DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Half of Malware Detections for SMBs Are Keyloggers, Spyware and Stealers

DigitalCIO Bureau by DigitalCIO Bureau
March 16, 2024
in Tech News
0
CEOs Lack Confidence in Their Organisations’ Ability to Protect Against Cyberattacks: Accenture
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Sophos has released its annual 2024 Sophos Threat Report, with this year’s report detailing “Cybercrime on Main Street” and the biggest threats facing small- and medium-sized businesses (SMBs). According to the report, in 2023, nearly 50% of malware detections for SMBs were keyloggers, spyware and stealers, malware that attackers use to steal data and credentials. Attackers subsequently use this stolen information to gain unauthorized remote access, extort victims, deploy ransomware, and more.

The Sophos report also analyses initial access brokers (IABs)—criminals who specialize in breaking into computer networks. As seen in the report, IABs are using the dark web to advertise their ability and services to break specifically into SMB networks or sell ready-to-go-access to SMBs they’ve already cracked.

“The value of ‘data’ as currency has increased exponentially among cybercriminals, and this is particularly true for SMBs, which tend to use one service or software application, per function, for their entire operation. For example, let’s say attackers deploy an infostealer on their target’s network to steal credentials and then get hold of the password for the company’s accounting software. Attackers could then gain access to the targeted company’s financials and have the ability to funnel funds into their own accounts,” said Christopher Budd, director of Sophos X-Ops research at Sophos. “There’s a reason that more than 90% of all cyberattacks reported to Sophos in 2023 involved data or credential theft, whether through ransomware attacks, data extortion, unauthorized remote access, or simply data theft.”

Ransomware Still the Biggest Cyberthreat to SMBs

While the number of ransomware attacks against SMBs has stabilized, it continues to be the biggest cyberthreat to SMBs. Out of the SMB cases handled by Sophos Incident Response (IR), which helps organizations under active attack, LockBit was the top ransomware gang wreaking havoc. Akira and BlackCat were second and third, respectively. SMBs studied in the report also faced attacks by lingering older and lesser-known ransomware, such as BitLocker and Crytox.

Ransomware operators continue to change ransomware tactics, according to the report. This includes leveraging remote encryption and targeting managed service providers (MSPs). Between 2022 and 2023, the number of ransomware attacks that involved remote encryption—when attackers use an unmanaged device on organizations’ networks to encrypt files on other systems in the network—increased by 62%.

In addition, this past year, Sophos’s Managed Detection and Response (MDR) team responded to five cases involving small businesses that were attacked through an exploit in their MSPs’ remote monitoring and management (RMM) software.

Attackers Sharpen Their Social Engineering and Business Email Compromise (BEC) Attacks

Following ransomware, business email compromise (BEC) attacks were the second highest type of attacks that Sophos IR handled in 2023, according to the Sophos report.

These BEC attacks and other social engineering campaigns contain an increasing level of sophistication. Rather than simply sending an email with a malicious attachment, attackers are now more likely to engage with their targets by sending a series of conversational emails back and forth or even calling them.

In an attempt to evade detection by traditional spam prevention tools, attackers are now experimenting with new formats for their malicious content, embedding images that contain the malicious code or sending malicious attachments in OneNote or archive formats. In one case Sophos investigated, the attackers sent a PDF document with a blurry, unreadable thumbnail of an “invoice.” The download button contained a link to a malicious website.

Tags: Sophos
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Hexaware and Abluva Offer Secure Agentic AI Solutions for Life Sciences Industry

by DigitalCIO Bureau
July 11, 2025
0
Deloitte And AWS To Deepen Generative AI Driven Innovations For Indian Enterprises

Hexaware Technologies has announced a strategic partnership with Abluva, an innovator in agentic AI security, to address security challenges posed by autonomous AI agents in the Life Sciences...

Read moreDetails

TP-Link Reinforces Commitment to India with new R&D GCC & Incubation Centre

by DigitalCIO Bureau
July 11, 2025
0
TP-Link Reinforces Commitment to India with new R&D GCC & Incubation Centre

Connectivity solutions provider TP-Link India have announced a significant expansion of its footprint in the country. TP-Link has unveiled its first incubation centre in India, co-located with its...

Read moreDetails

Gartner: Earth Intelligence Offers $20 bn Opportunity For Tech And Service Providers

by DigitalCIO Bureau
July 10, 2025
0

Earth intelligence will significantly impact every industry as it rapidly moves from government to the private sector, with annual revenue to surpass $4.2 billion in 2030, up from...

Read moreDetails

Okaya Power Group Appoints Prakash Dharmani as CIO

by DigitalCIO Bureau
July 9, 2025
0
Okaya Power Group Appoints Prakash Dharmani as CIO

Prakash Dharmani has joined Okaya Power Group as its new Chief Information Officer (CIO). With over 33 years of experience across industries such as petrochemicals, refining, specialty packaging,...

Read moreDetails

Total Unique Malware Increases By 171%: WatchGuard

by DigitalCIO Bureau
July 9, 2025
0
OpenText Names LockBit  Nastiest Malware Of 2024

New WatchGuard research reveals 171% increase in total unique malware as attackers defy traditional defenses. Other key findings show an increase in email-borne malware threats, a rise in...

Read moreDetails
Next Post
LockBit Ransomware Hacker Sentenced to Prison in Canada

LockBit Ransomware Hacker Sentenced to Prison in Canada

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Lam Research breaks ground on cutting-edge systems lab in Bengaluru

Lam Research breaks ground on cutting-edge systems lab in Bengaluru

September 10, 2024

astTECS announces appointment of Binish as Director – Sales

April 8, 2019
Gartner: 15 Million Electric Cars Will Be Shipped in 2023

Gartner: 15 Million Electric Cars Will Be Shipped in 2023

September 8, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Dell Technologies Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud HCLTech IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope NTT DATA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos Tenable Trend Micro Veeam Veeam Software Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?