Summary of trends observed in the last four months of the year published and progress in ESET cybersecurity research illustrated, with exclusive and unpublished updates on current threats
ESET, global leader in the cybersecurity market, published the Threat Report T3 2021, which summarizes trends observed by its detection systems and highlights advances in ESET cybersecurity research, including exclusive, never-before-seen updates on today's most prevalent threats. The latest edition of the ESET Threat Report (September-December 2021) sheds light on the most worrying external attack trends, reasons for the increase in email attacks, and changes in the spread of certain types of threats due to fluctuating cryptocurrency exchange rates.
The ProxyLogon vulnerability was the second most frequent external attack mode in ESET's 2021 statistics, just after password-guessing attacks. Microsoft Exchange servers came under siege again in August 2021, with ProxyShell, ProxyLogon's "little brother", being exploited around the world. This latest threat report for the year 2021 also contains commentary on the broader trends observed throughout the year, as well as predictions for 2022 from ESET researchers.
Further research presented in the Report revolves around the Log4Shell vulnerability, another critical flaw that emerged in mid-December. IT teams around the world were once again busy identifying and patching the flaw in their systems. "This vulnerability, with a score of 10 on the Common Vulnerability Scoring System, put countless servers at risk of complete takeover – so it was no surprise that cybercriminals immediately began exploiting it. Despite only being detected in the last three weeks of the year, Log4j attacks were the fifth most frequent external intrusion vector in 2021 in our statistics, showing how quickly threat actors exploit newly emerging critical vulnerabilities," he explains Roman Kováč, Chief Research Officer at ESET.
Exclusive research presented in the ESET Threat Report T3 2021 includes previously unpublished information on the operations of APT groups. This time, researchers provided updates on the activity of the OilRig cyberespionage group; the latest information on in-the-wild ProxyShell exploitation; and new spearphishing campaigns by the notorious cyberespionage group The Dukes.
According to ESET telemetry, the end of the year was also turbulent for Remote Desktop Protocol (RDP) attacks, which intensified throughout 2020 and 2021. The numbers in the final weeks of the year broke all previous records, with a staggering 897% year-on-year growth in total attack attempts blocked – despite 2021 no longer being characterized by lockdowns and hasty shifts to remote working.
The ransomware, described inESET Threat Report Q4 2020 as “more aggressive than ever,” 2021 has exceeded the worst expectations, with attacks against critical infrastructure, massive ransom demands and over $5 billion in bitcoin transactions linked to potential ransomware payments identified in the first half of 2021 alone. As the bitcoin exchange rate reached its highest point in November, ESET experts observed an increase in threats targeting cryptocurrencies, driven also by the recent popularity of Non-fungible tokens (NFTs).
In the mobile world, ESET has seen an alarming surge in Android banking malware detections, which increased by 428% in 2021 compared to 2020, reaching the levels of adware – a widespread problem on the Android platform. Email threats, the source of many attacks, have seen annual detection numbers more than double. This trend was primarily driven by the increase in phishing emails, which more than offset the rapid decline of Emotet-signed malicious macros in email attachments. Emotet, a notorious Trojan that was dormant for most of the year as detailed in the report, was back in business in Q3.
The ESET Threat Report T3 2021 also reviews the most important discoveries and results obtained by ESET researchers: among these, FontOnLake, new malware that targets Linux; a previously undocumented UEFI bootkit called ESPecter; FamousSparrow, a cyberespionage group that attacks hotels, government agencies and private companies around the world; and many others. The final months of last year also saw ESET researchers publish a comprehensive analysis of all 17 malicious frameworks known to have been used to attack airline networks, and final insights into Latin American banking Trojans.
The report also recaps the numerous talks given by ESET specialists in the last quarter of 2021, and previews their participation in events planned for the SeQCure conference in April 2022 and the RSA conference in June 2022, with the latter showcasing the recent ESPecter discovery.
For further information, please consult theESET Threat Report T3 2021 su WeLiveSecurity.






