GlobeNewswire

Cryptomining Replaces Ransomware as Most Popular Cybercrime Malware

Share

Analysis of vulnerability and threat trends shows cryptomining malware dominates threat landscape in the first half of 2018

SAN JOSE, Calif., July 18, 2018 (GLOBE NEWSWIRE) -- Skybox® Security, a global leader in cybersecurity management, announced today the release of its mid-year update to the Vulnerability and Threat Trends Report which analyzes vulnerabilities, exploits and threats in play. The report, compiled by the team of security analysts at the Skybox® Research Lab, aims to help organizations align their security strategy with the reality of the current threat landscape.

The mid-year update explores trends observed from January to June of 2018. One of the most significant findings is the replacement of ransomware as the cybercriminal tool of choice with cryptomining malware. In the last six months of 2017, ransomware accounted for 32 percent of attacks, while malicious cryptominers accounted for seven percent. By the first half of 2018, the figures had switched almost exactly: malicious cryptominers accounted for 32 percent of attacks while ransomware dropped to eight percent.

"In the last few years, ransomware reigned supreme as the shortcut money-maker for cybercriminals," said Ron Davidson, Skybox CTO and vice president of R&D. "It doesn't require data exfiltration, just encryption to hold the data hostage and a ransom note of how the victim can pay up. With cryptominers, the criminals can go straight to the source and mine cryptocurrency themselves. There's no question of if they'll be paid or not."

Cryptomining uses the computational power of compromised assets to create new blocks in the blockchain of like Bitcoin and Monero. The malicious or unauthorized cryptomining approach indeed avoids several of the drawbacks of ransomware:

  • The victim doesn't need to be notified of the attack in order to pay the ransom, so it can continue indefinitely in a stealth manner
  • Cryptocurrency can be mined over long-periods of time, rather than the cybercriminal receiving a single lump-sum ransom payment
  • There is no decision of payment on the part of the victim - the attack itself controls how much money will be generated.

"Ransomware received a lot of attention in years past, especially thanks to the likes of WannaCry, NotPetya and BadRabbit," said Skybox Director of Threat Intelligence Marina Kidron and leader of the Research Lab behind the report. "To some extent, organizations took note and put effective precautions in place, ensuring they had reliable back-ups and even thwarting attackers with decryption programs. So cybercriminals found - in cryptomining- a path of lesser resistance. The recent uptick in value of cryptocurrencies also made this an incredibly profitable attack option."

Other findings in the report appear to relate to this rise in cryptomining. Internet and mobile vulnerabilities made up nearly a third of all new vulnerabilities published in the first half of 2018. Google Android had by far the most vulnerabilities during that time period, exceeding the tally of the next five most vulnerable vendors combined. Android also logged 200 more vulnerabilities than it did in the second half of 2018. Malicious cryptomining has found an advantage in targeting the app store of the global market leader in mobile devices, with billions of potential targets worldwide.

Browser-based malware is also on the rise in the first half of 2018. "Out of all software today, web browsers are considered the most prone to malicious attacks," said Kidron. "They constantly interact with websites and applications that cybercriminals have infected with malware like cryptominers and other threats via the web, which are notoriously difficult to detect. The cryptomining malware could be active as long as the web session is active, and 'file-less' cryptominers also can hide from conventional security tools as there's no download or attachment to analyze."

No matter the payload, attackers looking to exploit vulnerabilities have more resources than ever. Not only are dark web market places rich with attack tools and services, and criminal forums ripe with information, vulnerabilities themselves have skyrocketed. New vulnerabilities catalogued by MITRE's National Vulnerability Database doubled in 2017 over the previous year, and 2018 looks to be on track to shatter even that record. The 2017 surge and continued elevated numbers is largely due to organizational improvements at MITRE and increased security research by vendors and third-parties, including vendor-sponsored bug bounty programs. But no matter the reason, organizations have to employ smarter and faster ways to find the signal in the noise and mitigate vulnerability risks before they're used in an attack.

Skybox recommends establishing a threat-centric vulnerability management (TCVM) program to adapt to these changes in the threat landscape and those yet to come. The TCVM approach helps security practitioners focus on the small subset of vulnerabilities most likely to be used in an attack by incorporating vulnerability and threat intelligence with the context of their assets, network and security controls. This way, remediation is targeted at the greatest areas of risk while leveraging all response options - patching as well as network-based changes.

