Skip to content

2022 年擺脫十大網絡安全壞習慣

2021 年依舊是網絡犯罪頻繁的一年,僅僅在上半年,就有近 190 億筆訊息被曝露,盤點十大網絡安全壞習慣,ESET 資安專家提醒保持警惕,積極主動去改善,相信您就可以擁有安全無虞的2022 年。

1. 沒有定期更新
電腦及設備上的操作系統、瀏覽器和其他軟件中的漏洞是網絡犯罪可以進行攻擊的主要方式之一,在 2020 年發現了超過 18,100 個,而這相當於每天有 50 多個新的軟件漏洞,而您只要一個動作打開自動更新功能並在出現提示時點擊更新,就可以如常您的生活及工作。

2. 不安全的密碼
對多個帳戶使用相同的密碼和易於猜測的憑證,為黑客提供了極大的便利,他們擁有破解弱加密的軟件,利用殭屍網絡(botnet)以自動化方式不斷使用偷來的登入憑證試圖登入網絡服務,稱為憑據填充(Credential Stuffing)。您可以使用密碼管理器來記住具強度的密碼並在提供它的任何帳戶上使用雙重身份驗證 (2FA)。

3. 使用公共 Wi-Fi
黑客可以利用相同的網絡了解您的互聯網使用情況、登錄您的帳戶並竊取您的身份。為了安全起見,請儘量避開這些公共熱點,若您使用時,也避免在連接時登錄任何重要帳戶。

4. 隨意點擊來路不明之連結
網絡釣魚是目前最大的網絡威脅之一,阻止這些攻擊的首要規則是在點擊之前三思而後行,與發送電子郵件的個人或公司仔細核對以確保其合法,不要被迫採取過於倉促的行為。

5. 未在所有設備上使用資安產品
在網絡威脅多變的時代,應該確認所有的電腦設備都有安裝專業且具知名度的資安產品,另外也請確認您的流動裝置(如平板…)是否也有這麼做?

6. 點擊不安全的網站
http:// 是網頁伺服器與您的電腦瀏覽器,以一般(非安全)模式在進行互動交談,所以內容有可能遭攔截竊聽;換句話說,在此類網頁上填寫傳送的資料有可能被有心人士看到。而 https:// 多了一個字母 S 的差別代表 ”安全(secure)”,基本上意謂著,您的電腦與伺服器間的資料傳遞是以加密的方式進行進行互動交談。

7. 工作的電子郵件被用於個人的日常
試想使用工作的電子郵件和密碼在消費性購物網站和其他網站上註冊,如果這些網站遭到破壞怎麼辦?黑客就有可能能夠劫持您的公司帳戶,另外使用未受保護的個人電腦設備進行工作其實也會增加額外的風險。

8. 通過電話提供詳細訊息
語音網絡釣魚(也稱為 vishing)是一種越來越流行的從受害者那裡獲取個人和財務資訊的方式,詐騙者經常偽裝他們的真實號碼以增加攻擊的合法性,所以請儘量避免透過電話發送任何敏感或重要訊息。

9. 沒有定期備份
勒索軟件每年給企業造成數億美元的損失,試想如果突然無法開啟您的電腦,裡頭所有的資料,都可能永遠丟失,其中包括家庭照片和重要的工作文件等等;根據 3-2-1 最佳備份原則,定期備份可在最壞的情況發生時,讓您高枕無憂。

10. 智能設備沒有被保護
近三分之一的歐洲家庭配備了智能設備,如語音助理、智能電視和監視器;但它們也同時連結網絡,也因此成為犯罪分子的目標,進而被劫持並變成殭屍網絡,對其他人發起攻擊,或者變成通往您其他設備和資料的管道。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

ESET Research: Latin American banking trojans spread to Europe at the height of activity

  • Latin American banking trojans are an ongoing, evolving threat and ESET has recently seen some of their biggest campaigns to date.
  • They target mainly Brazil, Spain, and Mexico.
  • Mekotio and Grandoreiro expanded to Europe, mainly targeting Spain but also Italy, France and Belgium.
  • There are at least eight different malware families still active.
  • In June this year, Spanish law enforcement arrested 16 people related to Mekotio and Grandoreiro.
  • The vast majority (90%) are distributed via spam.

