Most Vulnerabilities

Total Page:16

File Type:pdf, Size:1020Kb

Most Vulnerabilities WANTED WANTED Most WANTED CVE-2019-0604 CVE-2018-7600 Vulnerabilities Light Foot China Chopper Kitty MeOw Using CWE: Improper Input Validation, this threat is on the 10 With a small 4KB footprint and extensive field prowl from cryptomining to embedding ransomware. Routinely exploited by state, nonstate, and unattributed cyber actors experience going back to 2012, this still-powerful threat Vulnerable Products: Drupal before 7.58, 8.x before 8.3.9, preys on unpatched SharePoint servers and their data. 8.4.x before 8.4.6, and 8.5.x before 8.5. The Department of Homeland Security Cybersecurity and Infrastructure Security Agency (DHS CISA) Vulnerable Products: Microsoft SharePoint Malware Name: Kitty and the Federal Bureau of Investigation (FBI), urges public and private sector organizations alike to Malware Name: China Chopper Click to read RiskSense Web and Application Framework apply necessary updates in order to prevent the most common forms of attacks encountered today. Vulnerabilities report for more research about these types of weaknesses. Sources: Sources: https://nvd.nist.gov/vuln/detail/CVE-2019-0604 https://en.wikipedia.org/wiki/China_Chopper Sources: https://www.zdnet.com/article/dhs-cisa-and-fbi-share-list-of-top-10-most-exploited-vulnerabilities/ https://nvd.nist.gov/vuln/detail/CVE-2018-7600 https://www.us-cert.gov/ncas/alerts/aa20-133a https://www.zdnet.com/article/hello-kitty-malware-targets-drupal-to-mine-for- cryptocurrency WANTED WANTED WANTED WANTED CVE-2018-4878 CVE-2017-8759 CVE-2017-5638 CVE-2017-11882 The RAT called DOGCALL Fin and Feather Super Spy JexBoss the Bad The Chaos Crew What started out as a threat-hunting tool for good Has ties to multiple families and threat actors The threat covertly installs by exploiting security lapses This gang is all about running arbitrary code and turned into a rogue exploit and is closely associated attributed to North Korea and specializes in planting and originally worked as a government-sponsored enjoys a good game of hide-and-seek. with SamSam ransomware. malicious code. surveillance and reconnaissance tool. Vulnerable Products: Apache Struts 2 2.3.x before 2.3.32 and Vulnerable Products: Microsoft Office 2007 SP3/2010 Vulnerable Products: Adobe Flash Player before 28.0.0.161 Vulnerable Products: Microsoft .NET Framework 2.0, 3.5, 2.5.x before 2.5.10.1 SP2/2013 SP1/2016 Products 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 Malware Name: DOGCALL Associated Malware: JexBoss Associated Malware: Loki, FormBook, Pony/FAREIT Associated Malware: FINSPY, FinFisher, WingBird Sources: Click to read RiskSense Apache Struts Report to learn more Sources: https://nvd.nist.gov/vuln/detail/CVE-2018-4878 Sources: about this vulnerability. https://nvd.nist.gov/vuln/detail/CVE-2017-11882 https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with- https://nvd.nist.gov/vuln/detail/CVE-2017-8759 https://threatpost.com/new-formbook-dropper-harbors-persistence/145614/ Sources: dogcall-reaper-group-uses-new-malware-to-deploy-rat/ https://attack.mitre.org/software/S0182/ https://www.acunetix.com/blog/articles/pony-malware-credential-theft/ https://nvd.nist.gov/vuln/detail/CVE-2017-5638 https://www.infosecurity-magazine.com/news/threat-actors-exploiting-red-team/ WANTED WANTED WANTED WANTED CVE-2017-0143 CVE-2017-0199 CVE-2012-0158 CVE-2015-1641 WannaCry and Team Boi Power Bot the EternalBlue Fan Club Notorious Big Dollar Dridex The Elder One of the most prevalent financial Trojans with a Working from the safety of the shadows, allows continuous legacy of attacks prevented only by Team known for hiding daggers in Microsoft Office remote attackers to execute arbitrary code. From stories of old, this talented multi-OS RAT works .RTF document cloaks, their PowerShell commands up-to-date patching. through .RTF files, capable of Remote Code wreak havoc once deployed. Vulnerable Products: Microsoft Windows Vista SP2; Windows Execution (RCE). Vulnerable Products: Microsoft Office 2003 SP3, 2007 SP2 and Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; SP3, and 2010 Gold and SP1; Office 2003 Web Components Vulnerable Products: Microsoft Office 2007 SP3/2010 Windows Server 2012 Gold and R2; Windows RT 8.1; and Vulnerable Products: Microsoft Word 2007 SP3, Office 2010 SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and SP2/2013 SP1/2016, Vista SP2, Server 2008 SP2, Windows 7 Windows 10 Gold, 1511, and 1607; and Windows Server 2016 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP1, Windows 8.1 Word for Mac 2011, Office Compatibility Pack SP3, Word SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; Associated