Mobile Malware And IoT Attacks Surge, Zscaler Report Reveals
Mobile Malware And IoT Attacks Surge, Zscaler Report Reveals
Zscaler, Inc has released its 2024 Mobile, IoT, and OT Threat Report, revealing alarming trends in cyber threats from June 2023 to May 2024. The findings underscore the urgency for organisations to reevaluate and secure their mobile devices, IoT devices, and operational technology (OT) systems.
Zscaler, Inc發佈了《2024年移動、物聯網和物聯網威脅報告》,揭示了2023年6月至2024年5月網絡威脅的驚人趨勢。這些發現突顯了各組織重新評估和保護其移動設備、物聯網設備和運營技術(OT)系統的緊迫性。
The report identifies over 200 malicious apps on the Google Play Store, which collectively have more than 8 million installs globally. Zscaler's cloud platform blocked 45% more IoT malware transactions compared to the previous year, highlighting the continued spread of botnets across IoT devices.
該報告發現谷歌Play商店中有200多款惡意應用程序,這些應用程序在全球的總安裝量超過800萬。與去年相比,Zscaler的雲平台阻止的物聯網惡意軟件交易增加了45%,這凸顯了殭屍網絡在物聯網設備上的持續傳播。
"Cybercriminals are increasingly targeting legacy exposed assets, often acting as gateways to IoT and OT environments, leading to data breaches and ransomware attacks," said Deepen Desai, Chief Security Officer at Zscaler. "Mobile malware and AI-driven vishing attacks are adding to this threat, making it crucial for organisations to adopt AI-powered zero trust solutions to shut down all potential attack vectors."
Zscaler首席安全官Deepen Desai表示:「網絡犯罪分子越來越多地將遺留的暴露資產作爲目標,這些資產通常充當物聯網和物聯網環境的門戶,導致數據泄露和勒索軟件攻擊。」「移動惡意軟件和人工智能驅動的語音攻擊加劇了這種威脅,這使得組織採用人工智能驅動的零信任解決方案來關閉所有潛在的攻擊載體至關重要。」
The report also highlights the financial motivation behind mobile malware, with cyberattacks becoming more profitable, particularly through extortion and the sale of stolen personal data. Singapore has emerged as the second most targeted country in the APJ region by mobile malware, following India. The rise in spyware in the region has surged by 77% year-on-year. Anatsa, a well-known Android banking malware, has affected over 650 financial institutions, specifically targeting users in countries like Singapore, Germany, Spain, Finland, and South Korea.
該報告還強調了移動惡意軟件背後的財務動機,網絡攻擊變得越來越有利可圖,特別是通過勒索和出售被盜的個人數據。新加坡已成爲亞太及日本地區第二大移動惡意軟件攻擊目標國家,僅次於印度。該地區間諜軟件的增長同比增長了77%。著名的安卓銀行惡意軟件Anatsa已經影響了650多家金融機構,特別針對新加坡、德國、西班牙、芬蘭和韓國等國家的用戶。
Singapore also ranks as the second most impacted country globally by IoT attacks, following the United States. It accounts for 5.3% of all IoT attacks globally. The report outlines the top countries most affected by IoT attacks: the United States (81.3%), Singapore (5.3%), the United Kingdom (2.8%), Germany (2.7%), and Canada (2%).
新加坡還被列爲全球受物聯網攻擊影響最大的國家,僅次於美國。它佔全球所有物聯網攻擊的5.3%。該報告概述了受物聯網攻擊影響最大的國家:美國(81.3%)、新加坡(5.3%)、英國(2.8%)、德國(2.7%)和加拿大(2%)。
Industries most vulnerable to these threats include technology, education, and manufacturing. The education sector saw a significant 136% increase in blocked mobile malware transactions. Manufacturing, for the second consecutive year, experienced the highest volume of IoT malware attacks, accounting for 36% of all IoT malware blocks observed.
最容易受到這些威脅影響的行業包括科技、教育和製造業。教育部門被封鎖的移動惡意軟件交易顯著增加了136%。製造業連續第二年經歷了最多的物聯網惡意軟件攻擊,佔觀察到的所有物聯網惡意軟件封鎖的36%。
The report also draws attention to the growing risks associated with OT systems. Once isolated from the internet, OT and cyber-physical systems have become integrated into enterprise networks, creating a large attack surface for external threats. Zscaler highlights the need for organisations to secure their mobile endpoints, IoT devices, and OT systems to mitigate the risks of cyberattacks.
該報告還提請注意與Ot系統相關的日益增長的風險。一旦與互聯網隔離,物聯網和網絡物理系統已集成到企業網絡中,從而爲外部威脅創造了巨大的攻擊面。Zscaler 強調組織需要保護其移動端點、物聯網設備和 Ot 系統,以降低網絡攻擊的風險。
In response, Zscaler advocates for the adoption of zero trust architecture, enabling secure access from any device, location, and application. This approach reduces cyber risks while supporting hybrid work environments, remote access, and the use of IoT and OT connectivity.
作爲回應,Zscaler 主張採用零信任架構,支持從任何設備、位置和應用程序進行安全訪問。這種方法降低了網絡風險,同時支持混合工作環境、遠程訪問以及物聯網和物聯網連接的使用。
The 2024 report underscores the critical need for organisations to enhance their security measures to protect against these evolving and pervasive cyber threats.
2024年的報告強調,各組織迫切需要加強其安全措施,以防範這些不斷演變和普遍存在的網絡威脅。