资源描述:
《2016年金融网络威胁分析报告》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、FINANCIALCYBERTHREATSIN2016February,2017KasperskyLabKasperskyLabIntroductionandKeyFindingsThefinancialcyberthreatlandscapeisconstantlychanging.Inthelastcoupleofyears,financialcybercriminalshaveshiftedtheirfocusfromattacksagainsttheprivateusersofonlinebanking,e-shopsa
2、ndpaymentsystems,toattacksontheinfrastructureoflargeorganizations:banksandpaymentprocessingsystems,alongwithretailers,hotelsandotherbusinesseswherePOSterminalsarewidelyused.Thisincreaseinthenumberofattacksagainstlargeorganizationscouldbeexplainedbythefactthatalthough
3、thepreparationandexecutioncostsofsuchattacksarerelativelyhigh,theoutcomemaybeahundredtimesgreaterthantheresultofeventhemostsuccessfulmaliciouscampaignagainstprivateusers.ThistheoryhasbeenprovedbytheCarbanakfinancialcybercrimegroupandits“followers”,includingtheso-call
4、edSWIFThackers,whowereresponsibleforthemajorityofbigfinancialcybercrimeincidentsin2016.Usingnon-trivialattackmethods,andreducingtoaminimumtheuseofuniquemalicioussoftwareinfavorofopensourcedtools,thesegroupshavebeenabletostealmillionsofdollarsand,unfortunately,theyhav
5、enotyetbeencaught.However,eventhoughprofessionalcriminalshaveshiftedtheircrosshairstothebigfish,thisdoesn’tmeanthatregularusersandsmallandmedium-sizedbusinessesarenolongeratriskoffallingvictimtofinancialcybercrime.Onthecontrary:afterdetectingadecreaseinthenumberofatt
6、ackedusersin2014and2015,thenumberofvictimsstartedtogrowagainin2016.Thisreportisdedicatedtoprovidinganoverviewofhowthefinancialthreatlandscapehasevolvedduringthelastyear.ItcoversthephishingthreatsthatusersofWindows-basedandmacOS-basedcomputersencounter,andWindows-base
7、dandAndroid-basedfinancialmalware.Thekeyfindingsofthereportare:Phishing:•In2016theshareoffinancialphishingincreased13.14percentagepointsto47.48%ofallphishingdetections.Thisresultisanall-timehighaccordingtoKasperskyLabstatisticsforfinancialphishingcaughtonWindows-base
8、dmachines.•EveryfourthattempttoloadaphishingpageblockedbyKasperskyLabproductsisrelatedtobankingphishing.•Theshareofphishingrelatedt