Malware: Many using EternalSynergy and Automation Services on SharePoint Server 2010 SP2 and 2013 and Visual Basic 6.0 Associated Malware: FINSPY, LATENTBOT, Dridex EternalBlue Exploit Kit SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 Click to read RiskSense EternalBlue research which provides Associated Malware: Dridex Associated Malware: Toshliph, UWarrior Sources: a deep technical overview of this exploit. https://nvd.nist.gov/vuln/detail/CVE-2017-0199 Sources: Sources: https://nvd.nist.gov/vuln/detail/CVE-2012-0158 Sources: https://nvd.nist.gov/vuln/detail/CVE-2015-1641 https://www.us-cert.gov/ncas/alerts/aa19-339a https://nvd.nist.gov/vuln/detail/CVE-2017-0143 https://en.wikipedia.org/wiki/EternalBlue RiskSense – the industry’s only full spectrum risk-based vulnerability management and prioritization platform. Find more information about our research at: www.risksense.com/resources.
Recommended publications
  • Identifying Threats Associated with Man-In-The-Middle Attacks During Communication Between a Mobile Device and the Back End Server in Mobile Banking Applications
    IOSR Journal of Computer Engineering (IOSR-JCE) e-ISSN: 2278-0661, p- ISSN: 2278-8727Volume 16, Issue 2, Ver. IX (Mar-Apr. 2014), PP 35-42 www.iosrjournals.org Identifying Threats Associated With Man-In-The-Middle Attacks during Communication between a Mobile Device and the Back End Server in Mobile Banking Applications Anthony Luvanda1,*Dr Stephen Kimani1 Dr Micheal Kimwele1 1. School of Computing and Information Technology, Jomo Kenyatta University of Agriculture and Technology, PO Box 62000-00200 Nairobi Kenya Abstract: Mobile banking, sometimes referred to as M-Banking, Mbanking or SMS Banking, is a term used for performing balance checks, account transactions, payments, credit applications and other banking transactions through a mobile device such as a mobile phone or Personal Digital Assistant (PDA). Mobile banking has until recently most often been performed via SMS or the Mobile Web. Apple's initial success with iPhone and the rapid growth of phones based on Google's Android (operating system) have led to increasing use of special client programs, called apps, downloaded to the mobile device hence increasing the number of banking applications that can be made available on mobile phones . This in turn has increased the popularity of mobile device use in regards to personal banking activities. Due to the characteristics of wireless medium, limited protection of the nodes, nature of connectivity and lack of centralized managing point, wireless networks tend to be highly vulnerable and more often than not they become subjects of attack. This paper proposes to identify potential threats associated with communication between a mobile device and the back end server in mobile banking applications.
    [Show full text]
  • ERP Applications Under Fire How Cyberattackers Target the Crown Jewels
    ERP Applications Under Fire How cyberattackers target the crown jewels July 2018 v1.0 With hundreds of thousands of implementations across the globe, Enterprise Resource Planning (ERP) applications are supporting the most critical business processes for the biggest organizations in the world. This report is the result of joint research performed by Digital Shadows and Onapsis, aimed to provide insights into how the threat landscape has been evolving over time for ERP applications. We have concentrated our efforts on the two most widely-adopted solutions across the large enterprise segment, SAP and Oracle E-Business Suite, focusing on the risks and threats organizations should care about. According to VP Distinguished Analyst, Neil MacDonald “As financially motivated attackers turn their attention ‘up the stack’ to the application layer, business applications such as ERP, CRM and human resources are attractive targets. In many organizations, the ERP application is maintained by a completely separate team and security has not been a high priority. As a result, systems are often left unpatched for years in the name of operational availability.” Gartner, Hype Cycle for Application Security, 2017, July 2017 1 1 Gartner, Hype Cycle for Application Security, 2017, Published: 28 July 2017 ID: G00314199, Analyst(s): Ayal Tirosh, https://www.gartner.com/doc/3772095/hype-cycle-application-security- 02 Executive Summary With hundreds of thousands of implementations across the globe, Enterprise Resource Planning (ERP) applications support the most critical business processes and house the most sensitive information for the biggest organizations in the world. The vast majority of these large organizations have implemented ERP applications from one of the two market leaders, SAP and Oracle.