To read the full report on vulnerability and threat trends thus far in 2018, click here. To learn more about Skybox vulnerability management approach, download our e-book here

About Skybox Research Lab 
The Skybox Research Lab is team of security analysts who daily scour data from dozens of security feeds and sources as well as investigate sites in the dark web. The Research Lab validates and enhances data through automated as well as manual analysis, with analysts adding their knowledge of attack trends, cyber events and TTPs of today's attackers. Their ongoing investigations determine which vulnerabilities are being exploited in the wild and used in distributed crimeware such as ransomware, malware, exploit kits and other attacks exploiting client- and server-side vulnerabilities.

For more information on the methodology behind the Skybox Research Lab and to keep up with the latest vulnerability and threat intelligence, visit www.vulnerabilitycenter.com.

About Skybox Security

Skybox provides the industry's broadest cybersecurity management platform to address security challenges within large, complex networks. By integrating with 120 networking and security technologies, the Skybox® Security Suite gives comprehensive attack surface visibility and the context needed for informed action. Our analytics, automation and intelligence improve the efficiency and performance of security operations in vulnerability and threat management and firewall and security policy management for the world's largest organizations.

© 2018 Skybox Security, Inc. All rights reserved. Skybox Security and the Skybox Security logo are either registered trademarks or trademarks of Skybox Security, Inc., in the United States and/or other countries. All other trademarks are the property of their respective owners. Product specifications subject to change at any time without prior notice.

CONTACT INFORMATION

Skybox Security
Tawnya Lancaster
Director of Brand and Communications
408-205-1618 | Tawnya.lancaster@skyboxsecurity.com

OneChocolate for Skybox Security
United Kingdom: Daniel Couzens
+44 (0)20 7437 0227 | DanielC@onechocolatecomms.co.uk

Germany: Melanie Grasser
+49 (0)89 3888 920 10 | MelanieG@onechocolatecomms.de

France: Xavier Delhôme
+33 1 41 31 75 09 | xavier@onechocolate.fr

A photo accompanying this announcement is available at http://www.globenewswire.com/NewsRoom/AttachmentNg/8c26e3be-8dd4-457a-b19b-becd7c28c469




This announcement is distributed by Nasdaq Corporate Solutions on behalf of Nasdaq Corporate Solutions clients.
The issuer of this announcement warrants that they are solely responsible for the content, accuracy and originality of the information contained therein.
Source: Skybox Security via Globenewswire

About GlobeNewswire

GlobeNewswire
GlobeNewswire



Subscribe to releases from GlobeNewswire

Subscribe to all the latest releases from GlobeNewswire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from GlobeNewswire

Virtune lanserar Virtune Bittensor ETP på Nasdaq Stockholm19.12.2025 09:13:21 CET | Pressmeddelande

Stockholm, den 19 december 2025 - Virtune, en svensk reglerad kapitalförvaltare av kryptotillgångar, meddelar idag lanseringen av en ny innovativ krypto-ETP, Virtune Bittensor ETP, på Nasdaq Stockholm, den största börsen i Norden. Om Virtune Bittensor ETP Virtune Bittensor ETP är en fysiskt backad börshandlad produkt (ETP) som är utformad för att erbjuda investerare ett säkert och kostnadseffektivt sätt att få exponering mot Bittensor (TAO). Detta möjliggörs genom en transparent och fysiskt backad struktur med institutionell säkerhetsnivå. Viktig information om Virtune Bittensor ETP: 1:1 exponering mot Bittensor100% fysiskt backad av TAO1,95% årlig förvaltningsavgift Virtune Bittensor ETP Fullständigt namn: Virtune Bittensor ETPKortnamn: Virtune Bittensor Ticker: VIRTAOHandelsvaluta: SEKFörsta handelsdag: Fredagen den 19 december 2025ISIN: SE0027098484 Om Bittensor Bittensor är ett decentraliserat nätverk som möjliggör utvecklingen av artificiell intelligens genom en öppen marknadsplat

Milepost etablerar vardagsladdning i Lund i samarbete med Lunds Kommun18.12.2025 11:00:00 CET | Pressmeddelande

STOCKHOLM och LUND, Sverige, Dec. 18, 2025 (GLOBE NEWSWIRE) -- Milepost AB, Sveriges första oberoende laddoperatör specialiserad på vardagsladdning, etablerar bolagets laddtjänster för elfordon i Lund, i samarbete med Lunds kommun. Efter en grundlig utvärdering tilldelade Lunds kommun tidigare i år Milepost AB uppdraget att bygga ut bolagets laddtjänster för vardagsladdning vid ett antal platser i Lunds kommun. Milepost har nu driftsatt den första anläggningen som en del i denna utbyggnad, vilken finns vid Genarps Idrottsplats. Ett ytterligare antal anläggningar planeras att driftsättas inom kort och sedan fortlöpande under 2026. Lund följs av flertalet kommuner i Skåne där Milepost redan har etablerat sina tjänster inklusive Eslöv, Kävlinge, Lomma och Båstad. Lars Isaksson, affärsutvecklings- samt operativt ansvarig vid Milepost säger: ”Vi är glada över att fått förtroendet från Lunds kommun att etablera våra laddtjänster inom kommunen. Vi ser fram emot att hjälpa boende i Lund som bo

