DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Netskope Threat Labs: IoT botnets and infostealers target retail sector

DigitalCIO Bureau by DigitalCIO Bureau
April 5, 2024
in Tech News
0
Inspira Enterprise joins Nozomi Networks’ MSSP Elite Partners’ League
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Netskope Threat Labs has published its latest research report, focused on cloud threats in the retail sector. The report finds that IoT botnets, remote access tools and infostealers were the key malware families deployed by attackers targeting retail in the past year. Retail has also undergone a shift over the past year from predominantly Google Cloud-based applications towards Microsoft apps like Outlook.

Key findings include:

  • Attackers using infostealers to target retail: Infostealers are a prominent malware family for the retail sector as attackers attempt to steal valuable data such as payment details from organisations and customers.
    Infostealers also feed into the wider cybercrime ecosystem with attackers selling harvested credentials and personal financial details.
  • Botnets and trojans targeting network devices: The Mirai botnet family has increasingly been seen to target exposed networking devices running Linux such as routers, cameras, and other IoT devices in the retail environment
    – IoT devices are often overlooked as a security risk, but can be effective in providing visual or sensor information that can assist in cybercrime, or even abused to launch DDoS attacks against other targets.
    – Similarly, remote access trojans (RAT) were popular as they allow access to browsers and remote cameras, sending information to attackers or receiving commands.
    – Since the leak of Mirai malware’s source code, the number of variants of this malware has increased considerably and poses a risk to retail as a sector with multiple vulnerable endpoints.
  • Microsoft Suite increasingly a target: In last year’s report, Google applications were far more popular in the retail sector than in other industries, but over the past year the researchers have seen a resurgence of Microsoft’s popularity. This is particularly evident for storage with the gap between OneDrive and Google Drive widening over the past year, with the average percentage of users shifting from 43% to 51% for OneDrive and falling from 34% to 23% for Google Drive. We see similar trends with Outlook (21%) supplanting Gmail (13%) as the most popular email app.
    – Microsoft OneDrive remains the most popular cloud application for malware delivery across all sectors including retail. Attackers gravitate towards tactics that capitalise on users’ trust and familiarity with OneDrive, increasing the likelihood they will click on the links and download the malware.
    – In retail, attacks via Outlook are more successful than in other sectors – retail sees twice as many malware downloads via Outlook (10%) as other industry averages (5%).
  • WhatsApp’s popularity in retail: The app was three times as popular in retail (14%) than other industries (5.8%) both for average usage and downloads. However, WhatsApp was not listed among the current top apps for malware downloads. This may change as threat actors start to see its popularity justifying the economic case to direct more attacks via the app.
    Social media applications like X (12%), Facebook (10%) and Instagram (1.5% for uploads) were all more popular in retail than other industry averages.

Speaking on the findings, Paolo Passeri, Cyber Intelligence Principal at Netskope said, “It’s surprising that the retail sector still finds itself specifically targeted with botnets like Mirai as attackers look to compromise vulnerable or misconfigured IoT devices across retail locations and abuse them to dramatically amplify the effect of a Distributed Denial of Service (DDoS) attack. Mirai is not a particularly recent threat, and since its discovery in 2016, there are now multiple variants used today. The fact that attackers continue to use it to target IoT devices shows that too many organisations continue to dangerously overlook the security posture of their internet-connected devices. This poses a significant risk not only for the targets of the attacks launched from the IoT botnet but also for the organisation whose IoT devices are enslaved into the botnet, since their exploitation can easily lead to outages that impact the functioning of the business.”

“This vulnerability, coupled with the use of infostealers and remote access malware to extract credentials and customer financial data makes the retail sector a potentially lucrative target.”

“I was particularly interested to see that Qakbot is among the top threats for retailers, even though this operation was taken down by the FBI at the end of August 2023. Its infrastructure has been quickly refitted by the attackers to distribute additional malware payloads, providing additional opportunities for the attackers; and some isolated Qakbot campaigns have been detected even after its disruption.

“The fact that botnets like Mirai and infostealers like Quakbot continue to be among the top methods attackers use to target retail organisations shows security leaders still have much to do to fortify their infrastructure and endpoints. Fortunately, following fundamental cyber hygiene best practices like inspecting web and cloud traffic and ensuring you can block malicious traffic and isolate compromised endpoints or domains will reduce the risk that you fall victim to these attackers.”

