ESET Threat Report: Attempts to exploit MS Exchange

ESET Research releases its T3 2021 Threat Report, summarising key statistics from ESET detection systems and highlighting notable examples of ESET cybersecurity research, including exclusive, previously unpublished updates on current threats. The latest issue of the ESET Threat Report (covering September to December 2021) sheds light on the most frequent external attack vectors, the reason behind the rise of email threats, and shifts in the prevalence of certain types of threats due to fluctuating exchange rates of cryptocurrencies.Researchers reveal that the ProxyLogon vulnerability was the second most frequent external attack vector in ESET’s 2021 statistics, right after password-guessing attacks. Microsoft Exchange servers fell under siege again in August 2021, with ProxyLogon’s “younger sibling”, named ProxyShell, which has been exploited worldwide by several threat groups. As the final threat report of the year 2021, it also comes with commentary on the broader trends observed throughout the year as well as predictions for 2022 by ESET malware researchers and detection specialists.Further research in the report revolves around the Log4Shell vulnerability, yet another critical flaw in the ubiquitous Log4j utility that surfaced in mid-December. IT teams everywhere were sent scrambling, again, to locate and patch the flaw in their systems. “This vulnerability, scoring a 10 on the Common Vulnerability Scoring System, put countless servers at risk of complete takeover – so it came as no surprise that cybercriminals instantly started exploiting it. Despite only being known for the last three weeks of the year, Log4j attacks were the fifth most common external intrusion vector in 2021 in our statistics, showing just how quickly threat actors are at taking advantage of newly emerging critical vulnerabilities,” explained Roman Kováč, Chief Research Officer at ESET.The exclusive research presented in the ESET Threat Report T3 2021 provides previously unpublished information about APT group operations. This time, researchers offer updates on the activity of cyberespionage group OilRig; latest information on in-the-wild ProxyShell exploitation; and new spearphishing campaigns by the infamous cyberespionage group the Dukes.According to ESET telemetry, the end of the year was also turbulent for Remote Desktop Protocol (RDP) attacks, which escalated throughout all of 2020 and 2021. The numbers from the last weeks of T3 2021 broke all previous records, amounting to a staggering yearly growth of 897% in total attack attempts blocked – despite the fact that 2021 was no longer marked by the chaos of newly imposed lockdowns and hasty transitions to remote work.Ransomware, previously described in the ESET Threat Report Q4 2020 as “more aggressive than ever” surpassed the worst expectations in 2021, with attacks against critical infrastructure, outrageous ransom demands and over USD 5 billion worth of bitcoin transactions tied to potential ransomware payments identified in the first half of 2021 alone. As the bitcoin exchange rate reached its highest point in November, ESET experts observed an influx of cryptocurrency-targeting threats, further boosted by the recent popularity of NFTs. 

To read more exclusive features and latest news please see our Q4 issue here.

Media contact

Rebecca Morpeth Spayne,
Editor, Security Portfolio
Tel: +44 (0) 1622 823 922
Email: [email protected]

Georgina Turner image

Georgina Turner

Sales Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Copyright: Security Buyer

AmiViz Partners with Titania

AmiViz announced a strategic distribution agreement with Titania. This collaboration underscores a shared commitment to enhancing…
Malik Alyousef, Co-founder & COO, Mozn

Mozn Unveils a New Generation of AI Fraud Prevention

FOCAL by Mozn strengthens its Fraud Prevention Suite with Device Fingerprinting, Fraud Analytics, and Fraud Management as a Service…
NetApp

NetApp Appoints Suhail Hasanain

NetApp is pleased to announce the appointment of Suhail Hasanain as the new Regional Director for the Middle East and Africa region…
Axis Communications Riyadh website

Axis Communications opens new office and experience centre in Saudi Arabia

Axis Communications has officially inaugurated its new office and Axis Experience Centre in Riyadh, Saudi Arabia.
John Maddison website

Fortinet launches Lacework FortiCNAPP to enhance cloud-native security

In an advancement in cybersecurity, Fortinet has announced Lacework FortiCNAPP, providing organisations with visibility and security.
GITEX Global 2024 website

GITEX GLOBAL 2024: AI revolution drives strategic tech innovation

GITEX GLOBAL 2024 concluded on Friday, showcasing artificial intelligence (AI) as a transformative force driving business and economic growth
Perimeter website

Securing Boundaries in the Middle East

Perimeter security has become an integral part of protecting sensitive infrastructure across the Middle East.
SentinalOne

SentinelOne and Lenovo Collaborate

SentinelOne and Lenovo today announced a multi-year collaboration to bring AI-powered endpoint security to millions of Lenovo…
Gunnebo

Gunnebo Safe Storage at City Walk, Dubai

Gunnebo Safe Storage solutions have been specified for Private Vaults for Safe Deposits in Dubai’s premier lifestyle destination, City Walk..
Gallagher

Gallagher Security expands footprint in the Middle East

Gallagher Security is strengthening its foothold in the Middle East with the appointment of three new staff members joining their…
Scroll to Top