Netskope: Attackers Double Down On Social Engineering Techniques & Malicious Functionalities Leading To Sharp Increase In Malware Downloads

- Advertisement -

Netskope, a leader in Secure Access Service Edge (SASE), today unveiled new research confirming that attackers are finding new ways to evade detection and blend in with normal network traffic using HTTP and HTTPS to deliver malware. In its latest Cloud & Threat Report: Global Cloud and Web Malware Trends, Netskope identified that on average, five out of every 1,000 enterprise users attempted to download malware in Q1 2023, and new malware families and variants represented 72% of those malware downloads. 

Social Engineering and Search Engine Data Voids on the Rise

In the research, Netskope uncovered that nearly 10% of all malware downloads in Q1 were referred from search engines. These downloads mostly resulted from weaponized data voids, or combinations of search terms that have very few results, which means that any content matching those terms is likely to appear very high in the search results. This represents just one of many social engineering techniques that attackers are accelerating.

- Advertisement -

Social engineering as a whole continues to dominate as a leading malware infiltration technique with attackers abusing not only search engines, but email, collaboration apps, and chat apps to trick their victims. As the top two malware types, Trojans accounted for 60% of malware downloads in Q1 and phishing downloads accounted for 13%.

Evaluation of Primary Communication Channels for Attackers 

For the first time in its quarterly cloud and threat reporting, Netskope analyzed attacker communication channels. Researchers found that attackers, in order to consistently evade detection, have used HTTP and HTTPS over ports 80 and 443 as their primary communication channel. In fact, of the new malware executables analyzed by Netskope that communicated with external hosts, 85% did so over port 80 (HTTP) and 67% did so over port 443 (HTTPS). This approach enables attackers to easily go unnoticed and blend in with the abundance of HTTP and HTTPS traffic already on the network. 

Additionally, to evade DNS-based security controls, some malware samples sidestep DNS lookups, instead reaching out directly to remote hosts using their IP addresses. In Q1 2023, most malware samples that initiated external communications did so using a combination of IP addresses and hostnames, with 61% communicating directly with at least one IP address and 91% communicating with at least one host via a DNS lookup.

“Job number one for attackers is finding new ways to cover their tracks as enterprises put more resources into threat detection, but these findings indicate just how easy it still is for attackers to do so in plain sight,” said Ray Canzanese, Threat Research Director, Netskope Threat Labs. “As attackers gravitate towards cloud services that are widely used in the enterprise and leverage popular channels to communicate, cross-functional risk mitigation is more necessary than ever.” 

Extended Look into Global Cloud and Web Malware Trends

Other notable findings uncovered by Netskope’s research team include: 

  • 55% of HTTP/HTTPS malware downloads came from cloud apps, up from 35% for the same period one year earlier. The primary driver of the increase is an increase in malware downloads from the most popular enterprise cloud applications, with Microsoft OneDrive tracked as the most popular enterprise app by a wide margin.
  • The number of applications with malware downloads also continued to increase, reaching a high of 261 distinct apps in Q1 2023. 
  • Only a small fraction of total web malware downloads were delivered over web categories traditionally considered risky. Instead, downloads are spread out among a wide variety of sites, with content servers (CDNs) responsible for the largest slice, at 7.7%.

As enterprises work to defend against the onslaught of malware, cross-functional collaboration across multiple teams is required, including network, security operations, incident response, leadership, and even individual contributors. Some of the additional steps organizations can take to reduce risks include:  

  • Inspect all HTTP and HTTPS downloads, including all web and cloud traffic, to prevent malware from infiltrating your network
  • Ensure that security controls recursively inspect the content of popular archive files and that high-risk file types are thoroughly inspected 
  • Configure policies to block downloads from apps that are not used in your organization to reduce risk surface.
- Advertisement -

Most Popular Articles

Tata Elxsi Unveils New Bengaluru Lab To Boost 5G

0
With the opening of its xG-Force laboratory in Bengaluru, Tata Elxsi aims to drive 5G innovation, providing infrastructure and tools for various sectors, with...