    [Show full text]
  • Compromised Connections
    COMPROMISED CONNECTIONS OVERCOMING PRIVACY CHALLENGES OF THE MOBILE INTERNET The Universal Declaration of Human Rights, the International Covenant on Civil and Political Rights, and many other international and regional treaties recognize privacy as a fundamental human right. Privacy A WORLD OF INFORMATION underpins key values such as freedom of expression, freedom of association, and freedom of speech, IN YOUR MOBILE PHONE and it is one of the most important, nuanced and complex fundamental rights of contemporary age. For those of us who care deeply about privacy, safety and security, not only for ourselves but also for our development partners and their missions, we need to think of mobile phones as primary computers As mobile phones have transformed from clunky handheld calling devices to nifty touch-screen rather than just calling devices. We need to keep in mind that, as the storage, functionality, and smartphones loaded with apps and supported by cloud access, the networks these phones rely on capability of mobiles increase, so do the risks to users. have become ubiquitous, ferrying vast amounts of data across invisible spectrums and reaching the Can we address these hidden costs to our digital connections? Fortunately, yes! We recommend: most remote corners of the world. • Adopting device, data, network and application safety measures From a technical point-of-view, today’s phones are actually more like compact mobile computers. They are packed with digital intelligence and capable of processing many of the tasks previously confined
    [Show full text]
  • Mobile Financial Fraud April 2013
    White Paper: Mobile Financial Fraud April 2013 Mobile Threats and the Underground Marketplace Principal Investigator and Corresponding Author Jart Armin Contributing Researchers Andrey Komarov, Mila Parkour, Raoul Chiesa, Bryn Thompson, Will Rogofsky Panel & Review Dr. Ray Genoe (UCD), Robert McArdle (Trend Micro), Dave Piscitello (ICANN), Foy Shiver (APWG), Edgardo Montes de Oca (Montimage), Peter Cassidy (APWG) APWG Mobile Fraud web site http://ecrimeresearch.org/wirelessdevice/Fraud/ Table of Contents Abstract ..................................................................................................................................... 2 Introduction and Starting Position ........................................................................................ 2 A Global Overview .................................................................................................................. 3 Vulnerabilities Overview ....................................................................................................... 3 The Underground Mobile Market ....................................................................................... 13 Mobile DNS & Traffic ........................................................................................................... 15 iBots & the Pocket Botnet ..................................................................................................... 18 Mobile Intrusion ...................................................................................................................
