July 2021’s Most Wanted Malware: Snake Keylogger Enters Top 10 for First Time - Check Point Software (2024)

Check Point Research (CPR), the Threat Intelligence arm of Check Point® Software Technologies Ltd. (NASDAQ: CHKP), a leading provider of cyber security solutions globally, has published its latest Global Threat Index for July 2021. Researchers report that while Trickbot is still the most prevalent malware, Snake Keylogger, which was first detected in November 2020, has surged into second place following an intense phishing campaign.

Snake Keylogger is a modular .NET keylogger and credential stealer. Its primary function is to record users’ keystrokes on computers or mobile devices and transmit the collected data to threat actors. In recent weeks, Snake has been growing fast via phishing emails with different themes across all countries and business sectors.

Snake infections pose a major threat to users’ privacy and online safety, as the malware can steal virtually all kinds of sensitive information, and it is a particularly evasive and persistent keylogger. There are currently underground hacking forums where the Snake Keylogger is available for purchase, ranging from 25 to 500 dollars, depending on the level of service offered.

Keylogger attacks can be particularly dangerous because individuals tend to use the same password and username for different accounts, and once one login credential is breached, the cybercriminal gains access to all those that have the same password. To stop them, it is essential to use a unique option for each of the different profiles. To do this, a password manager can be used, which allows both managing and generating different robust access combinations for each service based on the guidelines decided upon.

“Where possible, users should reduce the reliance on passwords alone, for example by implementing Multi-Factor Authentication (MFA) or Single-Sign-On (SSO) technologies,” said Maya Horowitz, VP Research at Check Point Software. “Also, when it comes to password policies, choosing a strong, unique password for each service is the best advice, then even if the bad guys do get hold of one of your passwords, it won’t immediately grant them access to multiple sites and services. Keyloggers such as Snake, are often distributed via phishing emails so it’s essential that users know to look out for small discrepancies such as misspellings in links and email addresses, and be educated to never click on suspicious links or open any unfamiliar attachments.”

CPR also revealed this month that “Web Server Exposed Git Repository Information Disclosure” is the most commonly exploited vulnerability, impacting 45% of organizations globally, followed by “HTTP Headers Remote Code Execution” which affects 44% of organizations worldwide. “MVPower DVR Remote Code Execution” takes third place in the top exploited vulnerabilities list, with a global impact of 42%.

Top malware families

*The arrows relate to the change in rank compared to the previous month.

This month, Trickbot is the most popular malware impacting 4% of organizations globally, followed by Snake Keylogger and XMRig, each with a global impact of 3%.

  1. ↔ Trickbot – Trickbot is a modular Botnet and Banking Trojan constantly being updated with new capabilities, features and distribution vectors. This enables Trickbot to be a flexible and customizable malware that can be distributed as part of multi-purpose campaigns.
  2. ↑ Snake Keylogger – Snake is a modular .NET keylogger and credential stealer first spotted in late November 2020; its primary functionality is to record users’ keystrokes and transmit collected data to threat actors.
  3. ↓ XMRig – XMRig is an open-source CPU mining software used for the mining process of the Monero cryptocurrency, and first seen in-the-wild in May 2017.

Top exploited vulnerabilities

This month “Web Server Exposed Git Repository Information Disclosure” is the most commonly exploited vulnerability, impacting 45% of organizations globally, followed by “HTTP Headers Remote Code Execution” which affects 44% of organizations worldwide. “MVPower DVR Remote Code Execution” is in third place in the top exploited vulnerabilities list, with a global impact of 42%.

  1. ↑ Web Server Exposed Git Repository Information Disclosure – An information disclosure vulnerability has been reported in Git Repository. Successful exploitation of this vulnerability could allow an unintentional disclosure of account information.
  2. ↓ HTTP Headers Remote Code Execution (CVE-2020-10826,CVE-2020-10827,CVE-2020-10828,CVE-2020-13756) – HTTP headers let the client and the server pass additional information with an HTTP request. A remote attacker may use a vulnerable HTTP Header to run arbitrary code on the victim machine.
  3. ↓ MVPower DVR Remote Code Execution – A remote code execution vulnerability exists in MVPower DVR devices. A remote attacker can exploit this weakness to execute arbitrary code in the affected router via a crafted request.