Delhi’s Environment Department Unleashes’ E-Vehicle Parade’ in Oct To Boost Adoption Rate

0
According to the officials, the primary objective of the parade is to solidify awareness of the benefits of adopting electric cars. To increase the adoption...

Hyundai, Kia, And Samsung Team Up To Boost SDV Experience

0
Hyundai Motor and Kia are collaborating with 42dot to develop a next-generation infotainment system and foster an open ecosystem. This partnership aims to enhance...

Dutch Minister Advocates For ASML’s Freedom In Trade

0
During his US visit, the Economy Minister of Netherlands stated the importance of China as a trading partner and advocated for ASML's operational freedom...

JSW Group Executives Refute Reports Of Relocating EV Plant From Odisha to Maharashtra

0
The manufacturing operations include electric vehicles, a 50 GWh battery plant, electric powertrains, a lithium refinery, and various related production units. Senior management at Sajjan...

“Range Anxiety And Standardisation In EV Charging Infrastructure Need To Be Addressed” – Ravi...

0
In an interview with Nitisha from EFY, Ravi Mahankali of Axonify Tech Systems, outlines the company’s EV charging solutions, covering chargers for four-wheelers, buses,...
Sirajuddin Ali, Founder and CEO of Malitra

“We Need Changes In National Building Codes, Along With Stringent Guidelines For Existing Buildings...

0
What are the policy shifts that could drive the expansion of India's EV ecosystem? Sirajuddin Ali, Founder and CEO of Malitra, an EV charging...
Narayan Kumar, Divisional Director - Industrial Devices Division, Panasonic Life Solutions India

“Automotive Is Currently Dominant; Infrastructure, ICT, Factory Automation Poised For Growth” – Narayan Kumar,...

0
In a discussion with EFY, Narayan Kumar, Divisional Director of Panasonic Life Solutions India's Industrial Devices Division (INDD), shared insights on the company's strategy...
Brajendra Singh Tomar CEO and Founder of Finayo

“Leasing Companies Critical For EV Adoption In The B2B Vertical” – Brajendra Singh Tomar,...

0
Why do electric rickshaws outsell L-category electric three-wheelers in rural and semi-rural areas? Is there potential for change? Brajendra Singh Tomar, CEO and Founder...
Naresh Neelakantan Global Nexus

“Cyber attack On A Vehicle Is An Attack On The OEM’s Image” – Naresh...

0
With the ongoing rapid evolution in the automotive arena, are cyberattack threats also increasing? Moreover, are software defined vehicles (SDVs) equipped to counter these...
InCore Co-founders (L to R): Arjun Menon (Chief Engineer), G.S. Madhusudan (CEO), Neel Gala (CTO), and Gautam Doshi (Chief Architect)

InCore Unveils Six-Core RISC-V Test Chip To Accelerate Design Adoption

0
InCore Semiconductors has introduced a six-core RISC-V test chip that utilises the company’s proprietary generator technology to build its flexible architecture, allowing for the...

Formula Racing Students Teams To PMSM Motors With 97% Efficiency

0
What can four students from Formula Racing teams accomplish? Why would they shift from creating an electric two-wheeler brand to tackling the rigorous B2B...

STMicroelectronics Joins RISC-V Startup Quintauris As Shareholder

0
To enhance RISC-V product development, STMicroelectronics has joined startup Quintauris as its sixth shareholder, which focuses on automotive and future mobile/IoT applications. Swiss semiconductor company...

Chip Design Startup BigEndian Receives $3M Investment

0
Eyeing expansion in engineering and R&D teams for security solutions, domestic fabless startup BigEndian has obtained a $3 million investment from Vertex Ventures SEA...

Thinker bell’s Self-Learning And Remote-Enabled Braille Literacy Device

0
Bengaluru-based startup Thinkerbell Labs Pvt Ltd was founded by Dilip Ramesh, Sanskriti Dawle, Aman Srivastava, and Saif Shaikh in 2016. For many years, Braille has...

Industry's Buzz

Learn From Leaders

Startups