    [Show full text]
  • APT and Cybercriminal Targeting of HCS June 9, 2020 Agenda
    APT and Cybercriminal Targeting of HCS June 9, 2020 Agenda • Executive Summary Slides Key: • APT Group Objectives Non-Technical: managerial, strategic • APT Groups Targeting Health Sector and high-level (general audience) • Activity Timeline Technical: Tactical / IOCs; requiring • TTPs in-depth knowledge (sysadmins, IRT) • Malware • Vulnerabilities • Recommendations and Mitigations TLP: WHITE, ID#202006091030 2 Executive Summary • APT groups steal data, disrupt operations, and destroy infrastructure. Unlike most cybercriminals, APT attackers pursue their objectives over longer periods of time. They adapt to cyber defenses and frequently retarget the same victim. • Common HPH targets include: • Healthcare Biotechnology Medical devices • Pharmaceuticals Healthcare information technology • Scientific research • HPH organizations who have been victim of APT attacks have suffered: • Reputational harm Disruption to operations • Financial losses PII/PHI and proprietary data theft • HC3 recommends several mitigations and controls to counter APT threats. TLP: WHITE, ID#202006091030 3 APT Group Objectives • Motivations of APT Groups which target the health sector include: • Competitive advantage • Theft of proprietary data/intellectual capital such as technology, manufacturing processes, partnership agreements, business plans, pricing documents, test results, scientific research, communications, and contact lists to unfairly advance economically. • Intelligence gathering • Groups target individuals and connected associates to further social engineering
    [Show full text]
  • A PRACTICAL METHOD of IDENTIFYING CYBERATTACKS February 2018 INDEX
    In Collaboration With A PRACTICAL METHOD OF IDENTIFYING CYBERATTACKS February 2018 INDEX TOPICS EXECUTIVE SUMMARY 4 OVERVIEW 5 THE RESPONSES TO A GROWING THREAT 7 DIFFERENT TYPES OF PERPETRATORS 10 THE SCOURGE OF CYBERCRIME 11 THE EVOLUTION OF CYBERWARFARE 12 CYBERACTIVISM: ACTIVE AS EVER 13 THE ATTRIBUTION PROBLEM 14 TRACKING THE ORIGINS OF CYBERATTACKS 17 CONCLUSION 20 APPENDIX: TIMELINE OF CYBERSECURITY 21 INCIDENTS 2 A Practical Method of Identifying Cyberattacks EXECUTIVE OVERVIEW SUMMARY The frequency and scope of cyberattacks Cyberattacks carried out by a range of entities are continue to grow, and yet despite the seriousness a growing threat to the security of governments of the problem, it remains extremely difficult to and their citizens. There are three main sources differentiate between the various sources of an of attacks; activists, criminals and governments, attack. This paper aims to shed light on the main and - based on the evidence - it is sometimes types of cyberattacks and provides examples hard to differentiate them. Indeed, they may of each. In particular, a high level framework sometimes work together when their interests for investigation is presented, aimed at helping are aligned. The increasing frequency and severity analysts in gaining a better understanding of the of the attacks makes it more important than ever origins of threats, the motive of the attacker, the to understand the source. Knowing who planned technical origin of the attack, the information an attack might make it easier to capture the contained in the coding of the malware and culprits or frame an appropriate response. the attacker’s modus operandi.
    [Show full text]
  • Strategic Perspectives on Cybersecurity Management and Public Policies Volume 3 (2017)
    VOLUME 3 (2017) ▪ ISSUE 2 STRATEGIC PERSPECTIVES ON CYBERSECURITY MANAGEMENT AND PUBLIC POLICIES VOLUME 3 (2017) VOLUME ▪ ISSUE ISSUE 2 ANALYSES ▪ POLICY REVIEWS ▪ OPINIONS The European Cybersecurity Journal is a new specialized quarterly publication devoted to cybersecurity. It will be a platform of regular dialogue on the most strategic aspects of cybersecurity. The main goal of the Journal is to provide concrete policy recommendations for European decision-makers and raise awareness on both issues and problem-solving instruments. EDITORIAL BOARD Chief Editor: Dr Joanna Świątkowska The ECJ is a quarterly journal, published in January, CYBERSEC Programme Director and Senior Research Fellow of the April, July and October. Kosciuszko Institute, Poland Honorary Member of the Board: Dr James Lewis Director and Senior Fellow of the Strategic Technologies Program, Center for Strategic and International Studies (CSIS), USA Citations:This journal should be cited as follows: “European Cybersecurity Journal”, Member of the Board: Alexander Klimburg Volume 3 (2017), Issue 2, page reference Nonresident Senior Fellow, Cyber Statecraft Initiative, Atlantic Council ; Affiliate, Belfer Center of Harvard Kennedy School, USA Published by: The Kosciuszko Institute Member of the Board: Helena Raud ul. Feldmana 4/9-10 Member of the Board of the European Cybersecurity Initiative, Estonia 31-130 Kraków, Poland Member of the Board: Keir Giles Phone: 00 48 12 632 97 24 Director of the Conflict Studies Research Centre (CSRC), UK E-mail: [email protected] Editor Associate: Izabela Albrycht www.ik.org.pl Chairperson of the Kosciuszko Institute, Poland www.cybersecforum.eu Executive Editor: Karine Szotowski Printed in Poland by Drukarnia Diament | diamentdruk.pl Designer: Paweł Walkowiak | perceptika.pl DTP: Marcin Oroń Proofreading: Justyna Kruk and Agata Ostrowska ISSN: 2450-21113 Disclaimer: The views expressed in articles are the authors’ and not necessarily those of the Kosciuszko Institute.
