Firewall News

Top Menu

  • Home
  • Our Blog
  • Contact Us

Main Menu

  • Software Updates
  • Alerts & Bugs
  • Out of the Box
  • Home
  • Our Blog
  • Contact Us

Firewall News

Firewall News

  • Software Updates
    • WatchGuard logo

      TDR 6.0.0 is now integrated into WatchGuard Cloud

      04/01/2021
      0
    • Sophos Logo

      XG Firewall 17.5 MR14 Released

      30/07/2020
      0
    • Sophos Logo

      Sophos Firewall Manager SFM 17.1 MR4 Released

      27/07/2020
      0
    • Sophos Logo

      Sophos Enterprise console - Endpoint Security and Control v10.8.9 for Windows has ...

      16/07/2020
      0
    • Sophos Logo

      Sophos iView v3 MR-2 Released

      07/07/2020
      0
    • Sophos Logo

      SD-RED Firmware 3.0.002 Pattern Update

      06/07/2020
      0
    • Sophos Logo

      XG Firewall 17.5 MR13 Released

      06/07/2020
      0
    • Sophos Logo

      End-of-Life (EoL) announcement for old firmware v17 and v17.1 for XG Firewall

      03/07/2020
      0
    • WatchGuard logo

      Fireware 12.5.4 Now Available

      01/07/2020
      0
  • Alerts & Bugs
    • Sophos Logo

      Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

      29/03/2022
      0
    • Sophos Logo

      Sophos: Important Product Lifecycle Updates

      03/03/2022
      0
    • WatchGuard logo

      WatchGuard Support Alert

      23/02/2022
      0
    • Sophos Logo

      Sophos: Important Product Lifecycle Reminder

      03/02/2022
      0
    • Sophos Logo

      Sophos: Product Lifecycle Information: Extended Support for Windows 7 and Windows Server ...

      31/01/2022
      0
    • Sophos Logo

      End-of-Life (EoL) announcement for Sophos SSL VPN Client

      29/11/2021
      0
    • WatchGuard logo

      WatchGuard: macOS Monterey 12.0.1 Does Not Support the AuthPoint Logon App

      09/11/2021
      0
    • Sophos Logo

      Sophos UTM Manager (SUM) End of Distribution

      04/11/2021
      0
    • WatchGuard logo

      WatchGuard: End of Sale Notice: AP420

      01/11/2021
      0
  • Out of the Box
    • WatchGuard’s Firebox T80 Earns 5-Star Rating in SC Labs Review

      17/11/2020
      0
    • WatchGuard Wins Big in CRN 2020 Tech Innovator Awards

      16/11/2020
      0
    • Coronavirus scams: what to look for and how to stop them

      02/04/2020
      0
    • Dell SonicWALL TZ 300

      Out the Box - Dell SonicWALL TZ 300

      05/07/2016
      0
    • Dell SonicWALL TZ SOHO

      Out the Box - Dell SonicWALL TZ SOHO

      05/07/2016
      0
    • WatchGuard Firebox T50

      WatchGuard Firebox T50

      31/03/2016
      0
    • WatchGuard Firebox M200

      WatchGuard Firebox M200

      31/03/2016
      0
NewsWatchGuard
Home›News›WatchGuard’s Q2 Internet Security Report Finds Malware Hiding on Popular Content Delivery Networks

WatchGuard’s Q2 Internet Security Report Finds Malware Hiding on Popular Content Delivery Networks

By admin
25/09/2019
1352
0
Share:
WatchGuard logo

Data also shows Kali Linux modules cracking malware top ten list and a dramatic year-over-year increase in overall malware volume

SEATTLE – Sept 25, 2019 – WatchGuard® Technologies, a global leader in network security and intelligence, secure Wi-Fi and multi-factor authentication, today announced the release of its quarterly Internet Security Report for Q2 2019. For the first time, the report reveals and ranks the most common domains attackers use to host malware and launch phishing attacks – including several subdomains of legitimate sites and Content Delivery Networks (CDNs) such as CloudFlare.net, SharePoint and Amazonaws.com. It also highlights that modules from the popular Kali Linux penetration testing tool made the top ten malware list for the first time, year-over-year malware volume increased by 64%, and more.

“This edition of the Internet Security Report exposes the gritty details of the methods hackers use to sneak malware or phishing emails onto networks by hiding them on legitimate content-hosting domains,” said Corey Nachreiner, chief technology officer at WatchGuard Technologies. “Luckily there are several ways to defend against this, including DNS-level filtering to block connections to known malicious websites, advanced anti-malware services, multi-factor authentication to prevent attacks leveraging compromised credentials, and training to help employees recognize phishing emails. No one defense will prevent every attack, so the best way for organizations to protect themselves is with a unified security platform that offers multiple layered security services.”

WatchGuard’s Internet Security Report provides real-world data on top security threats, as well as detailed analysis of major security incidents and best practices to help organizations of all sizes protect their business and their customers’ data. Key findings from the Q2 2019 report include:

  • Malware and phishing attacks abusing legitimate domains – WatchGuard’s DNSWatch service intercepts connections intended for known malicious domains at the DNS level and redirects them. By tracking the most common malicious domains blocked by DNSWatch, WatchGuard can identify the top domains hosting malware and  phishing attacks. Of note, several of these domains are subdomains of legitimate CDNs like CloudFront.net (which belongs to Amazon) and legitimate file-sharing websites like my[.]mixtape[.]moe. While this attack method isn’t new, WatchGuard’s research sheds light on the specific domains used in these attacks.  
  • Kali Linux makes its debut on the top ten malware list – For the first time ever, two modules from the popular hacking operating system Kali Linux appear on WatchGuard’s list of most common malware. Trojan.GenericKD, which covers a family of malware that creates a backdoor to a command-and-control server, and Backdoor.Small.DT, a web shell script used to create backdoors on web servers, were numbers six and seven on the list. This could indicate either growing adoption among malicious actors or more penetration testing by white hat hackers using Kali Linux.
  • Significant year-over-year increase in overall malware volume – Across the board, the total volume of malware hitting WatchGuard Fireboxes is up significantly compared to last year. Two of WatchGuard’s three malware detection services saw increased malware in Q2 2019 than Q2 2018; one blocked 58% more and the other blocked 68% more, for an overall year-over-year increase of 64%.
  • Widespread phishing and Office exploit malware increases – Two pieces of malware (a phishing attack that threatens to release fake compromising information on the victim, and a Microsoft Office exploit) that appeared on the most widespread malware list in Q1 2019 and Q4 2018 have graduated to the top ten list by volume. This illustrates that these campaigns are on the rise and are sending a high volume of attacks at a wide range of targets. Users should update Office regularly and invest in anti-phishing and DNS filtering security solutions.
  • SQL injection dominates network attacks – SQL injection attacks made up 34% of all network attacks detected in Q2 2019 and have increased significantly in volume year-over-year (one specific attack increased over 29,000% from Q2 2018 to Q2 2019). Anyone who maintains a SQL database, or a web server with access to one, should patch systems regularly and invest in a web application firewall.
  • Malware increasingly targets Europe and APAC – In Q2 2019, nearly 37% of malware targeted the EMEA region, with several individual attacks focusing on the UK, Italy, Germany, and Mauritius. APAC came in second, targeted by 36% of overall malware attacks. The Razy and Trojan.Phishing.MH malware variants in particular primarily targeted the APAC region, with 11% of Trojan.Phishing.MH detections found in Japan.

WatchGuard’s Internet Security Report is based on anonymized Firebox Feed data from a subset of active WatchGuard UTM appliances whose owners have opted in to share data to support the Threat Lab’s research efforts. Today, 41,229 appliances throughout the world contribute to the Internet Security Report data pool. In total, those appliances blocked more than 22,619,836 malware variants, at a rate of 549 samples per device. Additionally, those Firebox appliances prevented 2,265,425 network attacks (60 per device), a significant increase from Q1 2019 that runs counter to past trends in network attack volume.

The complete report includes more detailed statistics on the most impactful malware and network attack trends from Q2 2019, an analysis of the RobbinHood ransomware attack that paralyzed the city of Baltimore in May 2019 (and cost approximately $17 million in total damages), and advice and best practices that readers can use to better protect themselves and their organizations.