Netskope Threat Labs recommends enterprises in the retail sector review their security posture and make several recommendations for best practices to counter these threats:

  • Inspect all HTTP and HTTPS downloads, including all web and cloud traffic, to prevent malware from infiltrating your network.
  • Ensure that high-risk file types like executables and archives are thoroughly inspected using a combination of static and dynamic analysis before being downloaded.
  • Configure policies to block downloads and uploads from apps and instances that are not used in your organisation to reduce your risk surface to only those apps and instances that are necessary for the business and minimise the risk of accidental or deliberate data exposure from insiders or abuse by attackers.
  • Use an Intrusion Prevention System (IPS) that can identify and block malicious traffic patterns, such as command and control traffic associated with popular malware.
  • Blocking this type of communication can prevent further damage by limiting the attacker’s ability to perform additional actions.
  • Use Remote Browser Isolation (RBI) technology to provide additional protection when there is a need to visit websites that fall into categories that can present higher risk, like newly observed and newly registered domains.

The report is based on anonymised usage data collected about a retail sector subset of Netskope’s 2,500+ customers, all of whom give prior authorisation for their data to be analysed in this manner.

Tags: Netskope Threat Labs
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Accenture Names Pradeep Prabhala to Head India Market Unit

by DigitalCIO Bureau
July 22, 2026
0
Accenture Names Pradeep Prabhala to Head India Market Unit

Accenture has announced the appointment of Pradeep Prabhala as the new lead for its India Market Unit, effective September 1, 2026. In his new role, Prabhala will oversee...

Read moreDetails

Microsoft and Mistral deepen their strategic partnership to deliver enterprises and regulated industries frontier AI they can control

by DigitalCIO Bureau
July 22, 2026
0
Microsoft and Mistral deepen their strategic partnership to deliver enterprises and regulated industries frontier AI they can control

Microsoft and Mistral announced a significant expansion of their strategic partnership to help enterprises and regulated industries adopt frontier AI with greater choice, control and operational consistency. The...

Read moreDetails

HCLTech recognized as a Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer for Outsourced Digital Workplace Services

by DigitalCIO Bureau
July 21, 2026
0
HCLTech recognized as a Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer for Outsourced Digital Workplace Services

HCLTech announced it has been named a Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer report for Outsourced Digital Workplace Services, marking the third...

Read moreDetails

Microsoft to Deploy Next-Generation AMD Instinct and EPYC Processors in Expanded Long-Term Partnership with AMD

by DigitalCIO Bureau
July 21, 2026
0
Microsoft to Deploy Next-Generation AMD Instinct and EPYC Processors in Expanded Long-Term Partnership with AMD

AMD announced an expanded strategic partnership with Microsoft spanning GPUs, CPUs, networking, and software on Microsoft Azure. As part of the deal, Microsoft will deploy the AMD Helios...

Read moreDetails

Intel and Google Cloud Partner to Fast-Track Intel’s AI-Driven Enterprise Transformation

by DigitalCIO Bureau
July 20, 2026
0
Intel and Google Cloud Partner to Fast-Track Intel’s AI-Driven Enterprise Transformation

Collaboration leverages Gemini Enterprise and Google Cloud to expand Intel’s AI workforce capabilities via scalable agentic workflows across core business functions Intel and Google Cloud have expanded their...

Read moreDetails
Next Post
Cloudflare Launches Unified Data Protection Suite

Cloudflare Powers One-Click-Simple Global Deployment For AI Applications With Hugging Face

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

VTEX Partners with Vinculum to Elevate Customer Experience in India

Qualcomm and MapmyIndia to accelerate ‘Make in India’ solutions for automotive

January 17, 2025
Infosys Recognized as a Leader in Inaugural AI Technical Services, Q4 2025 Analyst Report

Infosys Recognized as a Leader in Inaugural AI Technical Services, Q4 2025 Analyst Report

March 26, 2026
World’s largest tech & Start-up show GITEX GLOBAL,North Star 2023 Focus on Booming AI Economy

World’s largest tech & Start-up show GITEX GLOBAL,North Star 2023 Focus on Booming AI Economy

October 12, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Collaboration CrowdStrike Cybersecurity Digital Transformation E-books Enterprises Fortinet Gartner Generative AI Google Cloud HCLTech IBM India Infographics Infosys Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Partnership Sophos Strategic Partnership Tata Consultancy Services TCS Tenable Trend Micro Veeam Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?