    [Show full text]
  • The Dridex Swiss Army Knife: Big Data Dissolves the APT & Crime Grey Area
    #RSAC SESSION ID: HT-W10 The Dridex Swiss Army knife: big data dissolves the APT & crime grey area Eward Driehuis Director of product Fox-IT @brakendelama #RSAC Understanding criminal evolution Global visibility Collaboration Investigations Feeds #RSAC May 2014 #RSAC Rewind 9 years… 2006 Slavik launches ZeuS 2009 SpyEye & Carberp compete for market share 2010 Slavik creates ZeuS2 Hands over ZeuS support to the SpyEye guy 2011 ZeuS2 code leaks 2012 Gribodemon & Carberp members arrested In 2009 Slavik had joined JabberZeuS And Evolved to GameOver / P2PZeuS #RSAC The Businessclub Legacy Businesslike Financial guy perfected money laundry Targeted commercial banking Perfected the Hybrid attack / Tokengrabber Perfected ransomware / Cryptolocker Did some “light espionage” #RSAC Business club after Slavik Dyre Businessclub (GameOver ZeuS gang until May 2014) EvilCorp (Dridex crew) #RSAC Dridex: EvilCorp’s Swiss Army knife #RSAC EvilCorp network expands Core businessclub members in EvilCorp & Dridex operators Leveraging existing money laundry networks Branching out: Dridex operators do ransomware, RATs, Credit Cards, high value targets Ties with Anunak / Carbanak #RSAC Dridex Malware Based on Bugat/Cridex/Feodo, since 2014 Speading: scattergun (spam / attachments) Modular architecture P2P, with 3 operating modes: Token Grabber, data mining, inter node comm Using businessclub technology Loader dropping many different malwares #RSAC #RSAC EvilCorp: Dridex Targets 2015 -2017 #RSAC EvilCorp: ”Gucci” accounts Harvesting data from victims Big data techniques
    [Show full text]
  • Zerohack Zer0pwn Youranonnews Yevgeniy Anikin Yes Men
    Zerohack Zer0Pwn YourAnonNews Yevgeniy Anikin Yes Men YamaTough Xtreme x-Leader xenu xen0nymous www.oem.com.mx www.nytimes.com/pages/world/asia/index.html www.informador.com.mx www.futuregov.asia www.cronica.com.mx www.asiapacificsecuritymagazine.com Worm Wolfy Withdrawal* WillyFoReal Wikileaks IRC 88.80.16.13/9999 IRC Channel WikiLeaks WiiSpellWhy whitekidney Wells Fargo weed WallRoad w0rmware Vulnerability Vladislav Khorokhorin Visa Inc. Virus Virgin Islands "Viewpointe Archive Services, LLC" Versability Verizon Venezuela Vegas Vatican City USB US Trust US Bankcorp Uruguay Uran0n unusedcrayon United Kingdom UnicormCr3w unfittoprint unelected.org UndisclosedAnon Ukraine UGNazi ua_musti_1905 U.S. Bankcorp TYLER Turkey trosec113 Trojan Horse Trojan Trivette TriCk Tribalzer0 Transnistria transaction Traitor traffic court Tradecraft Trade Secrets "Total System Services, Inc." Topiary Top Secret Tom Stracener TibitXimer Thumb Drive Thomson Reuters TheWikiBoat thepeoplescause the_infecti0n The Unknowns The UnderTaker The Syrian electronic army The Jokerhack Thailand ThaCosmo th3j35t3r testeux1 TEST Telecomix TehWongZ Teddy Bigglesworth TeaMp0isoN TeamHav0k Team Ghost Shell Team Digi7al tdl4 taxes TARP tango down Tampa Tammy Shapiro Taiwan Tabu T0x1c t0wN T.A.R.P. Syrian Electronic Army syndiv Symantec Corporation Switzerland Swingers Club SWIFT Sweden Swan SwaggSec Swagg Security "SunGard Data Systems, Inc." Stuxnet Stringer Streamroller Stole* Sterlok SteelAnne st0rm SQLi Spyware Spying Spydevilz Spy Camera Sposed Spook Spoofing Splendide
    [Show full text]
  • Coordinating Across Chaos: the Practice of Transnational Internet Security Collaboration
    COORDINATING ACROSS CHAOS: THE PRACTICE OF TRANSNATIONAL INTERNET SECURITY COLLABORATION A Dissertation Presented to The Academic Faculty by Tarun Chaudhary In Partial Fulfillment of the Requirements for the Degree International Affairs, Science, and Technology in the Sam Nunn School of International Affairs Georgia Institute of Technology May 2019 COPYRIGHT © 2019 BY TARUN CHAUDHARY COORDINATING ACROSS CHAOS: THE PRACTICE OF TRANSNATIONAL INTERNET SECURITY COLLABORATION Approved by: Dr. Adam N. Stulberg Dr. Peter K. Brecke School of International Affairs School of International Affairs Georgia Institute of Technology Georgia Institute of Technology Dr. Michael D. Salomone Dr. Milton L. Mueller School of International Affairs School of Public Policy Georgia Institute of Technology Georgia Institute of Technology Dr. Jennifer Jordan School of International Affairs Georgia Institute of Technology Date Approved: March 11, 2019 ACKNOWLEDGEMENTS I was once told that writing a dissertation is lonely experience. This is only partially true. The experience of researching and writing this work has been supported and encouraged by a small army of individuals I am forever grateful toward. My wife Jamie, who has been a truly patient soul and encouraging beyond measure while also being my intellectual sounding board always helping guide me to deeper insight. I have benefited from an abundance of truly wonderful teachers over the course of my academic life. Dr. Michael Salomone who steered me toward the world of international security studies since I was an undergraduate, I am thankful for his wisdom and the tremendous amount of support he has given me over the past two decades. The rest of my committee has been equally as encouraging and provided me with countless insights as this work has been gestating and evolving.
    [Show full text]
  • Fortinet Threat Landscape Report Q3 2017
    THREAT LANDSCAPE REPORT Q3 2017 TABLE OF CONTENTS TABLE OF CONTENTS Introduction . 4 Highlights and Key Findings . 5 Sources and Measures . .6 Infrastructure Trends . 8 Threat Landscape Trends . 11 Exploit Trends . 12 Malware Trends . 17 Botnet Trends . 20 Exploratory Analysis . 23 Conclusion and Recommendations . 25 3 INTRODUCTION INTRODUCTION Q3 2017 BY THE NUMBERS: Exploits nn5,973 unique exploit detections nn153 exploits per firm on average nn79% of firms saw severe attacks nn35% reported Apache.Struts exploits Malware nn14,904 unique variants The third quarter of the year should be filled with family vacations and the back-to-school hubbub. Q3 2017 felt like that for a nn2,646 different families couple of months, but then the security industry went into a nn25% reported mobile malware hubbub of a very different sort. Credit bureau Equifax reported nn22% detected ransomware a massive data breach that exposed the personal information of Botnets approximately 145 million consumers. nn245 unique botnets detected That number in itself isn’t unprecedented, but the public nn518 daily botnet comms per firm and congressional outcry that followed may well be. In a congressional hearing on the matter, one U.S. senator called nn1.9 active botnets per firm the incident “staggering,” adding “this whole industry should be nn3% of firms saw ≥10 botnets completely transformed.” The impetus, likelihood, and extent of such a transformation is yet unclear, but what is clear is that Equifax fell victim to the same basic problems we point out Far from attempting to blame and shame Equifax (or anyone quarter after quarter in this report.
    [Show full text]
  • Banking Trojans: from Stone Age to Space Era
    Europol Public Information Europol Public Information Banking Trojans: From Stone Age to Space Era A Joint Report by Check Point and Europol The Hague, 21/03/2017 Europol Public Information 1 / 16 Europol Public Information Contents 1 Introduction .............................................................................................................. 3 2 The Founding Fathers ................................................................................................ 3 3 The Current Top Tier ................................................................................................. 5 4 The Latest .................................................................................................................. 9 5 Mobile Threat .......................................................................................................... 10 6 Evolutionary Timeline ............................................................................................. 11 7 Impressions/Current Trends ................................................................................... 11 8 Banking Trojans: The Law Enforcement View ......................................................... 12 9 How are Banking Trojans used by Criminals? ......................................................... 13 10 How are the Criminals Structured? ......................................................................... 14 11 Building on Public-Private-Partnerships - The Law Enforcement Response ........... 15 12 How to Protect Yourself .........................................................................................
    [Show full text]