Malware, botnets, exploits and other malicious cyber-activity have all increased more than 100% in the second quarter of 2022, according to Nuspire research.
In its Q2 2022 Quarterly Threat Report, the managed security services provider gathered the data from global sources, client devices and third parties.
Nuspire said they are seeing a major 25% boost in malware events, which is doubling that of botnet detections and a rise in exploit activity of 150% versus the first quarter of 2022.
Researchers discovered that the Log4j vulnerability Log4Shell contributed much of the surge in exploit activity due to the persistent threat posed by bugs in the software, discovered at the end of December 2021.
At the time, experts warned that the prevalence of the software, and the difficulty in finding the bugs, means it may continue to be a problem for years to come. The National Cyber Security Centre (NCSC) released a programme in January to make it easier for organisations to scan for potential malware vulnerabilities in their systems.
JR Cunningham, Chief Security Officer at Nuspire, commented: “We witnessed a stunning escalation in threat activity in Q2, and while it’s not a surprise given increased attack opportunities like remote work, it’s still a worrying development and one we cannot ignore.
“Attackers have always looked for the easiest way to profit from their targets, and because basic attacks like phishing continue to work, it’s clear organisations need to shore up their fundamental security practices like patching and user awareness training.
“It’s also critical organisations conduct regular reviews of their security programs to safeguard against a nonstop flow of potentially serious disruptive threats.”
What is Log4shell?
According to the NCSC, Log4shell is a critical vulnerability in the widely used logging tool Log4j. The tool is used by millions of computers globally to run online services, making the prevalence of the vulnerability a real concern.
The NCSC noted that a large section of society, including organisations, governments, and individuals, are likely to be affected by it in some way as it is being utilised across software applications and online services,
Despite fixes being issues to try and combat the issue, many are still unsure of the dangers and how vulnerable they are, especially individuals who are likely to believe they are not worth targeting.
However, the NCSC warned that if the issue is not fixed, attackers could break into systems, steal passwords and logins, extract data, and infect networks with malicious software.
The botnet problem
As well as Log4Shell, botnets have a profound impact on internet users, including individuals and businesses.
A study from Check Point Research (CPR) has revealed that the the Emotet botnet has held on to its spot as the most widely used malware, despite being effectively removed from the internet last year.
The news comes despite a 50% drop in its global impact in July compared to June. CPR estimated that Emotet currently affects 7% of organisations worldwide.
Researchers also warned that the botnet has added new features and capabilities, such as its latest credit card stealer module developed, and adjustments done in its spreading systems.
Recommended
- Traveltech for Scotland scores Catalonian partnership
- Robots to streamline windfarm inspection processes
- Scottish firms welcome CodeClan youth academy interns
When Emotet first emerged, it fast become one of the largest used by cybercriminals globally. The botnet spread onto computers, generally, through malicious email attachments.
Once a system was infected, Emotet will spread itself to other computers. From there, command and control servers could be used to send it updates and additional malware.
Craig Robinson, Research Vice President for Security Services at IDC, said: “Organisations continue to struggle balancing the need to protect against an onslaught of threats with the concurrent need for employees to properly manage digital sovereignty requirements.
“This is why we’re seeing the market becoming more receptive to increasing and enhancing internal security training. This combined with tools like multi-factor authentication and endpoint detection, as well as services like MDR, can make all the difference in an organisation’s security posture.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