 

BRATISLAVA, PRAGUE — December 15, 2021 — ESET Research is concluding today its blogpost series dedicated to demystifying Latin American banking trojans started in August 2019. Since then, it has covered the most active ones, namely Amavaldo, Casbaneiro,Mispadu, Guildma, Grandoreiro, Mekotio, Vadokrist, Ousaban and Numando. Latin American banking trojans share a lot of common characteristics and behavior. Altogether, ESET has identified a dozen different malware families, most of which remain active to this day. The most significant discovery during the course of this investigation is the expansion of Mekotio and Grandoreiro to Europe, mainly Spain. ESET researchers have also observed occasional small campaigns targeting Italy, France and Belgium. Since Latin American banking trojans expanded to Europe, they have been getting more attention from both researchers and police forces. In the last few months, ESET has seen some of their biggest campaigns to date.

ESET telemetry shows a surprisingly large increase in the reach of Ousaban, Grandoreiro and Casbaneiro in recent months, leading to the conclusion that the threat actors behind these malware families are determined to continue their nefarious actions against users in targeted countries.

The campaigns we see always come in waves and more than 90% of them are distributed through spam, usually leading to a ZIP archive or an MSI installer. One campaign usually lasts for a week at most.

“Brazil is still the most targeted country, followed by Spain and Mexico. Since 2020, Grandoreiro and Mekotio expanded to Europe – mainly Spain. What started as several minor campaigns, likely to test the new territory, evolved into something much bigger. In fact, in August and September 2021, Grandoreiro launched its largest campaign so far and it targeted Spain,” says ESET researcher Jakub Souček, who leads the investigation into Latin American banking trojans.

In June this year, Spanish law enforcement arrested 16 people related to Mekotio and Grandoreiro. In the report, police state that almost €300,000 were stolen and they were able to block the transfer of a total of €3.5 million. Correlating this arrest with Latin American banking trojan activity in Spain, Mekotio seems to have taken a much larger hit than Grandoreiro, leading ESET to believe that the arrested people were more connected to Mekotio. Even though Mekotio went very quiet for almost two months after the arrest, ESET continues to see new campaigns distributing Mekotio.

Latin American banking trojans used to change rapidly. In the early days of ESET’s tracking, some of them were adding to or modifying their core features even several times a month. Nowadays they still change very often, but the core seems to remain mostly untouched. Due to the partially stabilized development, we believe the operators are now focusing on improving distribution.

“Latin American banking trojans require a lot of conditions to attack successfully,” explains Souček. “Potential victims need to follow steps required to install the malware on their machines; they need to visit a targeted website and log into their accounts. On the other side, operators need to react to this situation by manually commanding the malware to display the fake pop-up window and take control of the victim’s machine.”

During the course of this research series, several Latin American banking trojans became inactive, namely, Krachulka, Lokorrito and Zumanek. ESET researchers also discovered Janeleiro, a new Latin American banking trojan. In the future, ESET expects we may see some of these banking trojans expanding to the Android platform.

For more technical details about these Latin American banking trojans, read the blogpost “The dirty dozen of Latin America: From Amavaldo to Zumanek” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

 Top three countries most affected by Latin American banking trojans

Latin American banking trojan activity worldwide

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET cybersecurity survey amongst internet users in APAC reveals large gap between threat awareness and taking action

Three out of five respondents in APAC have experienced a cyberattack or online threat with common forms being malware (17%), theft of personal data (13%) and social media breach or duplication (11%).
Only 23% respondents have installed free or paid antivirus/ security app on their mobile devices.
Majority of parents have not spoken to their children about cybersecurity. 32% of parents from Thailand and 25% from Hong Kong said that their children have been exposed to inappropriate content online.
11,200 respondents from Hong Kong, India, Indonesia, Malaysia, Singapore, Taiwan, and Thailand were surveyed.

SINGAPORE – November 22, 2021 – ESET, a global leader in cybersecurity, today released the results from its APAC Consumer Cybersecurity Survey, revealing that three in five (62%) respondents in APAC said they have experienced a cyberattack or online threat in the past 12 months. By analysing consumers’ habits based on previous online interactions, the survey provided a deeper insight on the awareness of basic cybersecurity threats and best practices of actions online. The survey was conducted earlier this year with 11,200 respondents from Hong Kong, India, Indonesia, Malaysia, Singapore, Taiwan, and Thailand.

While the pandemic has introduced a new paradigm in the way we live, work, learn, socialize and play, it has also resulted in consumers’ increased reliance on digital technologies and services, which is a major factor for cybercriminals to pursue illegal activities.

“As we continue to navigate challenges from the pandemic, the reliance on digital technology for various aspects of our daily lives will likely spill into the future. Our survey findings suggest that it is now common for internet users to encounter online threats. Therefore, it is critical that consumers are educated about the growing threats, and are aware of the steps they can take to protect themselves as well as their children when conducting online activities,” said Parvinder Walia, President of Asia Pacific and Japan, ESET.

