Report | Cyber Attack Trends Mid-Year Report, 2022 | Check Point Software

Report | Cyber Attack Trends Mid-Year Report, 2022

CYBER AT TACKTRENDSCheck Point’s 2022 Mid-Year Report

2CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT CHAPTER 1: EXECUTIVE SUMMARY MAYA HOROWITZ, VP RESEARCH CHAPTER 2: TRENDS08Russia Ukraine War—The First Hybrid War that Forced Everyone to Take Sides14Country Extortion—Ransomware Groups Step Up to Nation State Actor Level17 Microsoft Blocks Internet Macros in Office—The Developments inthe Email Infection Chains20Scope of The Mobile Malware Landscape23Cloud Supply Chain AttacksCHAPTER 3: CYBER ATTACK CATEGORIES BY REGION29Global Threat Index Map31 Top malicious file types—web vs. emailCHAPTER 4: GLOBAL MALWARE STATISTICSCHAPTER 5: TOP MALWARE FAMILIES38Top Multipurpose Malware40Top Infostealer Malware42Top Cryptomining Malware44 Top Mobile MalwareCONTENTS0407263336

3CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT CHAPTER 6: HIGH PROFILE GLOBAL VULNERABILITIESCHAPTER 7: TOP ATTACKS AND CYBER BREACHES H1 2022CHAPTER 8: H2 2022: WHAT TO EXPECT AND WHAT TO DOCHAPTER 9: INCIDENT RESPONSE PERSPECTIVECHAPTER 10: PREVENTION OF THE NEXT ATTACK IS POSSIBLECHAPTER 11: CONCLUSIONCHAPTER 12: ANNEX: MALWARE FAMILY DESCRIPTIONS46506063746876

4CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 401CHAPTER 1EXECUTIVE SUMMARY01 BY:MAYA HOROWITZ, VP RESEARCH

5CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 5MAYA HOROWITZVP Research, Check PointThe war in Ukraine has dominated the headlines in the first half of 2022 and we can only hope that it will be brought to a peaceful conclusion soon. However, its impact on the cyber space has been dramatic in both scope and scale, as cyberattacks have become firmly entrenched as a state level weapon. We have identified unprecedented levels of state-sponsored attacks, the growth of hacktivism and even the recruitment of private citizens into an “IT Army.” In this report, we take a closer look at how cyber warfare has intensified to become an essential part of the preparation for, and conduct of, actual military conflict. Furthermore, we uncover what the fallout of this will be for governments and enterprises all over the world, even those that are not directly involved in the conflict. A second major trend in the first half of this year has been the ability of threat actors to disrupt the everyday lives of normal citizens. In this regard there has been crossover with cyber warfare and hacktivism, as we saw a TV station taken down by missiles in Kyiv with a cyberattack launched at the same time for the same purpose, as well as interference with Moscow’s smart TV platform to beam live antiwar messages into homes across Russia. The full scale of cyber’s ability to cause real harm to citizens, though, is best illustrated by the attack on the entire country of Costa Rica which crippled essential services including healthcare and inland revenue, stopping medical appointments and the collection of taxes. In the US, teachers have been put out of work and student learning disrupted when Lincoln College succumbed to a ransomware attack which resulted in it closing its doors after 157 years. Cyber’s theoretical potential for major disruption to civic society just got real in 2022 and in this report, we will look at what organizations can do to avoid becoming the next victim.CHAPTER 1

6CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT The events in Costa Rica also highlighted why ransomware is the number one security threat to enterprises around the world. Imagine an entire country being the victim of cyber extortion by a criminal gang? This was not even an isolated example as Peru became the second victim of ‘Country Extortion’ not long afterward. The huge potential for financial gain means that ransomware is going to be around for a long time and it’s only going to get worse as threat actors invest their ill-gotten gains into better tools and resources. The good news, however, is that we also have new tools and technologies to meet the danger wherever it comes from and however sophisticated the attack. At the start of the year, we had the continued fallout of Log4j, one of the most serious zero-day vulnerabilities we have ever seen. Any assumptions that it was a one-off event were soon put to bed as just a couple of months later, another huge zero-day vulnerability was found in the open-source Spring Framework—Spring4Shell. We also saw in H1 the demise of a significant malware family, Trickbot, but the good news ended there as the notorious malware Emotet has continued to dominate since its resurgence late last year. In this report, we will unravel 2022’s threat landscape and provide examples and statistics of real-world events, so you know exactly what you need to be aware of in your organization.As we look ahead to the remainder of 2022 and beyond, our global team of experts have provided their predictions, from a tsunami of state-sponsored attacks to the first malicious activity in the Metaverse, so that we can all get prepared now for what’s to come.CHAPTER 1

7CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 7CHAPTER 202TRENDS‘ CYBER ATTACK TRENDS: 2022 MID-YEAR REPORT’ TAKESA CLOSER LOOK AT HOW CYBERATTACKS HAVE INTENSIFIED IN THE FIRST HALF OF THIS YEAR AND HIGHLIGHTS GLOBAL TRENDS.

8CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT which distributes power to approximately 230,000 consumers. The attackers also disabled two out of three relevant backup power supplies. • April 2022—two months into the current war, there was another attempt to attack a Ukrainian power grid, which showedsimilarities to the 2015 incident in terms of the malicious code deployed. While not as visible as other aspects of the war, the cyber front has silently swept up thousands of ‘volunteer troops’—hacktivists, cybercriminals, white hat researchers and even technology companies such as Elon Musk’s SpaceX. All these diverse groups chose sides and quickly joined the fight, each with its own targets and toolsets, from DDoS and website defacements to destructive critical infrastructure attacks. The powerful Conti ransomware group, who claimed hundreds of victims within just a few months, publicly vowed to protect the Kremlin. RUSSIA UKRAINE WAR—THE FIRST HYBRID WAR THAT FORCED EVERYONE TO TAKE SIDESOn February 24th 2022, Russia launched a full-scale military invasion of Ukraine with attacks on land, at sea and from the air. This was a dramatic escalation of a conflict between the two states that had been going on since 2014. • March 2014—following the Crimean dispute, Russia launched a massive Distributed Denial of Service (DDoS) attack against a large network in Ukraine. • December 2015—as geopolitical tensions continued to rise, Russian state-sponsored Advanced Persistent Threat (APT) group, Sandworm, hacked the power grid of the Ivano-Frankivsk region in Western Ukraine, CHAPTER 2 Cyber warfare is the Hidden Front in the Russo-Ukraine conflict and plays as pivotal a role as tanks and missiles. It has become an essential part of preparations for war as well as playing a role in the conduct or disruption of kinetic military operations. We have also seen that cyberspace is an effective front line in a country's defensive response to military incursion."SERGEY SHYKEVICHGroup Manager,Threat Intelligence

https://www.bbc.com/news/technology-61085480https://www.reuters.com/world/europe/russian-hackers-tried-sabotage-ukrainian-power-grid-officials-researchers-2022-04-12/https://blog.checkpoint.com/2022/02/27/how-the-eastern-europe-conflict-polarized-cyberspace/https://www.space.com/elon-musk-spacex-starlink-cyber-defense-ukraine-invasionhttps://blog.checkpoint.com/2022/03/03/hacktivism-in-the-russia-ukraine-war-questionable-claims-and-credits-war/https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Vwwdhttps://www.esentire.com/security-advisories/conti-ransomware-gang-claims-50-new-victims-including-oil-terminal-operator-sea-invest#:~:text=TRU%20reports%20that%20from%20November,Canada%2C%20Australia%20and%20New%20Zealand.https://www.reuters.com/technology/russia-based-ransomware-group-conti-issues-warning-kremlin-foes-2022-02-25/https://www.nytimes.com/live/2022/02/24/world/russia-attacks-ukrainehttps://www.wired.com/2016/03/inside-cunning-unprecedented-hack-ukraines-power-grid/

9CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT • In May, APT28 launched a campaign targeting local state entities, probably with the aim of espionage in order to steal tactical and strategic data. • In addition to Conti, cybercrime groups such as the ‘CoomingProject’ announcedat an early stage that they would assist the Russian government and protect Russian targets from attacks. • Killnet, a key pro-Russian hacktivist gang, has consistently targeted NATO members and Ukraine supporters with sophisticated DDoS attacks against critical infrastructure bodies. • In mid-March 2022, as the war escalated, the Ukrainian CERT reported that critical infrastructure entities were under attack by multiple APT groups. Ukraine statedthat 65 critical infrastructure attacks were recorded in a single week. Researchers further observed at times that kinetic military and cyberspace actions appeared to be coordinated. For example, on March 1st, a Kyiv TV tower was hit by Russian missiles, resulting in a halt to TV broadcasting in the city. A cyberattack was also launched at the same time for the same purpose. Ukraine in turn took unprecedented steps in the fight in cyberspace by recruiting an international army of motivated hackers to act on its behalf against Russia. RUSSIAN OPERATIONS AGAINST UKRAINE—DISRUPT AND DESTROYEven before the full-scale invasion, the Russian government and sophisticated state-sponsored APT groups made an intelligent and coordinated use of both kinetic and cyber-based tools. Top Russian APT groups, widely known for their sophisticated toolsets and global record of attacks, joined the fight as soon as the war started, providing significant cyberspace backup that could potentially tilt the scales in Russia’s favor: CHAPTER 2 Just three days after the invasion of Ukraine, on February 27th, Check Point Research (CPR) noted a 196% increase in cyber-attacks on Ukraine’s government-military sector, and a 4% increase in cyber-attacks per organization in Russia.

https://cert.gov.ua/article/40106https://www.euronews.com/next/2022/03/09/cyberespionage-is-key-to-russia-s-invasion-of-ukraine-the-international-community-is-fighthttps://blog.checkpoint.com/2022/02/27/how-the-eastern-europe-conflict-polarized-cyberspace/https://www.forescout.com/blog/killnet-analysis-of-attacks-from-a-prominent-pro-russian-hacktivist-group/https://cyberpeaceinstitute.org/ukraine-timeline-of-cyberattacks/https://www.infosecurity-magazine.com/news/attack-ukraine-telecoms-employee/https://blogs.microsoft.com/on-the-issues/2022/04/27/hybrid-war-ukraine-russia-cyberattacks/https://www.businessinsider.com/russian-forces-attack-kyiv-tv-tower-knock-out-broadcasting-2022-3https://blog.checkpoint.com/2022/02/27/196-increase-in-cyber-attacks-on-ukraines-government-and-military-sector/

10CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT Destructive malware is a significant component of the attacks carried out by the cyberspace actors on the Russian side. Also referred to as a “wiper,” destructive malware is used to cause immediate disruption to functionality, destroy data storage systems and harm critical operations. This can have a major impact on public morale as well as unsettle the leadership.Multiple wipers have been observed since January 2022, with a spike in February, just one day before the invasion when multiple malwares, including HermeticWiper, were deployed against hundreds of Ukrainian government targets, financial, IT and energy institutions. Researchers concluded that eight different wiper malware families were deployed. We estimate these groups started their preparations months earlier, collecting reconnaissance, coordinating targets, gaining access to strategic third-party entities and organizations of interest.Though some APT groups, such as APT28 and Sandworm, have been associated with the Russian GRU, it is unclear whether coordination procedures are in place, or a general target list is simply shared and pursued. What is clear is that Russian offensive actors are aggressively targeting key national entities in Ukraine to disrupt critical services. CHAPTER 2

https://www.cisa.gov/uscert/ncas/alerts/aa22-057ahttps://twitter.com/ESETresearch/status/1496581903205511181https://blogs.microsoft.com/on-the-issues/2022/04/27/hybrid-war-ukraine-russia-cyberattacks/https://blogs.vmware.com/security/2022/03/what-we-know-threat-intelligence-for-gru-backed-cyber-attacks.html

11CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT Just three days after its creation, the Telegram channel had no fewer than 175,000 members. Around that time, Ukraine supporters also started posting requests on underground forums for help in protecting Ukrainian cyberspace. Now, several months into the war, the channel is still active with 262,000 members and is still used to encourage people to help protect Ukrainian critical infrastructure but mostly to promote offensive activities. Attack tools and techniques are shared on a designated website and dozens of Russian targets are published on the channel every day. The channel is also used to publicize successful attacks carried out against Russia, such as replacing the home screen of Russia’s smart TV platform with an anti-war message. This attack, which took place on Russian Victory Day, also affected Rutube and Yandex. The Ukrainian government also leveraged its media presence for fundraising via designated ads on underground forums, with over $26 million already collected.UKRAINIAN OPERATIONS AGAINST RUSSIA—CYBER ARMY KICKSTARTERFrom recruiting personnel, through to selecting toolsets and coordinating operations between government and individuals, the cyber strategy of the Ukrainian forces has been a major surprise. Until now, Russia had the upper hand in the cyber landscape as it is home to some of the most notorious APT groups and naturally, their loyalty lies with the Russian government and intelligence services. After the war started though, most non-state actors including hacktivist groups, white hat hackers and even the infamous Anonymous Collective, sided with Ukraine, pledging to act against Russia in cyberspace.The most interesting part of Ukraine’s cyber defense strategy centers around the global recruitment of keyboard warriors, proactively inviting recruits from both sides of the law to join the offensive efforts in the cyber arena as part of an organized, government-led initiative. During the first few days of the war, the Ukrainian Minister of Digital Transformation, Mykhailo Fedorov, posted on Twitter calling for “digital talents” to join the newly created IT army, with operational tasks being allocated to them via a designated Telegram channel. Figure 1: The initiation of IT Army of Ukraine by the Ukrainian governmentCHAPTER 2

https://blog.checkpoint.com/2022/02/27/how-the-eastern-europe-conflict-polarized-cyberspace/https://blog.checkpoint.com/2022/03/02/telegram-becomes-a-digital-forefront-in-the-conflict/https://www.euronews.com/next/2022/02/26/ukraine-war-ukrainians-announce-the-launch-of-an-it-army-to-fight-off-russian-cyberattacks#:~:text=Ukraine%20will%20create%20an%20%22IT,spying%20missions%20against%20Russian%20troops.https://blog.checkpoint.com/2022/03/17/crypto-fundraising-for-ukraine-found-on-the-darknet-used-by-cyber-criminals-for-fraud/https://www.intezer.com/blog/malware-analysis/russian-apt-ecosystem/https://fortune.com/2022/04/11/anonymous-cyber-war-russia-ukraine/https://twitter.com/fedorovmykhailo/status/1497642156076511233?lang=en

12CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT FUTURE IMPLICATIONSNational political agendas have always been a beacon for state-sponsored APT groups. However, cybercrime groups have traditionally sought mostly financial gain, with the goal of monetization clearly guiding them to select their targets. For the first time in a long time, this situation appears to be changing. The Ukraine war has been pushing cybercriminal collectives and lone hackers to back one of the two sides in the conflict. The Ukraine war has set a precedent, moving the fight to cyberspace and blurring the line between the soldiers on the front and the citizens at home. Should cyber offense be a part of every conflict? Should self-motivated hackers take part in national affairs? All we know for sure is that the cyber landscape is continuing to evolve, as it serves more groups and more agendas.Anonymous Collective, whose goals overlap somewhat with those of the IT army, has also had successes since it declared cyber war against Russia on Twitter. It appears that the collective launched DDoS attacks against corporate, news and state websites, compromised over 90 databases belonging to telecom, retail and government sector organizations, and leaked hundreds of thousands of documents. CHAPTER 2 The formation of a state-sponsored cyber army is unprecedented— never before have we seen a government recruiting independents for a global volunteer organization to be used as its personal cyber army. Knowing that its enemy utilizes some of the best attack groups in the world, and that it has the world’s sympathies due to its underdog role in the conflict, Ukraine found a way to rapidly enlist powerful players from the global cyber field, helping it regain some advantage.