Virtune förlänger samarbetet med Truls Möregårdh17.12.2025 09:15:16 CET | Pressmeddelande

Stockholm, den 17 december 2025 – Virtune, en svensk reglerad kapitalförvaltare av kryptotillgångar, förlänger sitt samarbete med pingisstjärnan Truls Möregårdh. Efter två olympiska silver 2024 och segern mot världsettan i finalen av storturneringen WTT Europe Smash 2025 går Truls in i den intensiva säsongen 2026 med både energi och nyfikenhet. Det är egenskaper som också präglar Virtunes syn på framtiden. Virtune är en ledande svensk reglerad kapitalförvaltare av kryptotillgångar. Bolaget har vuxit snabbt i Norden och satsar nu även på den tyska marknaden, med ambitionen att ge både privatpersoner och professionella investerare en tryggare och reglerad väg in i kryptotillgångar. "Jag gillar att jobba med Virtune eftersom de vågar utforska hur investeringar kan utvecklas i framtiden. Det passar mig och hur jag själv vill tänka framåt. Att vi fortsätter tillsammans känns både rätt och inspirerande inför nästa säsong." säger Truls Möregårdh. Truls är känd för sin underhållande spelstil o

Virtune AB (Publ) (“Virtune”) har genomfört den månatliga rebalanseringen för november 2025 av Virtune Crypto Top 10 Index ETP, Nordens första kryptoindex-ETP5.12.2025 11:03:30 CET | Pressmeddelande

Stockholm, 5 december 2025 - Virtune meddelar idag att man har slutfört den månatliga rebalanseringen för Virtune Crypto Top 10 Index ETP SEK / EUR som är noterad på Nasdaq Stockholm för både SEK-varianten (ISIN-kod SE0020052207, tickernamn VIR10SEK) och EUR-varianten (ISIN-kod SE0020052215, tickernamn VIR10EUR). Utöver Virtune Crypto Top 10 Index ETP så innefattar Virtunes produktportfölj: Virtune Bitcoin ETP Virtune Stellar ETP Virtune Staked Ethereum ETP Virtune Staked Solana ETP Virtune Staked Polkadot ETP Virtune Litecoin ETP Virtune XRP ETP Virtune Avalanche ETP Virtune Chainlink ETP Virtune Arbitrum ETP Virtune Staked Polygon ETP Virtune Staked Cardano ETP Virtune Crypto Altcoin Index ETP Virtune Bitcoin Prime ETP Virtune Coinbase 50 Index ETP Virtune Staked Near ETP Virtune Sui ETP Virtune Stablecoin ETP Indexallokering per den 28 november (före rebalansering): Bitcoin: 40,80% Ethereum: 34,33% XRP: 12,46% Solana: 7,16% Cardano: 1,43% Bitcoin Cash: 1,00% Chainlink: 0,84% Stellar

Virtune AB (Publ) ("Virtune") har genomfört den månatliga rebalanseringen för november 2025 av Virtune Crypto Altcoin Index ETP3.12.2025 09:10:23 CET | Pressmeddelande

Virtune AB (Publ) ("Virtune") har genomfört den månatliga rebalanseringen för november 2025 av Virtune Crypto Altcoin Index ETP Stockholm, 3 december 2025 – Virtune meddelar idag att man har slutfört den månatliga rebalanseringen av Virtune Crypto Altcoin Index ETP, noterad på Nasdaq Stockholm, Nasdaq Helsinki och Xetra (ISIN-kod SE0023260716). Utöver Virtune Crypto Altcoin Index ETP omfattar Virtunes produktportfölj följande produkter: Virtune Bitcoin ETP Virtune Staked Ethereum ETP Virtune Stellar ETP Virtune Staked Solana ETP Virtune Staked Polkadot ETP Virtune XRP ETP Virtune Avalanche ETP Virtune Litecoin ETP Virtune Chainlink ETP Virtune Arbitrum ETP Virtune Polygon ETP Virtune Staked Cardano ETP Virtune Crypto Top 10 Index ETP SEK Virtune Crypto Top 10 Index ETP EUR Virtune Bitcoin Prime ETP Virtune Coinbase 50 Index ETP Virtune Staked Near ETP Virtune Sui ETP Virtune Stablecoin Index ETP Indexfördelning per den 28 november (före rebalansering): Bitcoin Cash: 13,30% Uniswap Prot

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye