Skip to content

Trickbot botnet grows quieter, Emotet botnet gets busy

Botnets are one of the top cyber threats to look out for in 2020, according to Forrester, and with a dispersed, remote workforce, many organizations may be more vulnerable than ever before. Botnet operations can become incredibly sophisticated, carrying out a wide range of illicit activities: collecting browser information, harvesting passwords, stealing login credentials from banking websites, or deploying ransomware.

One of the most infamous botnets is Trickbot, which has compromised over a million computing devices around the world since 2016. Earlier this month, ESET helped to disrupt Trickbot in a global collaboration with Microsoft and other partners.

ESET first detected Trickbot in late 2016, and it has since been recognized as one of the most prevalent banking malware families across the globe. The botnet has targeted several different industries – including education, real estate and government – but the most frequently targeted seems to be the financial sector. With its capabilities for stealing banking credentials and performing fraudulent transactions, Trickbot is a threat to financial data at any business, so businesses must be prepared to protect themselves against this threat.

Trickbot is extremely versatile, with a modular design that allows it to perform an array of malicious actions using a variety of plugins. ESET analyzed nearly 30 different plugins, of which over a third were infostealers. One of these, named injectDll, uses browser hooks to steal user credentials from banking websites, allowing Trickbot’s operators to perform fraudulent bank transfers and steal money from individuals and organizations. Another plugin, known as pwgrab, steals passwords from Filezilla, Microsoft Outlook and WinSCP. These are just two examples of the damage Trickbot could wreak on businesses once it has infested your systems.

A prolific distributor of ransomware – one of the largest threats to the upcoming US election – Trickbot is also a potential danger to election infrastructure. Operators of the botnet could infest a computer system used to report results or store voter rolls, sowing high levels of chaos and distrust among the electorate. The collaborative operation to disrupt Trickbot helped cut off key infrastructure, meaning that the botnet operators are no longer able to initiate new compromises or deploy ransomware as easily.

ESET telemetry shows Trickbot detection numbers plummeting in tandem with the disruption effort:

Figure 1: Trickbot detection numbers from July to October 2020

While the threat of Trickbot seems to have lessened for now, maintaining vigilance for other botnet attacks is still paramount. At the same time as Trickbot’s disruption, the rising detections in ESET telemetry for the Emotet botnet indicated a ramping up of Emotet’s activities, even downloading Trickbot, as well as Qbot, malware:

Figure 2: Emotet detection numbers from July to October 2020

The Emotet malspam campaign was recently bombarding users in Greece, Japan and Lithuania:

Figure 3: Countries most targeted by Emotet from July to October 19, 2020

Facing such a threat may seem like a daunting task, but there are a few ways businesses can protect themselves from botnet operations. Primarily, it is crucial to protect all endpoints with a security solution that has robust detection modules, such as ESET Endpoint Security. Businesses also need to ensure that their networks are always patched with the latest security updates to avoid falling victim to vulnerabilities that threat actors may exploit. Additionally, remote ports can provide an access point for hackers, so restrict access as far as possible – especially to remote desktop protocol (RDP) ports.

To find out more about ESET’s efforts to disrupt the Trickbot botnet, read ESET takes part in global operation to disrupt Trickbot on WeLiveSecurity.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Partner achieves #1 rank in leading Japanese customer satisfaction survey for eighth consecutive year

Bratislava – Slovakia, October 21, 2020 – ESET, a global leader in IT and cybersecurity, today announces that its exclusive partner in Japan, Canon Marketing Japan Inc., has received the #1 ranking in the security products category of the Nikkei Computer’s customer satisfaction survey for the eighth year in a row.

Nikkei Business Publications, Inc. is the largest content provider in the country. The prestigious 2020 survey was completed by the IT departments of over 12,000 businesses and local governments, assessing providers across seven groups of criteria; Overall Satisfaction, Performance & Functionality, Reliability, Operability, Cost, Support and Intent to Renew. Respondents assigned satisfaction scores to their selected products on a scale from Satisfied to Dissatisfied for each sub-category. Final scores were calculated as an average of all given points in each respective sub-category.

Canon Marketing Japan Inc. won first place in the survey and is noted as particularly competitive in pricing, performance and functionality – having exceeded the industry average for the last five years. ESET’s portfolio of Endpoint Security solutions, a central part of Canon Marketing Japan Inc.’s security product portfolio, combines multi-layered antivirus capabilities with intuitive software and a low system footprint. The result is award-winning, comprehensive protection for organizations of all sizes.

