In April 2019, banking trojanTrickbot re-appeared in the top ten most wanted malware list for the first time in almost two years. The multi-purpose trojan became April’s 8th most prevalent malware variant, returning with new capabilities, features and distribution vectors. Trickbot offers a high level of flexibility and customization, which enables it to be distributed as part of multi-purpose campaigns.
Trickbot was used in several campaigns in April timed to coincide with Tax Day in the USA. In the spam campaigns, attackers sent emails with Excel files attached, which downloaded Trickbot to victims’ computers. Once downloaded, Trickbot could spread inside the network and steal banking details and confidential tax documents for fraudulent use.
Although, cryptominers still occupied the top three positions in the index, the remaining seven malware types in April’s top ten were multi-purpose trojans, which is especially concerning given the fact that they may be used not only to steal private data and credentials, but also for other nefarious purposes. In the past, Emotet and Trickbot were also used to populate the Ryuk ransomware, for example. As these malware constantly morph, enterprises must have a robust line of defense against them with advanced threat prevention.
April 2019’s Top 10 ‘Most Wanted’:
*The arrows relate to the change in rank compared to the previous month.
- ↑ Cryptoloot– Crypto-Miner that uses the victim’s CPU or GPU power and existing resources for crypto mining – adding transactions to the blockchain and releasing new currency. Cryptoloot originally emerged as a competitor to Coinhive, trying to pull the rug under it by asking a smaller percentage of revenue from websites.
- ↑ XMRig- Open-source CPU mining software used for to mine the Monero cryptocurrency, and first seen in-the-wild on May 2017.
- ↓ Emotet – Advanced, self-propagate and modular Trojan. Emotet once used as a banking Trojan, and recently is used to distribute other malware or malicious campaigns. It uses multiple methods for maintaining persistence and Evasion techniques to avoid detection. In addition, it can be spread through phishing spam emails containing malicious attachments or links.
- ↓ Dorkbot- IRC-based Worm designed to allow remote code execution by its operator, as well as downloading additional malware to the infected system.
- ↑ Ramnit- Banking Trojan that steals banking credentials, FTP passwords, session cookies and personal data.
- ↑ Agentesla- AgentTesla is an advanced RAT functioning as a keylogger and a password stealer. AgentTesla is capable of monitoring and collecting the victim’s keyboard input, system clipboard, taking screenshots, and exfiltrating credentials belonging to of a variety of software installed on a victim’s machine (including Google Chrome, Mozilla Firefox and Microsoft Outlook email client).
- ↑ Trickbot- Trickbot is a dominant banking Trojan constantly being updated with new capabilities, features and distribution vectors. This enables Trickbot to be a flexible and customizable malware that can be distributed as part of multi purposed campaigns.
- ↑ Sality- Sality is a file infector, able to communicate with other infected systems over a peer-to-peer (P2P) network for spamming purposes, proxying of communications, compromising web servers, exfiltrating sensitive data, and coordinating distributed computing tasks to process intensive tasks.
- ↓ Lokibot- Lokibot is an Info Stealer distributed mainly by phishing emails, and is used to steal various data such as email credentials, as well as passwords to CryptoCoin wallets and FTP servers.
This month Triada is the most prevalent Mobile malware, replacing Hiddad at first place in the top mobile malware list. Lootor remains in second place, and Hiddad falls to third.
April’s Top 3 ‘Most Wanted’ Mobile Malware:
- Triada – Modular Backdoor for Android which grants super user privileges to downloaded malware, that helps it to embed into system processes. Triada has also been seen spoofing URLs loaded in browsers.
- Lotoor- Hack tool that exploits vulnerabilities on Android operating system in order to gain root privileges on compromised mobile devices.
- Hiddad- Android malware which repackages legitimate apps and then released them to a third-party store. Its main function is displaying ads, however it is also able to gain access to key security details built into the OS, allowing an attacker to obtain sensitive user data.
Check Point’s researchers also analyzed the most exploited cyber vulnerabilities. OpenSSL TLS DTLS Heartbeat Information Disclosure exploits is the most popular exploited vulnerability with a global impact of 44% of organization worldwide. For the first time after 12 months CVE-2017-7269 dropped from first place to the second, impacting 40% of organizations, followed by CVE-2017-5638 with a global impact of 38% of organizations around the world.
April’s Top 3 ‘Most Exploited’ vulnerabilities:
- ↑ OpenSSL TLS DTLS Heartbeat Information Disclosure (CVE-2014-0160; CVE-2014-0346) – An information disclosure vulnerability exists in OpenSSL. The vulnerability is due to an error when handling TLS/DTLS heartbeat packets. An attacker can leverage this vulnerability to disclose memory contents of a connected client or server.