Of the seven APAC markets surveyed, India (81%), Thailand (65%), and Taiwan (63%) had the highest number of respondents who have experienced a cyberattack or online threat. Across the surveyed markets, the most common forms were attributed to malware/virus attacks (17%), theft of personal data (13%), and social media breach or duplication (11%). Only about 23% respondents installed free or paid antivirus/security app on their mobile devices.

 

Figure 1: Respondents were asked if they experienced at least one cyberattack or online threat such as malware attack, theft of personal data and social media breach in the past 12 months

Consumers’ vigilance is critical as online shopping scams are rife
As people are increasingly dependent on the internet to work, communicate, shop and entertain themselves, scammers are also taking advantage of the new normal to lure victims. Around two thirds (67%) of surveyed respondents indicated that they have come across online scams.

Figure 2: The number of respondents who said they came across online scams

The most common types of scams were online shopping (21%), social media (18%), investment (15%). With close to half of surveyed respondents saying that they shop online at least once a month, it is critical for consumers to remain vigilant when engaging in online transactions.

Figure 3: The most common outcomes for online shopping scam victims across APAC

Moreover, more than half of the respondents in APAC trust the security measures by online retailers completely. 45% and 23% of respondents from Thailand and India respectively, also indicated that they would continue shopping at an online retailer even after a data breach, regardless of the security status thereafter.

To protect themselves from scams, consumers should take precautions when shopping online. Fortunately, more than 90% of surveyed respondents take some form of precaution when shopping online, with checking for product/seller reviews being the most popular method of assessing a retailer’s legitimacy across APAC.

Children are vulnerable and need guidance in an increasingly digital world
With the pandemic resulting in a hybrid model of learning, children’s risk exposure via devices and through various online platforms offering services ranging from collaboration, online learning and video streaming to online games and social media is growing. This puts them at greater risk of encountering online threats, and it is important to teach children the essential skills to remain safe while navigating in an online environment.

The survey revealed that 95% of respondents who are parents from Indonesia have never spoken to their children about cybersecurity, and this remains significantly high in the region – over three out of four (77%) respondents across APAC have never spoken to their children about the issue. To ensure that minors are protected in the digital world, parents should have a hand in demonstrating the threats that the online world poses. 32% of parents from Thailand and 25% from Hong Kong also said that their children have been exposed to inappropriate content online.

Figure 4: The number of respondents who said they have never spoken to their children about cybersecurity

Most parents (90%) in APAC did take actions to ensure their children’s online safety. Popular methods include limiting the amount of time their children spend online (31%), using parental control applications (29%) and checking what apps are installed on their children’s devices (24%).

For guides and tips on how to keep kids safe on the internet, please visit ESET’s Safer Kids Online at https://saferkidsonline.eset.com/.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET named a Major Player in two Modern Endpoint Security IDC MarketScape reports

Bratislava, November 10, 2021 – ESET, a global leader in cybersecurity, has been recognized as a Major Player in two IDC MarketScape reports – the Worldwide Modern Endpoint Security Enterprise 2021 Vendor Assessment (Doc #US48306021, November 2021), and the Worldwide Modern Endpoint Security SMB 2021 Vendor Assessment (Doc #US48304721, November 2021). Together, the reports assess vendors’ endpoint security offerings across the SMB and enterprise markets.

Through a mix of surveys and interviews with market leaders, participants and end users, IDC MarketScape is known for providing in-depth quantitative and qualitative technology market assessments of different vendors’ capabilities. The reports’ assessment criteria focused on two main categories – an organization’s capabilities and its strategies. While the capabilities category focuses on the company’s offerings today, the strategies category looks at how the vendor’s strategy will deliver on what customers need in three to five years’ time.

The two reports focus on the importance of robust modern endpoint security for organizations both small and large. Modern endpoint security products protect personal computing devices from cyberattacks through detect and response mechanisms. One of the two mechanisms, endpoint protection platforms (EPP), reach detection verdicts and initiate responses in real time and autonomously, without human involvement. Endpoint detection and response (EDR) is the second stage of detection and response against cyberattacks that have evaded EPP detection. With EDR, the time to reach detection verdicts and initiate responses can span minutes to days depending on the severity of the threat itself.

In both reports, ESET was noted for reinvesting its profits into software development, core threat research, and threat hunting – the essential areas for advancing its products. ESET was also recognized for its local language support across an expansive base of global customers. ESET’s participation in independent EPP and EDR evaluations and willingness to put its products to the test was highlighted, as well as its broad and natively integrated cross-product platform solutions. Customers also benefit from the in-house threat hunting services and the unique threat data it collects and analyzes. All this has been enabled by ESET’s constant drive for self-improvement throughout its history, robust research, a technology-driven culture and stable leadership.