Hiroya Kuroda, Country Manager at ESET Japan, commented, “We are extremely pleased for our Partner, Canon Marketing Japan Inc., and our products to be recognized in Japan for helping to support cutting-edge security services. The threat landscape faced by businesses today is ever evolving and marked by never-ending attacks. To stay ahead of the game, ESET has doubled its R&D investment worldwide over the past five years with almost 40 per cent of employees working in research and development. This has allowed us to protect our customers with industry-leading security solutions that are innovative, powerful, reliable and easy to use.”

Learn more about ESET Endpoint Security solutions here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

CVSS 8.6 DoS Vulnerability in Mitsubishi Electric MELSEC iQ-R Series CPU

Our Researchers Discover Another Vulnerability 

As part of our mission to secure the world’s OT, IoT and Cyber Physical infrastructures, we invest resources into offensive research of vulnerabilities and attack techniques.

CVE-2020-16850 (US ICS-CERT) is a CVSS 8.6 remote CPU DoS vulnerability in Mitsubishi Electric iQ-R Series that has been discovered by SCADAfence researcher Yossi Reuven.

Mitsubishi Electric is one of the world’s leading electronics and electrical equipment manufacturing companies, and is in use by many of our customers. We have been working with Mitsubishi Electric for the last few months in handling multiple vulnerabilities, and on October 8th, Mitsubishi Electric published an official security advisory reporting this vulnerability and its mitigations.

About The Vulnerability – CVE-2020-16850

MELSEC iQ-R Series is Mitsubishi Electric flagship product line – designed for high productivity automation systems. iQ-R CPUs’ communication with GX Works 3 (Engineering software package) is done via Mitsubishi Electric proprietary protocol MELSOFT (which works on both TCP and UDP).

single specially crafted packet sent by an attacker over the MELSOFT UDP protocol on port 5006 will cause a denial-of-service (DoS) vulnerability due to uncontrolled resource consumption (CWE-400). The PLC’s CPU will get into fault mode, causing a hardware failure (error code: 0x3C00 – hardware failure). The PLC then becomes unresponsive and requires a manual restart to recover.

What SCADAfence Recommends Vendors To Do

Perform an Industrial Vulnerability Management Process

Please refer to our guide on this topic: https://www.scadafence.com/public-preview-a-comprehensive-guide-to-industrial-device-patching/

Monitor for Unauthorized Network Activity and Exploitation

Some devices will always remain unpatched. Monitoring is an early warning system that allows you to act before attackers have gained full control over your network.

Upgrade to the Latest Firmware (When Available)

Currently no firmware update is available (will be released soon by Mitsubishi Electric)

Prevent Unauthorized and Untrusted Access

– Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.

– Use within a LAN and block access from untrusted networks and hosts through firewalls.

Block UDP Port 5006 and Use MELSOFT TCP

MELSOFT is an engineering software for Mitsubishi PLCs and gives users the option to use either the (connectionless) UDP and (connection-oriented) TCP protocols for programming and configuring the devices. SCADAfence recommends to block Block UDP port 5006 since the cyberattack leverages the connectionless UDP protocol and can cause the PLCs to stop functioning and cause a denial of service. Instead, users should use the TCP protocol for communicating with devices in the shop floor or the control network.

Special Thanks & Recognition

The SCADAfence Research team would like to thank the Mitsubishi Electric team for a speedy vulnerability reporting process even during the challenging COVID-19 times.

SCADAfence is committed to continued research of offensive technologies and development of new defensive technologies.

Exploit PoC

We wrote a Python POC (GPLv3) script of the exploit in action.

Currently, there’s no patch available. As a result, we limit the access to the exploit to vetted individuals only. The exploit is only available for educational and legal research purposes.

Warning: The script will crash the PLC’s CPU – do not use it in production.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

Safetica 9.5 – Ready for the cloud age

Download the report now!

In the next few weeks, we will be launching a brand new version of Safetica DLP. The new features allow Safetica to keep up with the undeniable trend of using cloud services for storing and working with sensitive data.

Take a quick look at our webinar recording and find out more from our Safetica Team.

E-mail DLP policies for Office 365

We’re very excited to see that so many of our customers are adopting Safetica Office 365 features to get a better picture of their cloud data. We’re also excited to let you know that Safetica 9.5 is now taking Office 365 integration to a whole new level with the introduction of e-mail DLP policies for Exchange Online! Protect your data on whichever devices your users use to communicate. In addition to auditing e-mail sent from work computers, home computers, and mobile devices, you can now enforce DLP policies over data sent from them.

Data anywhere, improved

We’re still fully committed to our ‘data anywhere’ philosophy that we introduced last autumn, and we’re pushing it even further. Safetica 9.5 improves on the previously introduced persistent file tagging with metadata technology, making it more robust and ready for wide use. If you hesitated before, now is the perfect time to embrace the new Safetica classification to ensure the audit and protection of your data anywhere.