- ↓ Microsoft IIS WebDAV ScStoragePathFromUrl Buffer Overflow (CVE-2017-7269) – By sending a crafted request over a network to Microsoft Windows Server 2003 R2 through Microsoft Internet Information Services 6.0, a remote attacker could execute arbitrary code or cause a denial of service conditions on the target server. That is mainly due to a buffer overflow vulnerability resulted by improper validation of a long header in HTTP request.
- ↑ Apache Struts2 Content-Type Remote Code Execution (CVE-2017-5638) – A remote code execution vulnerability exists in the Apache Struts2 using Jakarta multipart parser. An attacker could exploit this vulnerability by sending an invalid content-type as part of a file upload request. Successful exploitation could result in execution of arbitrary code on the affected system.
The map below displays the risk index globally (green – low risk, red- high risk, grey – insufficient data), demonstrating the main risk areas and malware hot-spots around the world.
ASUS ROG Announces ROG Masters Asia Pacific eSports Tournament
ASUS ROG will host its first ROG Masters Asia Pacific eSports tournament from March to April 2021. Due to COVID-19 pandemic affecting travel around the region, the tournament will be conducted entirely online, with quarterfinal to final matches livestreamed.
The ROG Masters tournament will feature Counter-Strike: Global Offensive (CS:GO) as the official game title will provide opportunity to teams with enthusiastic players to pitch their skills against each other, as well as the best professional teams from their market and in the region.
The tournament will see various teams from 15 markets across the region vying for the chance to be crowned as the first ROG Masters Asia Pacific Edition CS:GO Champion.
The tournament will be played in three stages played over the course of 2 months:
- Country qualifiers
- Country finals
- Asia Pacific finals
Country qualifiers matches for India will start in the second week of April 2021; 8th April and the finals to be held on the 10th April. The India finals to find the top three teams to represent the country will be livestreamed live on 10th April.
Professional teams from across the region will be automatically placed into seeded positions in the country finals. This gives a greater chance for non-professional, enthusiast teams from India to get through the qualifiers and meet the pro teams in the country finals.
Country Champions will then go on to experience battling winning teams from other APAC markets in the finals that will be livestreamed during 22nd to 25th April 2021.
3 qualifying teams from India finals will stand to win US$800 for first place, US$400 for second place, US$200 for third place. They will then go on to the Asia Pacific finals with the chance to win the following prizes for the championship:
|ROG Masters APAC Championship||APAC Finals (USD/ team)|
Registration and Official Tournament Website
Registration for the first ROG Masters Asia Pacific tournament opens on February 8, 2021 at the tournament’s official website.
Registration closes on February 28, 2021 Further details, match schedules, pro team information as well as rules and regulations can also be found on the tournament website.
Garena Launches Free Fire South Asia Showdown: Battle of the Stars
Garena has announced the Free Fire South Asia Showdown: Battle of the Stars, Free Fire’s first-ever esports tournament for the South Asia region. Taking place on 6 February, the tournament will feature some of the gaming community’s favourite Free Fire streamers and personalities from India, Pakistan, Nepal, and Bangladesh.
The Free Fire community has continued to expand in South Asia and across the world, with the mobile battle royale game the most downloaded mobile game globally in 2020, according to App Annie. Through the Free Fire South Asia Showdown: Battle of the Stars, Garena will look to continue its efforts to excite and delight its fast-growing South Asian community with exciting Free Fire content, and to support and develop the incredible online community in the region.
The Free Fire South Asia Showdown: Battle of the Stars will feature a total of 12 teams. Each team will be led by one of the top 3 streamers from each of the 4 participating nations – chosen by public voting – in this epic clash to determine the best in the region.
The 12 teams will compete in the Battle Royale Squad mode for a slice of the 1 million diamond prize pool. The ultimate winner of this star-studded tournament will receive 500,000 in-game diamonds; the first and and second runners-up will be awarded 300,000 and 200,000 diamonds respectively.
The Free Fire South Asia Showdown: Battle of the Stars will feature some of the most popular streamers and personalities from across South Asia.
