2020年恶意软件状况报告(英文版)_57页_5mb
报告摘要
2020 State of Malware Report Summary
Core Content
The 2020 State of Malware Report by Malwarebytes provides an in-depth analysis of the global malware landscape in 2019, highlighting trends, threat categories, and family-specific insights across different platforms and regions. It also includes predictions for the cybersecurity environment in 2020 and discusses the growing emphasis on data privacy following the implementation of GDPR and other regulatory actions.
Main Points
Overall Threat Trends
- Global Windows malware detections increased by 13% on business endpoints in 2019, while consumer detections decreased by 2%.
- Adware remained the most prevalent threat category across Windows, Mac, and Android, with a notable increase in detections.
- Macs outpaced Windows PCs in the number of threats detected per endpoint for the first time ever in 2019.
- Ransomware activity slightly declined, but the families involved (e.g., Ryuk, Sodinokibi) were more advanced and impactful.
- Hack tools increased significantly, indicating a shift in how cybercriminals are targeting systems.
Threat Categories by Platform
Windows
- Adware was the top threat category with a 463% increase in detections.
- Trojan activity decreased by 25%, though it still ranked second.
- RiskwareTool (primarily cryptominers) saw a 52% increase in business detections.
- Backdoor malware increased by 14%, and Hijacker dropped by 79%.
- Ransomware declined by 6%, but the threat families were more sophisticated.
Mac
- Adware dominated, with NewTab being the top threat family, responsible for 28 million detections.
- Mac threat volume increased by over 400% from 2018, driven by both growing userbase and actual threat growth.
- Adware was the top threat category for Mac users, surpassing other categories in terms of volume.
Android
- Pre-installed malware and adware increased, with a focus on stealing data or attention.
- Adware remained a major threat, with families like MindSpark and InstallCore seeing massive growth.
Web Threats
- Web skimmers (like MageCart) were at an all-time high, targeting payment processor sites.
- Malvertising and redirection campaigns remained active, leveraging browser vulnerabilities.
- Exploit kits and compromised infrastructure continued to be used for large-scale attacks.
- Browser developers' reliance on Chromium raised concerns about future exploit development.
Regional Threats
- North America (NORAM) accounted for 48% of all detections.
- EMEA had 26%, but saw a 2% decline in overall threats.
- LATAM had the highest growth, with an increase of 26%.
- APAC had 12% of detections, with a 11% decline (except for Australia, New Zealand, and Singapore).
Industry Threats
- Services, retail, and education were the most targeted industries.
- Emotet and TrickBot were the top threats for businesses, with TrickBot increasing by 52%.
- Ransomware families like Ryuk, Sodinokibi, and Phobos caused significant disruptions in 2019.
Data Privacy in 2019
- GDPR and related legislation led to increased data privacy awareness and regulation.
- New laws in the U.S. (Maine, Nevada, California) may influence future federal policies.
- Tech companies like Apple and Mozilla introduced privacy-focused features, while others (Google, Amazon, Facebook) faced privacy scandals.
- User data remains a valuable asset for cybercriminals, despite privacy efforts.
Key Threat Families
- Adware.MindSpark and Adware.InstallCore saw 497% and 367% increases, respectively.
- Adware.SearchEncrypt had an astounding 1730% increase, becoming one of the most active adware families.
- Trojan.Emotet increased by 375%, with a focus on business targets and acting as a secondary payload.
- Trojan.TrickBot increased by 52%, with a new spam module and lateral movement capabilities.
- Adware.Yontoo became the top business threat, increasing by over 6000%.
- Trojan.BrowserAssistant.PowerShell emerged as a new and dangerous threat, with over 100,000 instances.
- Backdoor.Qbot increased by 465%, evolving from a banking Trojan to a more sophisticated threat.
Cybersecurity Predictions for 2020
- The report predicts continued growth in adware and increased sophistication in malware attacks.
- Data privacy will remain a top concern, with more regulations and public scrutiny expected.
- Threat actors will likely continue to target businesses, leveraging advanced techniques and tools.
Conclusion
The 2019 malware landscape was marked by increased sophistication, targeted attacks, and a shift in focus from consumer to business endpoints. Adware and ransomware families like Emotet, TrickBot, Ryuk, and Sodinokibi were particularly active, and the rise of stalkerware and web skimmers highlighted new attack vectors. As the year came to a close, the cybersecurity community was left to reflect on the growing threat of data privacy breaches and the evolving tactics of cybercriminals.
试读结束,高清完整版pdf/doc/ppt,请点下载