Video calls have become very popular following social isolation measures and home restrictions, as they allow us to stay close to family, friends, and colleagues. Knowing that cybercriminals do not hesitate to use any opportunity to spread malware, Kaspersky experts investigated the current threat landscape that uses these online meeting apps as bait.
Kaspersky's analysis found that Skype is the most used brand by cybercriminals in their scams, with a total of 120,000 suspicious files disguised as the traditional video calling application. The survey then identified another 1,300 malicious files disguised as Zoom (42%), WebEx (22%), GoToMeeting (13%), Flock (11%), and Slack (11%).
Percentage of threats that spread malware using the names of popular video conferencing apps (scams using Skype were not included, as it leads by a wide margin).
Among the suspicious files, simple imitations of real programs were found, and among the truly malicious files were some malware. Two adware families stand out – programs that display advertisements abusively: DealPly and DownloadSponsor.
Generally, adware infects a device when the user downloads an app from outside the official app store. Although this program doesn't cause financial losses, it still represents a privacy risk. .
Furthermore, Kaspersky experts found malware disguised as .lnk files (program shortcuts, which are the desktop icons for quick access to frequently used programs). The vast majority of detections were of Exploit.Win32.CVE-2010-2568, an old but popular malicious program that allows cybercriminals to infect devices with other malicious programs.
“We haven’t identified a drastic increase in the number of attacks or in the number of files disguised as popular video calling applications. These attacks are moderate. At the same time, we consider it important to inform people about the existence of such threats. In the current scenario, when most of us are working from home, it is extremely important to ensure that what we use as a tool for online meetings is downloaded from a legitimate source, configured correctly, and without serious vulnerabilities,” says Denis Parinov, security expert at Kaspersky.
SOURCE:
SECURITY BRAZIL