The team captains for each nation are:
- Total Gaming (19.4 Million YT Subs)
- Desi Gamers (7.8 Million YT Subs)
- Two-Side Gamers (6.85 Million YT Subs)
- Gaming with Nayeem (1.6 Million YT Subs)
- Illusionist YT (479K YT Subs)
- Gaming With Zihad (698K YT Subs)
- Sooneeta (3.26 Million YT Subs)
- Bshow Mgr (399K YT Subs)
- Tonde Gamer (2.37 Million YT Subs)
- RKG ARMY (1.77 Million YT Subs)
- Unusual Gamer (81K YT Subs)
- The Skinzo FF (75.5K YT Subs)
Fans can witness all the high-octane action by tuning in to the live broadcasts of the Free Fire South Asia Showdown: Battle of the Stars. These will be hosted on Free Fire Esports India YouTube and Facebook, Free Fire Bangladesh Official YouTube and Facebook, as well as on BOOYAH!.
To cater to the diverse South Asian community, the matches will be streamed with live commentary in 5 languages – Bengali, English, Hindi, Nepali and Urdu.
Top Gaming Accessories for Ultimate Gaming Experience
Witnessing the consumer behaviour being impacted drastically last year, the year 2021 has welcomed an immense lifestyle change for gamers. Gaming has been one of the sectors that witnessed a spike like never before. From casual gamers to professional gamers, the segment realised immense growth in a matter of a few months. A lot of people opted for gaming for the first time with more time in hand, while amateur gamers worked on their skills to shift to pro-level. Owing to ‘isolate and chill’ mode to beat the anxiety and paranoia, a lot of people moved to ‘Play@Home’ and for many, it was rekindling their old gaming habits with the bountiful time in their grasp.
While gaming serves as a boosting engagement, it is important to have the kit and accessories to ensure the seamless and immersive experience of gaming. Especially for those who have just adopted gaming as a new hobby and do not want to invest steeply in buying the expensive accessories, we bring a perfect start-up kit to you that is sure to pave your path to the next level
Logitech G331: Enjoy the whole experience of all your favorite games with Logitech G331 gaming headset that produces big sound to get you into the game. Experience the thrill of a complete gaming experience where you hear everything and everyone hears you. The 6 mm mic ensures that your squad-mates can hear you clear and distinct. It also has an option of Flip-to-mute boom that silences you when you don’t want to be heard. The headphone is all set to work with your PC or Mac or with gaming consoles including PlayStation 4™, Xbox One™, Nintendo Switch™, and mobile devices via 3.5 mm cable. In fact, everything about these headphones is about comfort: The deluxe lightweight leatherette ear cups and headband are made to keep pressure off your ears that is available at Amazon.in at an offer price of INR 5995 .
Logitech G213: Sitting at your gaming desk in front of your gaming monitor might be the way for most PC gamers, but unless you’ve got a killer set-up with a solid keyboard, it may still not satiate your gaming soul. With a RGB color spectrum illumination lets you easily personalize up to 5 lighting zones from over 16.8 million colors to match your style and gaming gear, the Logitech G213 ensures you have a great customisable gaming experience. The G213 comes with a performance that is up to 4x faster than standard keyboards and features keys that are specially tuned to deliver a superior tactile experience. The dedicated media control allows you to quickly play, pause, skip and adjust the volume of music right from the keyboard. the brilliant color spectrum. The G213 also offers 12 function keys with custom commands and more with free Logitech gaming software. This keyboard is available at Amazon.in at an offer price of INR 4995
Logitech G102 LIGHTSYNC: It is of paramount importance to have an exact grip and size while using a gaming mice. With LIGHTSYNC RGB lighting across, Logitech G102 is designed to work seamlessly in any system to enhance your gaming experience. The classic six-button design provides both comfort and confidence that can be customised across 16.8 million colours so you can explore, cast spells, and play just like you want. With 8,000 DPI sensor – The gaming-grade sensor responds precisely to your movements. But if you’re looking to fine-tune controls, free-to-download customization software is easy to use and set up with Logitech G HUB software. it is a complete customization suite that allows you to personalize lighting, sensitivity, and button commands on your G102 mouse. It is available in Amazon.in at an offer price of INR 1985.
Gadgets5 days ago
OSS Infocom Launches eOnz Elite Smartwatch
Trending5 days ago
TECNO Launches Doorstep Delivery Facility
Startups5 days ago
Fyool App Launches New User Interface
Gadgets5 days ago
Top Four Tech Gadgets You Can Buy to Simplify Day-to-day Life
Trending5 days ago
Kingston Announces New ‘‘Kingston Is With You’’ Campaign
Videos5 days ago
Portronics Wireless Neckbands I Harmonics 216 & 300 Unboxing & Review
Trending5 days ago
Video Meet Adds Artificial Intelligence to Its Platform
Trending4 days ago
Vivo Announces Three Years of Android Upgrades for X Series Smartphones