Top Mobile Malwares

This month xHelper takes first place in the most prevalent Mobile malwares, followed by AlienBot and Hiddad.

  1. xHelper – A malicious application seen in the wild since March 2019, used for downloading other malicious apps and display advertisem*nts. The application is capable of hiding itself from the user and can even reinstall itself in the event that it was uninstalled.
  2. AlienBot – AlienBot malware family is a Malware-as-a-Service (MaaS) for Android devices that allows a remote attacker, as a first step, to inject malicious code into legitimate financial applications. The attacker obtains access to victims’ accounts, and eventually completely controls their device.
  3. Hiddad – Hiddad is an Android malware which repackages legitimate apps and then releases them to a third-party store. Its main function is to display ads, but it can also gain access to key security details built into the OS.

Check Point’s Global Threat Impact Index and its ThreatCloud AI Map is powered by Check Point’s ThreatCloud AI intelligence, the largest collaborative network to fight cybercrime which delivers threat data and attack trends from a global network of threat sensors. The ThreatCloud AI database inspects over 3 billion websites and 600 million files daily, and identifies more than 250 million malware activities every day.

The complete list of the top 10 malware families in July can be found on the Check Point < href="https://blog.checkpoint.com/2021/08/12/july-2021s-most-wanted-malware-snake-keylogger-enters-top-10-for-first-time/">blog.

Follow Check Point Research via:
Blog: https://research.checkpoint.com/
Twitter: https://twitter.com/_cpresearch_

About Check Point Research
Check Point Research (CPR) provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber-attack data stored on ThreatCloud AI to keep hackers at bay while ensuring all Check Point solutions are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcement, and various CERTs.

July 2021’s Most Wanted Malware: Snake Keylogger Enters Top 10 for First Time - Check Point Software (2024)
Top Articles
About the University of Louisville < University of Louisville
Ohio Winter Road Conditions
Fernald Gun And Knife Show
Loves Employee Pay Stub
Danatar Gym
Occupational therapist
Valley Fair Tickets Costco
Missing 2023 Showtimes Near Cinemark West Springfield 15 And Xd
Activities and Experiments to Explore Photosynthesis in the Classroom - Project Learning Tree
Wmlink/Sspr
No Credit Check Apartments In West Palm Beach Fl
Mission Impossible 7 Showtimes Near Regal Bridgeport Village
MindWare : Customer Reviews : Hocus Pocus Magic Show Kit
Marion County Wv Tax Maps
Moonshiner Tyler Wood Net Worth
Jesus Calling Oct 27
The Superhuman Guide to Twitter Advanced Search: 23 Hidden Ways to Use Advanced Search for Marketing and Sales
Jet Ski Rental Conneaut Lake Pa
[Cheryll Glotfelty, Harold Fromm] The Ecocriticism(z-lib.org)
Ruse For Crashing Family Reunions Crossword
Eine Band wie ein Baum
Scout Shop Massapequa
Tripadvisor Napa Restaurants
How to Grow and Care for Four O'Clock Plants
THE FINALS Best Settings and Options Guide
F45 Training O'fallon Il Photos
Hannah Palmer Listal
Sienna
Craigslist Wilkes Barre Pa Pets
Sand Dollar Restaurant Anna Maria Island
Barista Breast Expansion
Panolian Batesville Ms Obituaries 2022
Dhs Clio Rd Flint Mi Phone Number
Delete Verizon Cloud
Gt7 Roadster Shop Rampage Engine Swap
Isablove
County Cricket Championship, day one - scores, radio commentary & live text
Myra's Floral Princeton Wv
Davita Salary
Kaiserhrconnect
Http://N14.Ultipro.com
Reborn Rich Ep 12 Eng Sub
Cbs Fantasy Mlb
Tsbarbiespanishxxl
Henry Ford’s Greatest Achievements and Inventions - World History Edu
Frigidaire Fdsh450Laf Installation Manual
Rage Of Harrogath Bugged
Marcal Paper Products - Nassau Paper Company Ltd. -
Sacramentocraiglist
Upcoming Live Online Auctions - Online Hunting Auctions
Horseneck Beach State Reservation Water Temperature
Every Type of Sentinel in the Marvel Universe
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 5319

Rating: 4.7 / 5 (47 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.