The share of corporate devices compromised with data-stealing malware has increased by one third since 2020, according to Kaspersky Digital Footprint Intelligence.
Twenty-one percent of employees whose devices were infected ran the offending malware repeatedly.
Kaspersky reveals that corporate devices are facing a growing threat from infostealers. According to data extracted from data-stealing malware log-files available on the dark web, the share of corporate users compromised with such malware has increased by 34% since 2020.
Kapersky concluded that every second device (53%) in 2023 was infected with credential-stealing malware was corporate, based on data indicating that the biggest share of infostealer infections was found in the Windows 10 Enterprise version.
After infecting a single device, cyber-criminals can gain access to all accounts – both personal and corporate. According to Kaspersky statistics, one log file contains credentials with a corporate email as a login to an average of 1.85 corporate web applications, including web mail applications, customer data processing systems, internal portals, and more.
“We were curious to know if corporate users re-open malware, thereby allowing cybercriminals to again access data collected from a previously infected device without needing to infect it again,” comments Sergey Shcherbel, expert at Kaspersky Digital Footprint Intelligence.
He added: “To investigate this, we examined a sample of log-files containing data likely related to 50 banking organizations across various regions. We found 21 percent of employees reopened the malware again, and 35 percent of these reinfections occurred more than three days after the initial infection.
Recommended reading
- YouTube Introduces Tool to Flag AI Content Ahead of Global Elections
- Report: Data-Stealing Malware Threatens Millions Worldwide
- Is Google Promoting Malware in Search?
“This may indicate several underlying issues, including insufficient employee awareness, ineffective incident detection and response measures, a belief that changing the password is sufficient if the account has been compromised, and a reluctance to investigate the incident.”
To minimise the impact of a data leak caused by infostealer activity, we suggest you follow these steps:
- Change passwords for compromised accounts immediately and monitor them for suspicious activity
- Advise potentially infected users to run antivirus scans on all devices and remove any malware;
- Monitor dark web markets for compromised accounts to detect compromised accounts before they affect the cybersecurity of customers or employees. A detailed guide on setting up monitoring can be found here
- Utilise Kaspersky Digital Footprint Intelligence to detect potential threats and take prompt action