Pavol Balaj, Segment Director for Enterprises at ESET comments, “We are very proud to be named a Major Player in the IDC MarketScape evaluation of our endpoint solutions. With cyber-attacks being one of the most pertinent threats to modern businesses, at ESET we invest heavily in our people and our technology to deliver solutions that address the constantly evolving threat landscape. We will continue on our path of innovation to ensure the highest possible level of protection for our customers and partners.”

Michal Jankech, Segment Director for SMB and MSP at ESET comments, “Here at ESET, we are committed to protecting businesses of all sizes and equipping them and our MSP partners with cutting edge modern endpoint security. We are proud that our continued investment in our customers and partners, through our ever-improving services and solutions, is recognized externally too.”

To learn more about ESET’s Endpoint Security offering for SMBs, click here, and for Enterprises, click here

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About IDC MarketScape
IDC MarketScape vendor assessment model is designed to provide an overview of the competitive fitness of ICT (information and communications technology) suppliers in a given market. The research methodology utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each vendor’s position within a given market. IDC MarketScape provides a clear framework in which the product and service offerings, capabilities and strategies, and current and future market success factors of IT and telecommunications vendors can be meaningfully compared. The framework also provides technology buyers with a 360-degree assessment of the strengths and weaknesses of current and prospective vendors.

New ESET HOME platform offers consumers greater control and superior management

BRATISLAVA — October 19, 2021 – Today, global cybersecurity leader ESET launched a new version of its consumer security lineup along with ESET HOME, a platform that allows users to manage the security of all their Windows and Android home devices from one seamless and convenient interface.

With the steady tide of cyberattacks, it is essential that home users remain protected. As smartphones are increasingly at the center of people’s digital lives, empowering users to manage their security via mobile devices is critical. To effectively address home users’ requirements and provide top-level protection ESET is introducing LiveGuard, integrated within ESET Smart Security® Premium. LiveGuard provides an additional proactive layer of protection against never-before-seen types of threats. Additionally, ESET NOD32 Antivirus, ESET Internet Security and ESET Smart Security® Premium offer improved protection and a host of new features for customers. Recognizing how our digital lives have changed over the past year, these upgrades focus on banking and payment protection, ransomware protection, parental control and password management. At the center of the new suite of ESET products is ESET HOME, a new and improved management platform that makes it easy to manage security at home whenever and wherever required. ESET HOME provides users with a complete overview of all their ESET solutions for Windows and Android devices in one place, giving users total visibility of the current protection status of the various devices connected to their accounts. Accessible via web portal and mobile app, the ESET HOME platform is designed with mobile users in mind and built for on-the-go security management. The application enables users to add, manage and share licenses with family and friends, and to manage Anti-Theft, Parental Control and Password Manager via the web portal. Other key updates in the new product suite include:
  • Protection improvements — Banking & Payment Protection will now have the option to run by default, protecting any supported browser with a hardened mode. Ransomware Shield has been bolstered with enhanced behavior-based detection techniques. Exploit Blocker has been improved to cover additional malicious techniques.
  • ESET HOME — Parents can use ESET HOME to share licenses with family and friends or to monitor their children’s online activity and control their screen time in Parental Control (via the ESET HOME web portal).
  • LiveGuard — Integrated with ESET Smart Security® Premium, LiveGuard provides an additional proactive layer of protection against never-before-seen types of threats, shielding users from the malware before its code executes. This service, personalized for each user, analyzes suspicious files, including documents, scripts, installers and executable files, in a safe sandbox environment.
  • Password Manager — Available with ESET Smart Security® Premium, Password Manager has been completely redesigned for improved security and ease of use. Password Manager is available in all major browsers as a browser extension and on Android and iOS devices as a native application. New features include support for KeePass and Microsoft Authenticator.

Mária Trnková, consumer & IoT segment director at ESET, commented, “We are incredibly excited about this launch and to provide consumers with the very latest in cybersecurity protection. The updated product suite, including our new LiveGuard feature and the impressive ESET HOME platform puts users firmly in control of their home cybersecurity needs and instills them with the confidence needed to manage multiple devices on the go. After more than a year of being heavily reliant on technology, and with the threat landscape constantly evolving, it is vital to us that our consumer users are protected with cutting-edge solutions that are easily accessible and best in class in terms of user experience.”

To find out more about all the new features and improvements coming in the latest version of our consumer offering, head to https://www.eset.com/hk/.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×