Try Safetica with Azure SQL

Early adopters of cloud technologies will surely appreciate that Safetica can now also run on Azure SQL databases. Enjoy the benefits of hosting your data in the cloud, such as scalability of storage and performance, and easier database backup. This makes for an attractive and powerful alternative to running a limited instance of Microsoft SQL Server Express.

Safetica 9.5 – The most important changes

  • Email DLP policies for Office 365 / Exchange Online
  • Revamped automatic Office 365 integration configuration
  • Enhanced persistent file tagging using metadata-based context DLP technology
  • Support for Azure SQL database hosting
  • New built-in sensitive content templates for Brazil, Ecuador, Singapore
  • Improved support of security groups and large Active Directory structures
  • Improved support for end-to-end encrypted web sites, e.g. Telegram, WhatsApp, etc.
  • Revised security issues, charts and summaries in the Security Audit report
  • macOS device control in non-restrictive, alert-only mode
  • Improved file audit and Safetica client management on macOS
  • Coronavirus and home office

Author Ján Lakatoš

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Safetica
Safetica is to provide small and mid-sized companies with the same quality data protection that corporations have – affordably, and without any additional IT administration or disruptions in operation.

Nobel laureate Kip Thorne chairs the ESET Science Award International jury in 2020

BRATISLAVA – The laureates of this year’s ESET Science Award will be decided by the International jury chaired by a Nobel laureate, Kip Thorne. An American physicist known for his work in gravitational physics and astrophysics, Thorne is one of the three scientists who were awarded the 2017 Nobel Prize in Physics. He entered the world of science fiction as an executive producer and scientific advisor on the movie Interstellar. Together with other members of the jury, he will select the laureates in two categories of the ESET Science Award: Outstanding Individual Contributor to Slovak Science and Exceptional Young Scientist in Slovakia under the Age of 35.

The International jury of renowned scientists is one of the pillars of the ESET Science Award. When evaluating finalists and selecting laureates, they assess various parameters of scientific work, such as current scientific research results and publications, measurable scientometric data, involvement in international scientific projects, communication and popularization, cooperation with other scientific disciplines, the principles of scientific ethics, the potential impact of scientific work on other areas of life, and as reference point for close collaborators or students.

The chair of the International jury in 2019 was the German biophysicist Erwin Neher, laureate of the Nobel Prize in Physiology or Medicine in 1991 for his development of the patch-clamp technique for detection of ion activity in the cell membrane. Kip Thorne will fill the role of chair on the International jury in 2020. He is known for his work in gravitational physics and astrophysics, with an emphasis on relativistic stars, black holes and gravitational waves. He and two other scientists were awarded the 2017 Nobel Prize in Physics for the first direct detection and observation of gravitational waves. Since his retirement, Thorne has taken new directions in his career, including film, where he was not only a consultant on the blockbuster movie Interstellar but also a co-author of its original concept.

The International jury consists of the following renowned scientists:

Hana Dvořaková is a Czech chemist and philanthropist who has dedicated her scientific career to the development of substances that can be used against the HIV virus. In 2013, she and her husband Dalimil founded the Experientia Foundation, which focuses on supporting young scientists in the field of organic, bioorganic and medicinal chemistry with the aim of making Czech chemistry among the world’s best.

Rolf-Dieter Heuer is an experimental particle physicist. Most of his scientific work is related to the study of electron-positron reactions, the development of experimental techniques, and the construction and operation of large detection systems. Professor Heuer was the Director-General of CERN from 2009 to 2015. More recently, he has served as the chair of the European Commission’s Group of Chief Scientific Advisors.

Ralf Riedel focuses on two main areas – molecular synthesis of advanced ceramics at ultra-high temperatures and their energy-related applications, and ultra-high-pressure synthesis of new materials.

Fiona Watt is a British scientist, internationally known for her work in stem cell research. She has explored the role of stem cells in maintaining the skin, which is constantly repaired and replaced throughout our lifetime. She has discovered factors that control how stem cells differentiate, shedding light on how this process might be disrupted in mouth and skin cancer.

Tibor Krisztin is a Hungarian mathematician working on dynamical systems and differential equations. Since 2000, he has been a professor at the Bolyai Institute of the University of Szeged, where he was also the director from 2011 to 2014.

The third category of the ESET Science Award, Outstanding Academic, is decided by a committee composed of representatives of Slovak universities. The award laureates will be announced via an online event on the ESET Science Award Facebook profile on Wednesday, October 14, at 1:30 pm (CEST).

Further information is available at www.esetscienceaward.sk.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.