Analysis of MSP Sodinokibi Ransomware Attacks

The report also contains a detailed analysis of the actual malware used in the Sodinokibi MSP ransomware attacks. The WatchGuard Threat Lab’s research shows that the attackers leveraged weak, stolen, or leaked credentials to gain administrative access to legitimate management tools that these MSPs used to monitor and manage their clients’ networks, then used these tools to disable security controls and stage and deliver the Sodinokibi ransomware via PowerShell.

For more information, download the full report here.

Previous Article

Barracuda named a September 2019 Gartner Peer ...

Next Article

Barracuda Forensics and Incident Response now generally ...

0
Shares
  • 0
  • +
  • 0
  • 0
  • 0
  • 0

Related articles More from author

  • Sophos CRN ARC 2018
    News

    Sophos gets top marks in CRN’s 2018 Annual Report Card

    24/08/2018
    By admin
  • BarracudaNews

    Barracuda rated one of the best in the business in 2019 CRN Vendor Report

    25/10/2019
    By admin
  • Fortinet Predictions Update
    FortinetNews

    Fortinet Ranked in Top Three by Gartner for SD-WAN Equipment Market Share by Revenue

    01/10/2019
    By admin
  • FortinetNews

    Fortinet Fortifies Firewall, SD-WAN Capabilities

    01/11/2019
    By admin
  • Fortinet FortiSandbox2000E
    News

    FortiSandbox 2000E Earns Coveted NSS Recommended in Latest Breach Detection System Public Test

    01/11/2017
    By admin
  • SonicWall Press Release
    FortinetNews

    Fortinet’s Longstanding History of AI-driven Security

    24/02/2020
    By admin

  • Sophos Logo
    Alerts & BugsSophos

    XG Firewall Vulnerability Notification

  • Alerts & BugsTrendMicro

    Trend Micro: TMRM Scheduled Maintenance for Database Upgrade

  • WatchGuard logo
    NewsWatchGuard

    WatchGuard Releases a Full Endpoint Security Platform

Timeline

  • 29/03/2022

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

  • 03/03/2022

    Sophos: Important Product Lifecycle Updates

  • 01/03/2022

    Shoring up your cybersecurity posture in light of ongoing crisis

  • 23/02/2022

    WatchGuard Support Alert

  • 03/02/2022

    Sophos: Important Product Lifecycle Reminder

Sponsored Links

Latest Comments

  • Paul Sillars
    on
    21/06/2016
    I received this in an email this morning, it was the first I heard about it ...

    Dell Software Group sold to help fund looming EMC deal

  • Paul Sillars
    on
    20/06/2016
    This is going to be an interesting one to watch. Especially after today's announcement that ...

    Ingram Micro gets distribution access to Dell’s security range in Australia

Find us on Facebook

Firewall.News Logo

This site serves more as a reference point for some of the major security vendor's updates and product/press releases

It will never be a definitive list, but it helps our customers keep up to date and also allows us to express our comment and observations as well.

About us

  • PO Box 451, North Lakes, Queensland, 4509, Australia
  • [email protected]
  • Recent

  • Popular

  • Comments

  • Sophos Logo

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

    By admin
    29/03/2022
  • Sophos Logo

    Sophos: Important Product Lifecycle Updates

    By admin
    03/03/2022
  • Shoring up your cybersecurity posture in light of ongoing crisis

    By admin
    01/03/2022
  • WatchGuard logo

    WatchGuard Support Alert

    By admin
    23/02/2022
  • Dell SonicWALL Supermassive

    Ingram Micro gets distribution access to Dell’s security range in Australia

    By admin
    14/06/2016
  • Francisco Partners and Elliott Management to Acquire the Dell Software Group

    Dell Software Group sold to help fund looming EMC deal

    By admin
    21/06/2016
  • WatchGuard Firebox M500 – The Cure for HTTPS Performance Headaches

    By admin
    05/03/2015
  • Sophos Logo

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

    By admin
    29/03/2022
  • Paul Sillars
    on
    21/06/2016

    Dell Software Group sold to help fund looming EMC deal

    I received this in ...
  • Paul Sillars
    on
    20/06/2016

    Ingram Micro gets distribution access to Dell’s security range in Australia

    This is going to ...

Follow Me

  • Contact
  • About Us
  • Home