Community Short Facts - March 2022
Log4j opens new doors
Avast publishes the Q4/2021 Threat Report. In particular, the abuse of the Log4j vulnerability by coin miners, remote access Trojans (RATs), botnets, ransomware and APTs put pressure on CISO departments in December 2021. In addition, Avast Threat Researchers observed the resurgence of the Emotet botnet and a 40 percent increase in coin miners - a risk to both consumers and businesses. The Q4 results also show an increase in adware, tech support scams on desktops, as well as subscription scams and spyware on Android devices targeting consumers.
At the same time, Avast recorded less ransomware and RAT activity. The vulnerability in the Java logging library Log4j proved to be extremely dangerous for organizations, as the library is ubiquitous and easy to exploit. Avast Threat Researchers observed that coinminers, RATs, bots, ransomware and APT groups have abused the vulnerability. Various botnets, including the infamous Mirai botnet, exploited the vulnerability. However, most of the bot attacks were merely tests of the vulnerability.