ADVERTISEMENT

'EternalBlue' still popular exploit among cybercriminals: Seqrite

'EternalBlue' still popular exploit among cybercriminals: Seqrite

Published
Hot News Text
2 min read
'EternalBlue' still popular exploit among cybercriminals: Seqrite
Pune, May 9 (IANS) With a detection count of over seven million in March 2018 globally, the leaked exploit developed by the US National Security Agency (NSA) "EternalBlue" will continue to be a popular threat actor for cybercriminals to infiltrate into systems and make financial gains this year, a new report said on Wednesday.
Seqrite, the enterprise security solutions brand of Quick Heal Technologies, in its research report "EternalBlue--A Popular Threat Actor of 2017-2018"--revealed that it has detected more than 18 million hits of the exploit in advanced cyberattacks like ransomware and distributed cryptomining campaigns.
"EternalBlue", considered as one of the deadliest exploits, was leaked by the hacking group known as "The Shadow Brokers" in April 2017.
Seqrite said that it observed the first impression of "EternalBlue" in May 2017 with the outbreak of WannaCry ransomware. The detection count gradually increased as WannaCry started spreading to wider geographies.
After the global WannaCry cyber attack, several new Proof of Concept (POC) exploits were discovered on the Internet for "EternalBlue".
With an easy availability, hackers were observed using the exploit in the ensuing attacks like EternalRocks worm, Petya (also known as NotPetya) and BadRabbit ransomware.
"Exploits leaked by 'The Shadow Brokers'--especially EternalBlue--have helped hackers to launch some of the biggest cyberattacks," said Sanjay Katkar, Joint Managing Director and Chief Technology Officer at Quick Heal Technologies limited.
Seqrite also discovered that "EternalBlue" is now being deployed by hackers to distribute cryptomining campaigns like Adylkuzz, Zealot and WannaMine.
"While hackers using 'EternalBlue' to launch ransomware attacks is widely known, it is interesting to note that cybercriminals are now leveraging this tool to distribute cryptomining campaigns. What is worrisome is that a large number of endpoints continue to be unprotected and vulnerabilities remain unpatched," Katkar added.
Earlier in 2018, Quick Heal said that ransomware grew 300 per cent in 2017 in comparison with 2016 and in 2018 such attacks are set to become even more vicious.
--IANS
sku/and/bg

(This story was auto-published from a syndicated feed. No part of the story has been edited by The Quint.)

(This story was auto-published from a syndicated feed. No part of the story has been edited by The Quint.)

(The Quint is available on Telegram. For handpicked stories every day, subscribe to us on Telegram)

We'll get through this! Meanwhile, here's all you need to know about the Coronavirus outbreak to keep yourself safe, informed, and updated.

Liked this story? We'll send you more. Subscribe to The Quint's newsletter and get selected stories delivered to your inbox every day. Click to get started.

The Quint is available on Telegram & WhatsApp too, click to join.

ADVERTISEMENT
ADVERTISEMENT
Stay Updated

Subscribe To Our Daily Newsletter And Get News Delivered Straight To Your Inbox.

Join over 120,000 subscribers!
ADVERTISEMENT