) in particular causing havoc for organizations worldwide, according to a new report.

The security giant’s TrendLabs 2016 Security Roundup report revealed a significant increase in newly discovered ransomware families from 29 to 247 – that’s an astounding jump of 752%.

The stats show just how popular this get-rich-quick scheme is among the black hat community, netting cybercriminals in the region of $1 billion last year.

As more and more organizations decided to go against the advice of security experts and the police and pay up, so more hackers became aware of the massive gains to be made from such attacks.

According to Trend Micro, many variants were crafted to encrypt specific file types essential to business operations, such as tax return files, server files, and virtual desktop images.

Ransomware was not the only major threat to hit in 2016. The report also claimed that BEC attacks cost victim organisations on average $140,000. With these kinds of sums involved it’s no surprise that increasing numbers of cybercriminals are expected to put their efforts into these scams this year.

Unsurprisingly the US bore the brunt of global CEO fraud, comprising 38% of attacks in 2016. But the UK (10%) was second – well above a long tail of other countries including Hong Kong and Japan (both 3%), India, France, Norway, Brazil and Australia (all 2%).

To add to organizations’ woes, Trend Micro and the Zero Day Initiative discovered a record 765 vulnerabilities in 2016 – including 60 zero days.

The number of Microsoft bugs dropped by 47%, but the number discovered in Apple products jumped 133% – a reflection of the increasingly mobile world we live in.

The two most affected products overall were Adobe Acrobat Reader DC (89 bugs) and Advantech’s WebAccess SCADA software (109).

The figures highlight the importance of prompt patching – especially for flaws being actively exploited in the wild.

Simon Edwards, Trend Micro's European cyber security architect, argued that firms should take a blended approach to security featuring multiple controls.

“So, use signature based systems to detect the known, because they are very fast. Use machine learning, application control, IPS and behavioural monitoring to detect the unknown knowns; and finally use sandboxing to find the really unknown,” he told Infosecurity.

“This is nothing new as the concept of defence in depth has been around for years. The important thing is to ensure that all of these techniques integrate and share information with each other – and provide their findings in an easy-to-use format for the analyst.”
 

vemn

Level 6
Verified
Malware Hunter
Well-known
Feb 11, 2017
264
There's once when my friend told me his company's daily incoming email is around 12 million, but only less than 1% arrived at the exchange...the rest are spams/phishing...zzz

Good thing we have security vendors still able to keep up with this tons of spams at the gateway...
 
  • Like
Reactions: Daniel Hidalgo

larry goes to church

Level 3
Verified
Mar 10, 2017
103
There's once when my friend told me his company's daily incoming email is around 12 million, but only less than 1% arrived at the exchange...the rest are spams/phishing...zzz

Good thing we have security vendors still able to keep up with this tons of spams at the gateway...

From my experience in with my company only 22% monthly are legitimate emails. This is in the Manufacturing sector.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top