跳到主体内容

Ransom Aware: Kaspersky Lab Detected a 14% Increase in New Ransomware Modifications in Q1 2016

2016年5月5日

Ransomware has overtaken news about APT attacks to become the main topic of the quarter. According to Kaspersky Lab’s Q1 malware report, the company’s experts detected 2,900 new malware modifications during the quarter, an increase of 14 percent on the previous quarter

Ransomware has overtaken news about APT attacks to become the main topic of the quarter. According to Kaspersky Lab’s Q1 malware report, the company’s experts detected 2,900 new malware modifications during the quarter, an increase of 14 percent on the previous quarter. Kaspersky Lab’s database now includes about 15 thousand ransomware modifications and the number continues to grow.

In the first quarter of 2016, Kaspersky Lab security solutions saved 372,602 users from ransomware attacks, 17 percent of those attacked were in the corporate sector. The number of attacked users increased by 30 percent compared to Q4, 2015.

One of the most famous and widespread ransomware in Q1, 2016 was Locky. Kaspersky Lab products detected attempts to infect users with this Trojan in 114 countries, and as of early May 2016 it remains active. Another ransomware called Petya was interesting from a technical perspective because of its ability not only to encrypt data stored on the computer, but also to overwrite the hard disk drive's master boot record (MBR), leaving infected computers unable to boot into the operating system. According to Kaspersky Lab detections the top three ransomware families in Q1 were: Teslacrypt (58.4%), CTB-Locker (23.5%), and Cryptowall (3.4%). All three propagate mainly through spam emails with malicious attachments or links to infected web pages.

“One of the reasons why ransomware has become so popular lies in the simplicity of the business model used by cybercriminals. Once the ransomware gets into the users’ system there is almost no chance of getting rid of it without losing personal data. Also, the demand to pay the ransom in bitcoins makes the payment process anonymous and almost untraceable which is very attractive to fraudsters. Another threatening trend is the Ransomware-as-a-Service (RaaS) business model where cybercriminals pay a fee for the propagation of malware or promise a percentage of the ransom paid by an infected user,” says Aleks Gostev, Chief Security Expert in the Global Research and Analysis Team (GReAT).

There is a further reason for the rise in ransomware attacks: users believe the threat is unbeatable. Businesses and individuals are not aware of the technology countermeasures that could help to prevent infection and the locking of files or systems; and by ignoring basic IT Security rules they allow cybercriminals and others to profit.

Alongside an overview of the major ransomware outbreaks, Kaspersky Lab has counted the overall level of cyberthreats in Q1 2016 globally.

According to Kaspersky Security Network data, the malware landscape in Q1 2016 was the following:

  • Kaspersky Lab products blocked a total of 228 million malicious attacks on computers and mobile devices.
  • 21.2 percent of Internet users faced web-based attacks at least once, which is 1.5 percentage points lower than in Q4, 2015.
  • 44.5 percent of Kaspersky Lab solutions users faced a malicious threat at least once, which is a 0.8 percentage point increase on Q4, 2015.
  • Kaspersky Lab solutions protected 459,970 users from cybercriminals’ fraudulent attempts to access online banking services and steal their money. This is a 23 percent decrease compared with the previous quarter.
  • Cybercriminals continued to use vulnerabilities in Adobe Flash Player, Internet Explorer and Java to propagate malware. Less frequently, they used exploits for Java – according to our statistics this has decreased by 3.3 percentage points on Q4, 2015 and equals 8% of overall exploit statistics for Q1. The same statistics registered an increased use of vulnerabilities in Flash (a rise of 1 percentage point which is 6% in total) and Microsoft Office (an increase of 10 percentage points which is 15% in total).

Major mobile cyberthreats in Q1 were:

  • The share of adware in overall mobile threats in Q1 equals 42.7 percent which made adware the leading mobile threat. We observed a 13 percentage point increase on the previous quarter. 
  • 4,146 new mobile Trojans were detected which is 1.7 times more than in the previous quarter. Also, the number of detected SMS-Trojans continues to increase.
  • The number of new mobile ransomware has increased 1.4 times, from 1,984 in Q4,2015 to 2,895 in Q1,2016.  
  • China became the most attacked country: 40 percent of Kaspersky Lab security solutions users in this country have faced a mobile threat. Also on this list are Bangladesh (28%) and Uzbekistan (21%). On the other hand, the safest countries were Taiwan (2.9%), Australia (2.7%) and Japan (0.9%).

The full Q1 cyberthreats report is available at securelist.com.

Ransom Aware: Kaspersky Lab Detected a 14% Increase in New Ransomware Modifications in Q1 2016

Ransomware has overtaken news about APT attacks to become the main topic of the quarter. According to Kaspersky Lab’s Q1 malware report, the company’s experts detected 2,900 new malware modifications during the quarter, an increase of 14 percent on the previous quarter
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