Report: Ransomware Attacks Up 627%

According to the latest Internet Security Report from data security provider WatchGuard, ransomware at the endpoint level has surged 627% — despite an observed decrease at the network level of detected malware last quarter. What's the explanation?

Some 93% of malware is hiding behind encryption, WatchGuard said, and about 80% of the company's customers have not enabled https decryption in their firewalls, so the malware is going largely undetected until it reaches endpoints, where detections increased 22% overall.

"We continue to warn that most malware hides in the SSL/TLS encryption used by secured websites. Q4 continues that trend with a rise from 82% to 93%. If you don’t inspect this traffic, you are missing most malware — at least with your network security controls (endpoint security does still have a chance to catch it)."

The Internet Security Report is based on anonymized data collected from WatchGuard's Firebox appliances around the world. According to Watchguard: "Customer Fireboxes send a flurry of malware detections to our threat intelligence database, keeping us apprised of the latest trends. Network administrators who manage these Fireboxes have graciously allowed their devices to provide these anonymized detection reports to us. We analyze their details to understand what the malware landscape looked like last quarter and to investigate any trends or irregularities. With the data from this report, and previous ones, we can sometimes forecast what future malware trends might look like. We also make some conclusions and offer takeaways on defending against the current and future malware landscape."

The report also noted that overall network attacks were flat in the fourth quarter of 2022 compared with the previous quarter.

Among the other findings and recommendations:

  • Network-level detections of malware were down 9.2% for the quarter, despite endpoint detections being up. Recommendation: Inspect SSL/TLS traffic from secure websites before it reaches the endpoint.

  • Phishing attacks have increased. "Phishing and business email compromise (BEC) remains one of the top attack vectors, so make sure you have both the right preventative defenses and security awareness training programs to defend against it."

  • Lockbit continues to be a leading malware group for ransomware. "We continue to see Lockbit variants often, and they are definitely the group that seems to have the most success breaching companies (through their affiliates) with ransomware."

  • ProxyLogin exploits are growing. According to the report: "An exploit for this well-known, critical Exchange issue rose from eighth place in Q3 to fourth place last quarter. It should be long patched, but if not, you should know attackers are targeting it."

The complete report, including an executive summary and further details and analysis of findings from the quarter, is freely available on WatchGuard's site.

About the Author

David Nagel is the former editorial director of 1105 Media's Education Group and editor-in-chief of THE Journal, STEAM Universe, and Spaces4Learning. A 30-year publishing veteran, Nagel has led or contributed to dozens of technology, art, marketing, media, and business publications.

He can be reached at [email protected]. You can also connect with him on LinkedIn at https://www.linkedin.com/in/davidrnagel/ .


Featured

  • college students in a classroom focus on a silver laptop, with a neural network diagram on the monitor in the background

    Report: 93% of Students Believe Gen AI Training Belongs in Degree Programs

    The vast majority of today's college students — 93% — believe generative AI training should be included in degree programs, according to a recent Coursera report. What's more, 86% of students consider gen AI the most crucial technical skill for career preparation, prioritizing it above in-demand skills such as data strategy and software development.

  • laptop with a neural network image, surrounded by books, notebooks, a magnifying glass, a pencil cup, and a desk lamp

    D2L Lumi AI Updates Add Personalized Study Supports

    Learning platform D2L has announced new artificial intelligence features for D2L Lumi that help provide more personalized study supports for students.

  • three glowing stacks of tech-themed icons

    Research: LLMs Need a Translation Layer to Launch Complex Cyber Attacks

    While large language models have been touted for their potential in cybersecurity, they are still far from executing real-world cyber attacks — unless given help from a new kind of abstraction layer, according to researchers at Carnegie Mellon University and Anthropic.

  • young man in a denim jacket scans his phone at a card reader outside a modern glass building

    Colleges Roll Out Mobile Credential Technology

    Allegion US has announced a partnership with Florida Institute of Technology (FIT) and Denison College, in conjunction with Transact + CBORD, to install mobile credential technologies campuswide. Implementing Mobile Student ID into Apple Wallet and Google Wallet will allow students access to campus facilities, amenities, and residence halls using just their phones.