https://www.france24.com/en/europe/20220323-ukraine-conflict-presents-a-minefield-for-anonymous-and-hacktivistshttps://www.theguardian.com/world/2022/feb/27/anonymous-the-hacker-collective-that-has-declared-cyberwar-on-russiahttps://www.cnbc.com/2022/03/16/what-has-anonymous-done-to-russia-here-are-the-results-.htmlhttps://www.websiteplanet.com/blog/cyberwarfare-ukraine-anonymous/

13CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT cybercrime groups will continue to target governments in order to cause maximum disruption and to support the goals of their backers, but that’s not where the money is. They need a steady income stream to replenish their cyber warfare coffers to recruit and invest in the latest technology, and that’s why they continue to target enterprises. However, with the right expertise, strategy and cybersecurity solutions in place, organizations are able to prevent attacks from happening.When the Russia-Ukraine war does come to an end, it’s likely that we will be in a far worse situation than we are now when it comes to cyber. This is because state-sponsored APT groups, hacktivists and other cybercriminals have been able to ‘hone their craft’ during the conflict. There will be more expertise, more tooling and more groups that have consolidated their efforts and will start to look at attacking NATO countries. And it’s not just government departments in those countries that should be concerned, businesses really need to prepare themselves for what’s coming. DERYCK MITCHELSONField CISO, EMEA at Check Point If we think at the end of the conflict that the Russian state-sponsored hackers are suddenly going to disappear, then we are absolutely mistaken. I believe they are only going to increase their intensity and we will see a tsunami of cyberattacks on NATO countries.”CHAPTER 2

14CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT The larger the operation, though, the more difficult it became to stay under the radar as it is difficult to conceal a multi-billion business employing hundreds of skilled workers with offices in major cities. The larger the business, the more it relies on the cooperation or at least passive consent from local authorities. This dependency forces very large threat actors to identify and align with the geopolitical interests in their home countries. Most ransomware groups are very careful to not attack entities in post-Soviet territories, automatically aborting any operations on machines where Russian is the default language.In our previous report, we outlined a change in attitude by international law-enforcement agencies, who intensified their war against ransomware groups. Following high-profile attacks, the US government and other law enforcement agencies adopted a more proactive stance. This included internationally coordinated action against ransomware and cryptocurrency money laundering operations, sanctions and more. The Russian authorities ‘selectively’ cooperated with these moves, detaining some but not others, and releasing them according to their global interests. In January, Russia arrested some members of the REvil ransomware gang, but the group’s blog and Tor network returned to full action by April, strangely coinciding with the war in Ukraine and the ending of collaborations between the US and Russia. COUNTRY EXTORTION—RANSOMWARE GROUPS STEP UP TO NATION STATE ACTOR LEVELJust like with a new life form we have been tracking the evolution of the ransomware parasite through its evolutionary stages. In the last six months, we have witnessed ransomware groups actively stepping up to the level of nation state actors, choosing high-level targets and taking sides in global conflicts. The Conti group, for example, picked fights with entire countries like Costa Rica and Peru, and the newly established Lapsus$ began its malicious activity attacking governmental entities. Not long afterwards, it also successfully went on to target technology giants Microsoft, NVIDIA and Samsung.Initially, ransomware operations were conducted by individuals or small groups distributing random emails and hoping to collect small amounts of ransom from a large array of victims. As they evolved, the groups expanded to have hundreds of employees, with revenue in the hundreds of millions and sometimes billions of dollars. With their wider scope and scale of operations the groups had to start investing in research and development teams, quality assurance departments, HR people, specialist negotiation teams and sometimes even actual offices.CHAPTER 2

https://www.nbcnews.com/politics/national-security/code-huge-ransomware-attack-written-avoid-computers-use-russian-says-n1273222https://research.checkpoint.com/2022/2022-security-report-software-vendors-saw-146-increase-in-cyber-attacks-in-2021-marking-largest-year-on-year-growth/https://www.bbc.com/news/technology-59998925https://therecord.media/researchers-warn-of-revil-return-after-january-arrests-in-russia/https://blog.checkpoint.com/2022/05/11/how-the-evolution-of-ransomware-changed-the-threat-landscape/https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/https://research.checkpoint.com/2022/leaks-of-conti-ransomware-group-paint-picture-of-a-surprisingly-normal-tech-start-up-sort-of/

15CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT Following its political move, Conti increased the rate of attacks. As reported on its shame blog, the group went from ten victims in January to more than 20 in February, over 50 in March, and nearly 80 in April. April also signaled a new stage of “country extortion”, when Conti attempted to extortthe entire country of Costa Rica. The group continued extorting more government entities, continuing with Peru on May 7th. A few days later, on May 12th, Costa Rica’s president declared a state of national emergency, later announcing the country was at war with Conti - the first time ever that a country has declared war on a cybercrime group. This extraordinary situation came about after the cybercriminals breached and encrypted the data of at least 27 Costa Rica government agencies, probably the most disruptive cyberattack ever inflicted on any country, including those by another government.Shortly after the war started, Conti expressedits full support for the Russian government and threatened to retaliate with all its resources against “any enemy” that attacks Russian organizations. Conti took the ransomware threat to its highest level, transforming itself into an actor in the geopolitical arena, with cyber offensive weapons capable of causing serious damage to the critical infrastructures of many nation states. Conti’s declaration had immediate repercussions. Two days later, a new Twitter account called “Conti Leaks” was created by an individual who claimed to be a Ukrainian researcher and who started leaking the group’s internal communications. The leak contained nearly 170,000 messages as well as malware source code, which amounted to an unprecedented exposure of the operation and its internal strategies. Check Point Research (CPR) analyzed the Conti leaks and discovered the different layers and hierarchy that you might find in a typical high-tech company with clearly defined roles and departments.Figure 2: Conti ransomware group announcement from their site.CHAPTER 2

https://blog.checkpoint.com/2022/05/26/country-extortion-ransomware-expands-business-to-the-governmental-sector/https://securityaffairs.co/wordpress/131093/cyber-crime/conti-ransomware-peru-direccion-general-de-inteligencia.htmlhttps://www.bleepingcomputer.com/news/security/costa-rica-declares-national-emergency-after-conti-ransomware-attacks/https://www.cyberscoop.com/conti-ransomware-russia-ukraine-critical-infrastructure/https://research.checkpoint.com/2022/leaks-of-conti-ransomware-group-paint-picture-of-a-surprisingly-normal-tech-start-up-sort-of/

16CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT in a ransomware attack, focusing only on data exfiltration and extortion based solely on the threat of publication. This revival of an old phenomenon could be the start of a new trend as the tactics have since been adopted by the RansomHouse group and Karakurt, the data extortion group related to Conti. Apparently, data exfiltration is much easier than encrypting an entire network and then assisting with decryption when the ransom is paid. Threat actors are clearly finding ways to do less work for more money.After Costa Rica decided to not pay the ransom, the group publicly declared its intentions to overthrow the government and called for citizens to revolt, stating it would carry out similar operations in the future. In May, the US offered a bounty of ten million dollars for information that would lead to the arrest of Conti’s leaders.While Conti brought about the new method of ‘country extortion’, Lapsus$ reintroduced an old one and was able to get its hands on proprietary information and source code belonging to the biggest technology companies. Surprisingly, the group’s modus operandi excludes the usual encryption element you would expect to see CHAPTER 2 Large threat actors are under a lot of pressure to avoid detection, which could explain their tendency to “rebrand” their ventures. Disbanding an existing operation and later reassembling it under a different name is meant to hinder any investigations. Some observers claimed that Conti’s current international actions are a smoke screen, leading up to another rebrand. Regardless of the outcome, these events prove that it is possible to extort an entire country and that a cybercrime organization can evolve into a geopolitical actor. The inclination to rebrand and change operation tactics creates fertile ground for the continued emergence of new groups and new operation methods." LOTEM FINKELSTEEND i r e c to r, Threat Intelligence and Research

https://cyberint.com/blog/research/ransomhouse/https://www.cisa.gov/uscert/ncas/current-activity/2022/06/01/karakurt-data-extortion-grouphttps://blog.checkpoint.com/2022/03/22/lapsuss-okta-the-cyber-attacks-continue/

17CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT “Macros automate frequently used tasks to save time... Many were created by using Visual Basic for Applications (VBA) and are written by software developers. However, some macros can pose a potential security risk. Macros are often used by people with malicious intent to quietly install malware, such as a virus, on your computer or into your organization's network.”Although PoC and active exploits using VBA macros appeared as early as 1995, they lacked info-stealing functionality and were mostly used for pranks. These types of attacks died out in 2010 when Microsoft introduced “Protected view”, a yellow ribbon warning users not to enable macros’ functionality. The use of macros was re-introduced when threat actors realized that, with a bit of social engineering, they could convince users to enable macros and then use them to download and execute other binaries. MICROSOFT BLOCKS INTERNET MACROS IN OFFICE—THEDEVELOPMENTS IN THE EMAIL INFECTION CHAINSWhy do 34% of burglars enter homes through the front door? Because every home has one, and very often, they are left wide open. For many years, MS Office documents have been our digital front doors. Everyone uses them, mostly without questioning their source, which makes them a very widely open door indeed.The malicious use of Microsoft docs occurs so frequently that they have a name - maldocs. One of the main techniques to create maldocs involves the abuse of Office Macros, which are a highly versatile tool with extensive programing capabilities. Security companies have been fighting this for years, but it was always clear that the key to preventing macro abuse lies in the hands of Microsoft. Indeed, in February 2022 Microsoft announced it would change Office default settings to disable. Office macros are special purpose programs and, as stated on Microsoft’s support page, are often used for malicious purposes: Figure 3: Typical label designed to convince victim to enable macros.CHAPTER 2

https://research.checkpoint.com/2022/the-death-of-please-enable-macros-and-what-it-means/https://www.asecurelife.com/security-infographic/https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805https://support.microsoft.com/en-us/office/macros-in-office-files-12b036fd-d140-4e74-b45e-16fed1a7e5c6

18CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 11%16%17%36%67%89%84%83%64%33%20182019202020212022-H1WebMailAlthough Microsoft acknowledged the issue multiple times, the malicious use of Office macros and vulnerabilities increased in popularity throughout the years. By January 2022, our analysis found that as much as 61% percent of all malicious payloads attached to emails sent to our clients were various document types (such as xlsx, xlsm, xls, docx, doc, ppt, pdf, rtf and others). Our current report finds that Excel files alone made up 49% of all malicious files received by email! This trend corresponds with the evident tendency of most actors to use email (SMTP) instead of web-based sites as their initial attack vector. Typically, a carefully socially engineered email carrying an Excel file with a malicious macro is the weapon of choice for non-sophisticated actors as well as top niche A P Ts.Figure 5: Increase in proportion of malicious files sent by email.Figure 4: Percentage of Excel files of the total malicious files received by email.11%23%30%49%xls2019202020212022-H1CHAPTER 2 Although Microsoft acknowledged the issue multiple times, the malicious use of Office macros and vulnerabilities increasedin popularity throughout the years. By January 2022, our analysis found that as much as 61% percent of all malicious payloads attached to emails sent to our clients were various document types (such as xlsx, xlsm, xls, docx, doc, ppt, pdf, rtf and others). Our current report finds that Excel files alone made up 49% of all malicious files received by email!"ITAY COHENGroup Manager,Cyber Research

https://support.microsoft.com/en-us/office/macros-in-office-files-12b036fd-d140-4e74-b45e-16fed1a7e5c6https://blog.checkpoint.com/2022/05/19/twisted-panda-check-point-research-unveils-a-chinese-apt-espionage-campaign-against-russian-state-owned-defense-institutes/https://support.microsoft.com/en-us/office/macros-in-office-files-12b036fd-d140-4e74-b45e-16fed1a7e5c6

19CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT files. Xll files are .dll libraries designed for Excel, and threat actors typically use an exported xlAutoOpen function to download and run malicious payloads. Various existing tools and services, such as Excel-DNA, are already available to build .xll downloaders. Another possible alternative TTP to maldocs is the use of ISO archives, which bypass the MOTW mechanism. Together with a combination of .hta payload, they can look like documents but run malicious code in the background. We already saw a rise in attacks using these archives. Bumblebee, a new downloader detected in February, delivers various payloads that often result in ransomware attacks, and is reported to initially involve .iso files delivered in email.Blocking Office internet macros does not eliminate maldoc options. Threat actors continue to exploit vulnerabilities. (CVE-2021-40444) and the newly-discovered Follina, which use HTML template injection, are just recent examples. Threat actors will continue to find new ways to deliver malware, but this policy update by Microsoft is certainly going to have an effect on current TTPs. Both security providers and users should prepare accordingly.Only recently, CPR reviewed a series of attacks by various APT groups, who socially engineered their attacks using articles on the current Russian war against Ukraine to send weaponized Word documents. Other major malware families using malicious Office documents include TrickBot, Qbot, Dridex and many more. The unofficial king of maldoc usage is Emotet, which routinely sends high volumes of maldocs through email, sometime concealed inside password-protected zip files, to expend its botnet.In February this year, Microsoft announcedits intention to block VBA macros on Office docs. They will present users with a series of alerts and ultimately require them to save files locally and turn off the Mark of the Web (MOTW) protection mechanism. This is in addition to its previous policy change, in which Microsoft restricted the use of Excel 4.0 macros. The policy change is planned to roll out in the coming months. Following these announcements, threat actors began examining the alternatives for non-executable malicious email attachments. Emotet was reported in April to be testing new TTPs (Tactics, Techniques, and Procedures), emailing OneDrive URL links of Zip files containing malicious xll CHAPTER 2

https://threatresearch.ext.hp.com/how-attackers-use-xll-malware-to-infect-systems/https://blog.checkpoint.com/2022/05/10/a-german-car-attack-on-german-vehicle-businesses/https://www.proofpoint.com/us/blog/threat-insight/bumblebee-is-still-transforminghttps://www.sentinelone.com/blog/peeking-into-cve-2021-40444-ms-office-zero-day-vulnerability-exploited-in-the-wild/https://www.sentinelone.com/blog/peeking-into-cve-2021-40444-ms-office-zero-day-vulnerability-exploited-in-the-wild/https://blog.checkpoint.com/2022/05/31/follina-zero-day-vulnerability-in-microsoft-office-check-point-customers-remain-protected/https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/https://research.checkpoint.com/2021/when-old-friends-meet-again-why-emotet-chose-trickbot-for-rebirth/https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805https://techcommunity.microsoft.com/t5/excel-blog/excel-4-0-xlm-macros-now-restricted-by-default-for-customer/ba-p/3057905https://threatpost.com/emotet-back-new-tricks/179410/

20CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT • April—Pegasus was revealed to have been detected on multiple official UK networks, including the Prime Minister’s office. • May—Pegasus was confirmed to have been found on devices belonging to the Spanish Prime Minister and Defense Minister.Fortunately, Apple announced in July that it is introducing a ‘lockdown mode’ for its devices in order to protect against Pegasus hacks. But while Pegasus is one of the most powerful tools currently on the market, the surveillance vendor ecosystem has also become more competitive. Another marketed spyware called Predator, produced by the North Macedonian commercial surveillance company Cytrox, was found to have infected iPhones towards the end of 2021 via single click links sent over WhatsApp. As of today, the reach of these tools, let alone their mechanisms, is not yet fully understood by the cyber community despite extensive research efforts. SCOPE OF THE MOBILE MALWARE LANDSCAPE In an age when we increasingly rely on third-party applications and connect corporate networks to employees’ personal devices, mobile devices have become valuable targets, requiring us to invest resources in mobile protection. The mobile marketplace’s exponential growth over the past few years offers a wider range of opportunities for threat actors. This potential is being exploited to its fullest, as we see malicious actors investing efforts in more advanced techniques and innovative social engineering schemes, rivaling the threat landscape for PCs. Our last security report addressed Pegasus, the notorious NSO group Spyware which made headlines in 2021 after the discovery that the tool was used to gain access to mobile devices belonging to government officials, journalists, human rights activists and business executives worldwide. Additional Pegasus campaigns were uncovered in the first half of 2022:• January—Pegasus was found to have infected new governmental targets in Finland’s Ministry of Foreign Affairs, targeting Finnish diplomats as part of a cyberespionage campaign. CHAPTER 2

https://www.reuters.com/world/uk/watchdog-warned-uk-government-spyware-infections-inside-10-downing-street-2022-04-18/https://www.theguardian.com/world/2022/may/02/spain-prime-minister-pedro-sanchez-phone-pegasus-spywarehttps://www.theguardian.com/technology/2022/jul/06/apple-to-launch-lockdown-mode-to-protect-against-pegasus-style-hackshttps://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/https://threatpost.com/nso-group-pegasus-spyware-finnish-diplomats/178113/

21CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT found that threat actors used five zero-day vulnerabilities and other known unpatched flaws to install the Predator malware as part of three campaigns that occurred between August and October 2021. In addition to politically and ideologically driven spyware actors, we have also observed financially motivated operations like Flubot. Since its emergence in December 2020, it has been considered the fastest growing Android botnet ever seen. Flubot’s success is partly due to its spreading technique called “Smishing” (SMS Phishing), which uses SMS messages as the attack vector for malware distribution. It sends the same SMS to the initial victim’s contacts, resulting in exponential spread. In February, researchers found that one of the same vulnerabilities in Apple software exploited by the NSO group in iPhones wassimultaneously leveraged by a competing firm called QuaDream. Zero-click vulnerabilities allow a remote intrusion into iPhones without any action needed by the victim, such as clicking a malicious link, to trigger an infection. Later in April, a new zero-click iMessage exploit leveraged to install Pegasus on iPhones was discovered, running on some early iOS versions prior to 13.2. The exploit named HOMAGE was used in a campaign against Catalan officials, journalists and activists. In this campaign, some victims were also infected with Candiru spyware, from yet another mercenary hacking company. Finally, in May, security researchers CHAPTER 2 In May 2022, CPR discovered that MediaTek and Qualcomm, the two largest mobile chipset makers, ported the vulnerable ALAC code into their audio decoders, which are used in more than half of all smartphones worldwide. The ALAC issues found by CPR could be used by an attacker for remote code execution on a mobile device through a malformed audio file. In addition, an unprivileged Android app can use these vulnerabilities to escalate privileges and gain access to media data and user conversations.

https://www.bleepingcomputer.com/news/security/google-predator-spyware-infected-android-devices-using-zero-days/https://www.jpost.com/business-and-innovation/tech-and-start-ups/article-695389https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/https://research.checkpoint.com/2022/bad-alac-one-codec-to-hack-the-whole-world/

22CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT security measures with different tactics such as manipulating their code to pass through the filters or introduce initially benign applications and add the malicious elements at a later stage.It’s not so surprising to still find malicious applications hiding in these stores. In fact, these platforms remain the main infection vectors in mobile threats. For example, CPR recently analyzed suspicious applications on the Google Play Store and found a few of them masquerading as genuine Anti-Virus solutions, while in reality, once downloaded the apps installed an Android Stealer called SharkBot which steals credentials and banking information. SharkBot implements a geofencing feature, Domain Generation Algorithm (DGA), and evasion techniques that make it stand out in the field. SharkBot distribution is not widespread but rather targeted: it selects victims using the geofencing feature to identify and ignore users from China, India, Romania, Russia, Ukraine or Belarus.In February, a new Android banking Trojan called Xenomorph was spotted lurking behind a fake productivity application on the Google Play Store. There were over 50,000 downloads. The Xenomorph malware has a lot of potential to evolve, as it currently uses classic overlay attacks and has the ability to steal credentials along with intercepting SMS and notification to log and use two-factor authentication (2FA) tokens. It’s evident that threat actors will continue to try and leverage official stores.The Flubot gang is known to be particularly innovative and continuously seeking to improve its variants, using features that are ordinarily seen in the development of PC malware rather than mobile. Those features include DNS tunneling or Domain Generation Algorithm (DGA), which make detection and shut down more difficult. With its multiple campaigns and tens of thousands of victims, Flubot received so much attention that in June, an international law enforcement operation involving 11 countries led to its infrastructure takedownand rendered the malware inactive. Evidently, Flubot’s position could not remain vacant for too long, as a new Android malware operation called MaliBot emerged in the wild soon after. MaliBot is targeting online banking and cryptocurrency wallets in Spain and Italy, using the same smishing distribution method as Flubot. At the other end of the mobile threat spectrum are application stores, which encapsulate a whole arena of their own for cybercriminals. The most secured stores like the Google Play Store and the Apple App Store have thorough review processes to investigate candidate applications before they are uploaded and are held to high security standards once they are admitted onto the platforms. A recent reportstated that throughout 2021, Google blocked 1.2 million suspicious applications from the Google Play Store, and Apple blocked 1.6 million apps from their App Store. Resourceful cybercriminals continually try to bypass these CHAPTER 2

https://research.checkpoint.com/2022/google-is-on-guard-sharks-shall-not-pass/https://www.threatfabric.com/blogs/xenomorph-a-newly-hatched-banking-trojan.htmlhttps://www.f5.com/labs/articles/threat-intelligence/flubots-authors-employ-creative-and-sophisticated-techniques-to-achieve-their-goals-in-version-50-and-beyondhttps://www.europol.europa.eu/media-press/newsroom/news/takedown-of-sms-based-flubot-spyware-infecting-android-phoneshttps://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibothttps://www.zdnet.com/article/apple-these-are-the-sorts-of-apps-we-blocked-from-our-app-store-last-year/

23CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT Log4Shell, a vulnerability in Apache’s most popular Java logging library, Log4j, that allowsthreat actors to easily gain control over Java-based web servers and execute arbitrary code. It seems we are now gearing up for when supply chain attacks meet the cloud arena. On March 21st, the notorious ransomware gang Lapsus$ released a statement in its Telegram group that said it had gained access to Okta, an identity management platform, by obtaining access to an administrative account. Lapsus$ is known for publishing sensitive information, often source code, stolen from high-profile tech companies such as Microsoft, NVIDIA, and Samsung. However, this time, the target wasn’t Okta, but rather its customers. Okta, a cloud-based software, is used by thousands of companies to manage and secure user authentication processes as well as by developers to build identity controls. This means that hundreds of thousands of users worldwide could be potentially compromised by the company responsible for their security. Unfortunately, cybercriminals are well aware of the central role that mobile devices play in many peoples’ lives and are always adapting and improving their tactics to match. The threat landscape is evolving rapidly, and mobile malware is a significant danger for both personal and enterprise security.CLOUD SUPPLY CHAIN AT TACK SFor the past few years, CPR has been following the evolution of the cloud threat landscape, as well as the constant increase in cloud infrastructure adoption by corporate environments. As many as 98% of organizations utilize cloud-based services, and approximately 76% of them have multi-cloud environments, featuring services from two or more cloud providers. In March 2022, we released a review of the latest cloud trends and attacks on industry-leading cloud service providers. Critical vulnerabilities were exploited by cybercriminals to gain access to the corporate environments of the cloud provider’s entire customer list. We also covered the unprecedented progress made by cybercriminals in the field of supply chain attacks, from the SolarWinds Orion software breach—an innovative on-premise-to-cloud incident in which a backdoor embeddedin a software update was leveraged to gain access to private cloud environments—to the Figure 6: Lapsus$ announcement about OKTA, on their Telegram channel.CHAPTER 2

https://www.checkpoint.com/latest-cyber-attacks/critical-vulnerability-in-apache-log4j/https://www.reuters.com/technology/authentication-services-firm-okta-says-it-is-investigating-report-breach-2022-03-22/https://blog.checkpoint.com/2022/03/22/lapsuss-okta-the-cyber-attacks-continue/https://www.msspalert.com/cybersecurity-breaches-and-attacks/ransomware/alleged-lapsus-cyberattack-victim-list-grows-microsoft-nvidia-okta-samsung-more/https://techcrunch.com/2022/03/23/microsoft-lapsus-hack-source-code/https://analyticsindiamag.com/lapsus-hack-leaves-nvidia-in-a-tight-spot/https://threatpost.com/samsung-lapsus-ransomware-source-code/178791/https://blog.checkpoint.com/2022/03/22/okta-breached-by-lapsus-ransomware-gang/https://blog.checkpoint.com/2022/04/18/the-biggest-cloud-security-challenges-in-2022-check-point-software/https://blog.checkpoint.com/2022/03/16/cloud-services-under-attack-closing-the-virtual-open-doors-to-cyber-crime/https://www.securityweek.com/attacks-targeting-omigod-vulnerability-rampinghttps://research.checkpoint.com/2020/sunburst-teardrop-and-the-netsec-new-normal/https://research.checkpoint.com/2021/solarwinds-explained/https://research.checkpoint.com/2021/solarwinds-explained/

24CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT Although the statements were probably released to reassure Okta’s customers, they only contributed to the general fear caused by the attack. Lapsus$ commented on the statements, or as it called them, “the lies given by Okta”, on its popular Telegram channel. Lapsus$ assured its 35,000 followers that the successful breach allowed the attack group to “log in to superuser portal with the ability to reset the password and MFA of ~95% of clients”.CPR suggested that the access Lapsus$ had gained to Okta clients might possibly explain the cybercrime gang’s modus operandiand impressive record of successes, all thanks to excessive permissions having been granted to a third-party within the corporate cloud environment. Curiously, on March 22nd, Okta released an official statement claiming that an investigation concluded that a breach did not occur, although an unsuccessful compromise attempt was observed in January 2022, when a new factor was added to the Okta account of a client’s support engineer. At that point, no notification was sent to Okta’s customers. However, another statement released in close proximity to the first one, shared that approximately 2.5% of Okta’s customers were affected by the Lapsus$ breach—around 375 companies, according to a media report. CHAPTER 2STUART GREENCloud Security ArchitectCheck Point The two biggest concerns I’m seeing in the cloud landscape in 2022 are vulnerabilities within cloud providers themselves and modules in the open-source community that are not properly vetted or managed.”

https://techmonitor.ai/technology/cybersecurity/lapsus-okta-attack-supply-chain-cybersecurityhttps://securityaffairs.co/wordpress/129422/data-breach/okta-says-375-customers-impacted-by-data-breach.htmlhttps://blog.checkpoint.com/2022/03/22/lapsuss-okta-the-cyber-attacks-continue/https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/https://www.forbes.com/sites/thomasbrewster/2022/03/22/fury-as-okta-the-company-that-manages-100-million-logins-fails-to-tell-customers-about-breach-for-months/?sh=79c1ad987341

25CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT you’re importing one thing, but it actually has dependencies that you aren’t aware of. This is how NotPetya came about. It infiltrated computer systems using a popular piece of open-source accounting software. Unfortunately, when it comes to your chosen cloud provider, you can’t control the security of the platform itself. And these platforms do have vulnerabilities. You could have the best will in the world and the highest expertise, but unless you’ve got a team of analysts constantly researching the platform you’re using, it’s not going to be enough. This really makes the case for multiple layers of security. You might not be able to prevent a breach of the cloud provider itself, but what you are able to do is mitigate the fallout. Implementing things like zero-trust and least privilege will mean that in the event of a breach, it is contained and cannot spread. Identity and Access Management (IAM) role abuse attacks were thoroughly discussed by CPR in 2021, and while still an ongoing issue, there are other risks that businesses need to be aware of. While the Okta breach wasn’t necessarily a ‘cloud supply chain attack’—this would be when a cloud provider such as Azure or AWS is compromised—it was a significant event fromthe first half of this year that did affect the supplychain and will hopefully teach businesses some important IAM lessons. Currently, the most prominent supply chain risk we are seeing comes from open-source software. Many modules and packages are written by individuals who may not have the expertise or budget to make it completely secure. Then when the ‘unsecure’ code is contributed to the open-source community, who owns it? Who maintains it? As a developer, you might think CHAPTER 2

https://blog.checkpoint.com/2021/05/05/check-your-privilege-the-risks-of-privilege-escalation-in-the-cloud/

26CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT CHAPTER 3CYBER AT TACK CATEGORIESBY REGION03 IN THE FIRST HALF OF THE YEAR, THERE WAS A 42% INCREASE IN WEEKLY CYBERATTACKS GLOBALLY WITH EVERY REGION EXPERIENCING A SIGNIFICANT ESCALATION.

27CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 27GLOBALAMERICASMULTIPURPOSE MALWARE*CRYPTOMINERSINFOSTEALERMOBILERANSOMWARE23%15%13%12%8%MULTIPURPOSE MALWARE*CRYPTOMINERSINFOSTEALERMOBILERANSOMWARE19%11%9%11%6%Figure 7: Percentage of corporate networks attacked by each malware type globally.CYBER ATTACK CATEGORIES BY REGIONFigure 8: Percentage of corporate networks attacked by each malware type in the Americas.\* Banking Trojans and botnets, previously classified as two distinct types, are combined in a single category. As many banking Trojans received additionalfunctionalities, making the differentiation between the two categories less distinct, we introduce the category “multipurpose malware” to include both genres.27CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORTCHAPTER 3

28CHECK POINT SOFTWARE|SECURITY REPORT 2022EMEAAPACMULTIPURPOSE MALWARE*CRYPTOMINERSINFOSTEALERMOBILERANSOMWARE23%14%14%12%8%MULTIPURPOSE MALWARE*CRYPTOMINERSINFOSTEALERMOBILERANSOMWARE31%25%17%15%12%CYBER ATTACK CATEGORIES BY REGIONFigure 9: Percentage of corporate networks attacked by each malware type in EMEA.Figure 10: Percentage of corporate networks attacked by each malware type in APAC.\* Banking Trojans and botnets, previously classified as two distinct types, are combined in a single category. As many banking Trojans received additionalfunctionalities, making the differentiation between the two categories less distinct, we introduce the category “multipurpose malware” to include both genres.28CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORTCHAPTER 3

29CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 29GLOBAL THREAT INDEX MAPFigure 11: Global Threat Index Map* Darker = Higher Risk * Grey = Insufficient DataThe map displays the cyber threat risk index globally, demonstrating the main risk areas around the world.*CHAPTER 3OMER DEMBINSKYData Research Group Manager The biggest change this year regarding cyberattack categories comes from ransomware. Each region is facing more of these types of attacks, with APAC leading the way (12% of organizations compared to 4% in H1 2021). It is no surprise really when we look at how ransomware actors have evolved this year, and unfortunately it looks set to get worse."

30CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 302297(+44%)Education / ResearchGovernment / MilitaryISP / MSPCommunicationsHealthcareFinance / BankingUtilitiesManufacturingSI / VAR / DistributorInsurance / LegalLeisure / HospitalitySoftware VendorTransportationRetail / WholesaleConsultantHardware Vendor166914571425138711231090989968957969777754767703419(+48%)(+38%)(+33%)(+69%)(+62%)(+49%)(+42%)(+26%)(+53%)(+65%)(+47%)(+52%)(+47%)(+23%)(+15%)Figure 12: Average weekly attacks per organization by Industry H1 2022 compared to 2021.Similar to what we saw in our 2021 top industry ranking, the first half of 2022 displays significant rises in attacks against all sectors alike. Education and Research still leads as the most targeted industry, with an average of 2,297 attacks against organizations every week showing a 44% increase compared to 2021. In addition, Healthcare is still one of the most targeted sectors globally, with a 69% increase compared to 2021. This is the highest increase of all industries, going hand-in-hand with the multiple breaches of different ranges we observed against healthcare organizations during that period.CHAPTER 3

31CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 31exepdfxlsxxlsdocshjarbatxlsblnk45%21%5%5%3%3%2%2%2%2%EMAIL WEB201964%36%201867%33%202083%17%202184%16%2022-H189%11%Figure 13: Delivery Protocols—Email vs. Web Attack Vectors in 2018-2022. Figure 14: Web—Top malicious file types.TOP MALICIOUS FILE TYPES—WEB VS. EMAILCHAPTER 3

32CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 32exepdfxlsxlsxxlsmdocdocxrtflnkppt22%20%19%16%15%3%2%1%0.4%0.3%Figure 15: Email—Top malicious file types.The proportion of email-delivered-attacks has gradually risen to reach a staggering record of 89% of all in-the-wild attacks. Email-delivered attacks typically include socially engineered content, intended to convince recipients to open an attachment, often a PDF or Office file (75% of attachments). Many mass distributed campaigns, with Emotet being the most extensive, use this tactic. However, as important as user awareness and email protection solutions are, it is not enough to ensure full protection. Data collected from the Check Point Incident Response Team (see the last chapter in this report) shows that from cases handled by our IR team, with a known entry point, only 17% of successful breaches originated from SMTP attack. This puts an extra emphasis on alternative attack vectors and the importance of rapid protection publication and vulnerability patching.CHAPTER 3

33CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT CHAPTER 4GLOBALMALWARE STATISTICS04 DATA COMPARISONS PRESENTED IN THE FOLLOWING SECTIONS OF THIS REPORT ARE BASED ON DATA DRAWN FROM THE CHECK POINT THREATCLOUD CYBER THREAT MAP BETWEEN JANUARY AND JUNE 2022.

34CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 34EmotetFormbookAgentTeslaXMRigRemcosRamnitLokibotGluptebaPhorpiexTofsee11.7%5.5%2.9%2.7%2.5%2.5%2.3%2.1%1.7%1.5%EmotetFormbookRemcosXMRigAgentTeslaGluptebaPhorpiexRamnitTrickbotVidar8.6%4.2%2.3%1.9%1.5%1.4%1.3%1.2%1.1%1.1%TOP MALWARE FAMILIESFigure 16: Most prevalent malware globally.Percentage of corporate networks attacked by each malware family.Figure 17: Most prevalent malware in the Americas.GLOBALAMERICASGLOBAL MALWARE STATISTICSData comparisons presented in the following sections of this report are based on data drawn from the Check Point ThreatCloud Cyber Threat Map between January and June 2022.For each of the regions below, we present the most prevalent malware. CHAPTER 4

https://threatmap.checkpoint.com/ThreatPortal/livemap.html

35CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 35EmotetFormbookAgentTeslaLokibotXMRigRemcosQbotTofseeRamnitGlupteba13.5%6.0%3.6%2.7%2.7%2.5%2.2%1.8%1.7%1.6%EmotetFormbookRemcosXMRigAgentTeslaGluptebaPhorpiexRamnitTrickbotVidar15.2%7.4%4.0%3.4%2.6%2.5%2.4%2.2%2.0%1.9%Figure 18: Most prevalent malware in EMEA.Figure 19: Most prevalent malware in APAC.EUROPE, MIDDLE EAST AND AFRICA (EMEA)ASIA PACIFIC (APAC)CHAPTER 4

36CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT CHAPTER 5TOPMALWARE FAMILIES05GLOBAL ANALYSIS OF TOP MALWARE

37CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 37The Emotet botnet has re-claimed its rightful place at the top of the global top malware chart. In our last yearly report summarizing 2021, Emotet fell to 4th place in the chart, but still impacting approximately 5% of corporate networks worldwide. In the last couple of years, Emotet has been on quite a journey. In early 2021, the malware was taken down in a global operation involving multiple law enforcement agencies and national authorities, in which researchers gained control of its infrastructure. By the end of the year, however, Emotet was back in business. Within two months, the malware resumed operating at approximately 50% of its former attack volume, relying on Trickbot—yet another botnet superpower—as its dropper. Since the end of 2021 and well into 2022, Emotet has been continuously active, carrying out spam campaigns of all kinds. These include a campaign targeting IKEA employees using the thread hijacking technique which relies on legitimate internal corporate emails; a US phishing campaign impersonating the IRS during the 2022 tax season; a financial theft campaign aimed at collecting credit card information stored on Google Chrome; and many more. Emotet operators even managed to recover quickly from the launch a faulty campaign using a broken installer preventing victim infection. It is therefore not surprising that according to data collected by CPR, Emotet has impacted approximately 12% of all corporate networks globally.In the first half of 2022, we saw the demise of a significant malware family—Trickbot. In our report, summarizing 2021, Trickbot claimed the first place in the global malware chart, with an impact of approximately 11% on all corporate networks. In February, the Banker-turned-Botnet’s operators shut down their attack infrastructure, following months of inactivity, with no new campaigns observed by CPR in early 2022 after its delivery of Emotet. Finally, Dridex, another prominent botnet, left the top chart for the first time in years. The botnet was originally developed as a credential-stealing malware utilizing malicious macros. CHAPTER 5

https://www.europol.europa.eu/media-press/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-actionhttps://research.checkpoint.com/2022/2022-security-report-software-vendors-saw-146-increase-in-cyber-attacks-in-2021-marking-largest-year-on-year-growth/https://research.checkpoint.com/2021/when-old-friends-meet-again-why-emotet-chose-trickbot-for-rebirth/https://www.bleepingcomputer.com/news/security/emotet-growing-slowly-but-steadily-since-november-resurgence/https://www.bleepingcomputer.com/news/security/ikea-email-systems-hit-by-ongoing-cyberattack/https://www.bleepingcomputer.com/news/security/emotet-malware-campaign-impersonates-the-irs-for-2022-tax-season/https://www.bleepingcomputer.com/news/security/emotet-malware-now-steals-credit-cards-from-google-chrome-users/https://www.bleepingcomputer.com/news/security/emotet-malware-infects-users-again-after-fixing-broken-installer/https://therecord.media/trickbot-gang-shuts-down-botnet-after-months-of-inactivity/https://www.checkpoint.com/press/2022/february-2022s-most-wanted-malware-emotet-remains-number-one-while-trickbot-slips-even-further-down-the-index/https://www.checkpoint.com/press/2022/january-2022s-most-wanted-malware-lokibot-returns-to-the-index-and-emotet-regains-top-spot/

38CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 3826%12%5%5%45%4%3%EmotetFormbookRamnitGluptebaPhorpiexQbotOther28%13%5%4%4%4%EmotetFormbookGluptebaPhorpiexRamnitTrickbotOther43%28%12%4%4%3%3%EmotetFormbookQbotRamnitGluptebaPhorpiexOther45%EmotetFormbookGluptebaPhorpiexRamnitTrickBotOther28%13%5%4%4%43%4%Figure 20: Most prevalent multipurpose malware globallyFigure 22: Most prevalent multipurpose malware in EMEAGLOBALFigure 21: Most prevalent multipurpose malware in the AmericasFigure 23: Most prevalent multipurpose malware in APACAMERICASEUROPE, MIDDLE EAST AND AFRICA (EMEA)ASIA PACIFIC (APAC)TOP MULTIPURPOSE MALWARECHAPTER 5

39CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 39MULTIPURPOSE MALWARE GLOBAL ANALYSISWe combined banking Trojans and botnets, previously classified as two distinct types into a single category. As many banking Trojans received additional functionalities, which makes the differentiation between the two categories less distinct, we introduce the unified category, “multipurpose malware.”In 2022, Glupteba is one of the most dominant multipurpose malware families in the wild, taking the 3rd place in the chart with involvement in approximately 5% of all corporate networks. This malware features a variety of capabilities including a rootkit, a router attack tool, a credential stealer, a crypto miner and more. However, Glupteba is best known for its unique use of the BitCoin blockchain technology as its C&C infrastructure to receive configuration information. Glupteba’s high activity rate in 2022 is curious since in December 2021, Google carried out a takedown operation to put a halt to its attack activities. The operation involved both legal and technical steps. First, the company, in collaboration with industry partners, disrupted key C&C infrastructure to halt the communications between the botnet operators and its infected bots. Glupteba’s innovative C&C technology allows it to swiftly find an alternative C&C server by scanning the blockchain—composed of hundreds of thousands of servers daily taking part in BitCoin transactions—in case its current server is shut down. The technological complexity of the botnet’s communication method led Google to incorporate legal steps into the operation. The company took part in a civil lawsuit against the alleged operators of the blockchain-enabled botnet. Despite the large-scale operation, in March 2022 a new massive campaign involving Glupteba and Trickbot was observed by researchers. The campaign targeted MikroTik routers and was designed to form a botnet-as-a-service infrastructure.CHAPTER 5

https://nakedsecurity.sophos.com/2020/06/24/glupteba-the-bot-that-gets-secret-messages-from-the-bitcoin-blockchain/https://blog.google/technology/safety-security/new-action-combat-cyber-crime/https://blog.google/threat-analysis-group/disrupting-glupteba-operation/https://www.techtarget.com/searchsecurity/news/252510609/Google-takes-action-against-blockchain-based-Glupteba-botnethttps://decoded.avast.io/martinhron/meris-and-trickbot-standing-on-the-shoulders-of-giants/

40CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 40FormbookAgentTeslaLokibotVidarNanocoreSnakeKeyloggerOther28%15%11%7%25%7%6%35%12%9%7%5%7%FormbookAgentTeslaVidarLokibotNanocoreAZORultOther26%FormbookAgentTeslaLokibotSnakeKeyloggerNanocoreVidarOther27%16%12%7%7%6%25%FormbookAgentTeslaVidarLokibotNanocoreAZORultOther35%12%9%7%7%26%5%Figure 24: Top infostealer malware globallyFigure 26: Top infostealer malware in EMEAGLOBALFigure 25: Top infostealer malware in the AmericasFigure 27: Top infostealer malware in APACAMERICASEUROPE, MIDDLE EAST AND AFRICA (EMEA)ASIA PACIFIC (APAC)TOP INFOSTEALER MALWARECHAPTER 5

41CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 41INFOSTEALER MALWARE GLOBAL ANALYSIS Still topping the chart is Formbook, a commodity infostealing malware sold as-a-service on underground forums since 2016 and is designed to collect information via keylogging. In March, a malicious campaign involving Formbook was found to be targeting Ukrainians with spams, luring victims with fake funding approval letters from the government. Shortly afterwards in April, CPR detecteda peak in Formbook’s activity.The Snake Keylogger modular .NET keylogger/infostealer is a first-time entrant in our chart. Snake first surfaced around late 2020, and quickly grew in popularity among cyber criminals. Snake’s main functionalities include recording keystrokes, taking screenshots, harvesting credentials and clipboard content, in addition to supporting exfiltration of the stolen data by both HTTP and SMTP protocols. It is usually spread through emails that contain DOCX or XLSX attachments with malicious macros. However, in May researchers reported that Snake Keylogger was spreading through PDF files. This could be due in part to Microsoft blockingby default internet macros in Office, compelling cybercriminals to explore new file types such as PDFs. Finally, we note that the popular Raccoon stealer left the ranks. A report in March stated that a key member of the malware as-a-service operation was possibly affected by the conflict in Eastern Europe, and temporarily suspended all activities. Nevertheless, Raccoon resurfaced in June with the newly developed Raccoon Stealer V2 integrating improvements and new features.CHAPTER 5

https://blog.malwarebytes.com/threat-intelligence/2022/03/formbook-spam-campaign-targets-citizens-of-ukraine%EF%B8%8F/https://blog.checkpoint.com/2022/05/11/april-2022s-most-wanted-malware-a-shake-up-in-the-index-but-emotet-is-still-on-top/https://threatpost.com/snake-keylogger-pdfs/179703/https://research.checkpoint.com/2022/the-death-of-please-enable-macros-and-what-it-means/https://www.bleepingcomputer.com/news/security/raccoon-stealer-malware-suspends-operations-due-to-war-in-ukraine/https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d

42CHECK POINT SOFTWARE|2022 MID-YEAR SECURITY REPORT 4248%11%9%6%21%5%XMRigLemonDuckWannamineRubyMiner Darkgate Other60%9%9%3%5%XMRigRubyMinerLemonDuckDarkgateWannamineOther14%48%7%7%4%4%XMRigLemonDuckDarkgateRubyMinerWannamineOther29%XMRigRubyMinerLemonDuckDarkgateWannamineOther60%9%9%5%14%3%Figure 28: Top cryptomining malware globallyFigure 30: Top cryptomining malware in EMEAGLOBALFigure 29: Top cryptomining malware in the AmericasFigure 31: Top cryptomining malware in APACAMERICASEUROPE, MIDDLE EAST AND AFRICA (EMEA)ASIA PACIFIC (APAC)TOP CRYPTOMINING MALWARECHAPTER 5

https://www.bloomberg.com/news/articles/2022-06-26/crypto-winter-why-this-bitcoin-bear-market-is-different-from-the-pasthttps://www.microsoft.com/security/blog/2021/07/22/when-coin-miners-evolve-part-1-exposing-lemonduck-and-lemoncat-modern-mining-malware-infrastructure/

1 / 87

90%