NjRAT

January 2023’s Most Wanted Malware: Infostealer Vidar Makes a Return while Earth Bogle njRAT Malware Campaign Strikes

Retrieved on: 
Monday, February 13, 2023

In January, infostealer Vidar was seen spreading through fake domains claiming to be associated with remote desktop software company AnyDesk.

Key Points: 
  • In January, infostealer Vidar was seen spreading through fake domains claiming to be associated with remote desktop software company AnyDesk.
  • Researchers also identified a major campaign dubbed Earth Bogle delivering the njRAT malware to targets across the Middle East and North Africa.
  • njRAT came in at number ten on the top malware list, having dropped off after September 2022.
  • “Once again, we’re seeing malware groups use trusted brands to spread viruses, with the aim of stealing personal identifiable information.

Emotet rockets into pole position as most seen malware family in Q1

Retrieved on: 
Thursday, May 12, 2022

The latest global HP Wolf Security Threat Insights Report which provides analysis of real-world cybersecurity attacks shows that Emotet has bolted up 36 places to become the most common malware family detected this quarter (representing 9% of all malware captured).

Key Points: 
  • The latest global HP Wolf Security Threat Insights Report which provides analysis of real-world cybersecurity attacks shows that Emotet has bolted up 36 places to become the most common malware family detected this quarter (representing 9% of all malware captured).
  • Such attacks are harder for organizations to defend against because detection rates for these file types are often low, increasing the chance of infection.
  • Threats used 545 different malware families in their attempts to infect organizations, with Emotet, AgentTesla and Nemucod being the top three.
  • HP Wolf Security provides comprehensive endpoint protection and resiliency that starts at the hardware level and extends across software and services.

September 2021’s Most Wanted Malware: Trickbot Once Again Tops the List

Retrieved on: 
Friday, October 8, 2021

Researchers report that Trickbot has returned to the top of the list having fallen into second place in August following a three-month long reign.

Key Points: 
  • Researchers report that Trickbot has returned to the top of the list having fallen into second place in August following a three-month long reign.
  • HTTP Headers Remote Code Execution takes third place in the top exploited vulnerabilities list, with a global impact of 43% as well.
  • Trickbot - Trickbot is a modular Botnet and Banking Trojan constantly being updated with new capabilities, features and distribution vectors.
  • This enables Trickbot to be a flexible and customizable malware that can be distributed as part of multi-purpose campaigns.