Ransomware attacks skyrocketed 148% in March, compared to baseline levels in February, as corporations shift to remote work because of the coronavirus pandemic, according to VMware Carbon Black threat researchers.
Between Feb. 4 and April 7, the security analysts estimated a 70% increase in remote work. This is based on data collected by the VMware Carbon Black Cloud sensor and doesn’t include people who already worked from home.
And, perhaps not surprisingly, during this time attacks against companies and individuals rose steeply. The threat researchers observed hackers using COVID-19 to launch phishing attacks, fake apps and maps, trojans, backdoors, crypto miners, botnets, and ransomware.
Attacks Correlate to COVID-19 Key Days“Notable spikes in attacks can also be correlated to key days in the COVID-19 news cycle, suggesting attackers are being nefariously opportunistic and leverage breaking news to take advantage of vulnerable populations,” wrote VMware Cabon Black threat researchers Patrick Upatham and Jim Treinen in a blog post.
Some of these notable spikes include a 48% spike in attacks over baseline levels on Jan. 30, the day the U.S. announced its first COVID-19 case. A 66% increase on Feb. 29 when multiple U.S. states declared public health emergencies. A day later on March 1, VMware Carbon Black reported another 66% spike on the day the first COVID-19 death was announced in the U.S. And a 49% jump over baseline levels on March 2, when Italy’s COVID-19 cases surpassed 2,000. The spikes continued in the days following when Italy issued a public lockdown and then the World Health Organization (WHO) declared a pandemic.
While no industry sector has been immune to coronavirus-related security attacks, the finance sector has been increasingly targeted during the COVID-19 surge. Between February and March, the threat researchers saw a 38% increase in cyberattacks against financial institutions.
Upatham and Treinen also note that while the retail sector led the majority of observed threats in February, with just over 31%, it shrank to 1.6% in March. This suggests that “as retail organizations shifted to remote business models, attacks actually went down and attackers shifted to target financial organizations,” they wrote.
Big Data to Hunt AttackersAs the pandemic continues, companies must use big data analytics collected across endpoints, event streams, attackers’ tactics and techniques, and global threat intelligence to uncover attackers’ behavior, according to VMware Carbon Black. “Without big data analytics, companies can only focus on finding and stopping known methods and attacks, which leaves them vulnerable to new and emerging attacks. Security teams must be able to predict and prevent not only known attacks, but future and unknown ones too.”
And because more employees are working remotely, this data collection and threat hunting needs to extend into the home, said Tom Kellermann, head cybersecurity strategist at VMware Carbon Black, in an earlier interview with SDxCentral. Staying safe and healthy — physical security to defend against COVID-19 — is everyone’s top priority right now, Kellermann said. “And the No. 2 priority must be the fact that their corporations are being hunted through their home.”
Comments