This dangerous malware pretends to be some of your most-used business software tools, so watch out

An abstract image of digital security.
(Image credit: Shutterstock) (Image credit: Shutterstock)

Hackers are now using an old form of banking malware to launch damaging ransomware attacks, new research has claimed.

In their latest Monthly Threat Pulse, cybersecurity experts from NCC Group broke down how a well-known banking malware called Carbanak returned in ransomware attacks.

“First emerging in 2014, Carbanak malware has been used by ransomware gangs to infiltrate financial systems after deploying advanced phishing techniques to compromise bank employees,” the researchers explained. “The malware allows threat groups to gain access to networks through human entry points and criminals to take control of payment processing services.”

Impersonating business software

While a decade old, Carbanak’s popularity dwindled over the years. However, the malware did evolve and is now experiencing a resurgence. It was adopted to incorporate attack vendors and techniques to diversify its effectiveness, it was said.

Now, hackers are using compromised websites to host the malware, impersonating popular business-related software such as HubSpot, Veeam, or Xero.

Carbanak gained notoriety thanks to its data exfiltration and remote control features, TheHackerNews reported. It started off as banking malware and was observed being used by the FIN7 cybercrime syndicate.

As an attack vector, ransomware is going from strength to strength. Last month, a total of 442 ransomware incidents were reported, up from 341 a month ago, the report states. For the year, ransomware attacks were reported 4,276 times, which is "less than 1000 incidents fewer than the total for 2021 and 2022 combined (5,198)."

Industrials (33%), consumer cyclicals (18%), and healthcare (11%) were the most targeted sectors, located mostly in North America (50%), Europe (30%), and Asia (10%). The most popular ransomware families are LockBit, BlackCat, and Play (responsible for 206 - 47% of all attacks).

"With one month of the year still to go, the total number of attacks has surpassed 4,000 which marks a huge increase from 2021 and 2022, so it will be interesting to see if ransomware levels continue to climb next year," Matt Hull, global head of threat intelligence at NCC Group, said.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Fraud
Hackers are tricking victims into scam-yourself attacks with fake tutorials, CAPTCHAs, and updates
Ransomware attack on a computer
Ransomware attacks surged in 2024 as hackers looked to strike faster than ever
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all