Facebook Twitter Instagram
    • Privacy Policy
    • Contact Us
    Facebook Twitter Instagram Pinterest Vimeo
    AI Home SecurityAI Home Security
    • Home
    • Home Security
    • Cyber Security
    • Biometric Technology
    Contact
    AI Home SecurityAI Home Security
    Cyber Security

    Rootkit Attack Detections Increase at UAE Businesses

    justmattgBy justmattgJuly 21, 2023No Comments3 Mins Read

    [ad_1]

    Detections of attack attempts using rootkits against business targets in the United Arab Emirates (UAE) have significantly increased in 2023, with 2.6 times more of these types of attacks so far this year in comparison to the same time period in 2022.

    According to research by Kaspersky, the number of rootkit detections grew by 167% in the first five months of 2023. In the Middle East region overall, the increase in detections was measured at 103%.

    Abdessabour Arous, security researcher in the Global Research and Analysis Team at Kaspersky, said some nation-state groups have started to leverage rootkits in their activities, and other groups have followed, as a rootkit can be installed on any hardware or software platforms.

    More Activity Than in Previous Years?

    James Maude, lead security researcher at BeyondTrust says rootkit activity has generally been drowned out by the tidal wave of ransomware threats in recent years. “While we have continued to see some examples, they have become less common in the wild and tend to be used by more niche cybercriminal groups or by nation states conducting espionage activities,” he says.

    But even if they don’t get the same press, they’ve remained popular because they’re used to getting quietly into a machine. “I would say a rootkit is a is a very nice way to stay in a machine with a very small payload and maybe it stays like that for months and months,” Vibin Shaju, general manager for UAE at Trellix, says.

    Shaju also notes that when an attacker gains entry with a rootkit, they have full rights and can do whatever they wish while maintaining persistence, including launching a ransomware attack, downloading a keystroke monitor, or maybe just sitting on the machine and collecting information for however long you can. “So, it is all about getting the base and getting that in place, and a rootkit is a perfect way to hide,” he says.

    An Attackers’ Collection of Tools?

    Described as often appearing as though it’s a single piece of software, rootkits are in reality made up of a collection of tools that allow hackers administrator-level control over the target device. Rootkits have been known to be used in targeted attacks in the past and capabilities to better disguise their actions are always in development.

    Maude says that while it is generally getting harder to create and install rootkits as operating system security architectures evolve to include hypervisor and hardware level isolation, “there are still some loopholes and common mistakes that attackers are able to exploit: most commonly, giving users local admin privileges, and failing to patch systems, provides an attacker with a path to elevate their access and install rootkits which then can cause complete system compromise.”

    [ad_2]

    Source link

    Previous ArticleDDoS Botnets Hijacking Zyxel Devices to Launch Devastating Attacks
    Next Article Azure AD Token Forging Technique in Microsoft Attack Extends Beyond Outlook, Wiz Reports
    justmattg
    • Website

    Related Posts

    Cyber Security

    Name That Toon: Last Line of Defense

    April 16, 2024
    Cyber Security

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024
    Cyber Security

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Add A Comment

    Leave A Reply Cancel Reply

    Facebook Twitter Instagram Pinterest
    • Privacy Policy
    • Contact Us
    AI Home Security © 2025 All rights reserved | Designed By ESmartsSolution

    Type above and press Enter to search. Press Esc to cancel.

    ↑