The AgentTesla keylogger was identified as one of the most widespread malware strains in October, affecting 7% of organisations globally.
Stats from Check Point’s latest Global Threat Index show a marked rise in the number of malware attacks during October, most notably involving Snakekeylogger and the Lokibot trojan.
Lokibot is a commodity infostealer designed to harvest credentials from a range of applications including web browsers, email clients and IT administration tools.
As a trojan, its goal is to sneak undetected onto a system by masquerading as a legitimate program. Researchers warned it can be distributed through phishing emails, malicious websites, SMS, and other messaging platforms.
Malware Surge
This surge in popularity can be explained by the increase in spam campaigns themed around online inquiries, orders, and payment confirmation messages, Check Point revealed.
October also saw disclosure of a new critical vulnerability, Text4Shell, (CVE-2022-42889).
Based on the Apache Commons Text’s functionality, this enables network attacks without the need for any specific privileges or user interaction.
Text4shell is reminiscent of the Log4Shell vulnerability, which is still ranked as a major threat faced by organisations one year on from its discovery.
Although Text4Shell did not make the list of top vulnerabilities exploited this month, it has already impacted over 8% of organisations worldwide, Check Point noted.
Maya Horowitz, VP Research at Check Point Software said the sharp rise in malware attacks highlights the growing popularity of phishing among threat actors.
She said: “As we head into November, which is a busy buying period, it is important that people remain vigilant and keep an eye out for suspicious emails that could be carrying malicious code.
“Be aware of signs such as an unfamiliar sender, request for personal information and links. If in doubt, visit websites directly and find the appropriate contact information from verified sources, and make sure you have malware protection installed.”
AgentTesla concerns
Check Point raised serious concerns about AgentTesla and warned organisations to remain vigilant amidst the rise of this latest threat vector.
AgentTesla is an advanced RAT (Remote Access Trojan) which functions as a keylogger and information stealer.
This particular malware strain is capable of monitoring and collecting a victim’s keyboard input.
The malware enabled hackers to monitor a system keyboard, take screenshots and exfiltrate credentials from a variety of software installed on a victim’s machine, including Google Chrome, Firefox and Microsoft Outlook.
Recommended
- Placing data centres in Scotland could cut carbon impact
- Scottish scale-up investment slows as VC’s exercise caution
- Public trust ‘key’ to building ethical digital Scotland
A number of key industries have been targeted by hackers using AgentTesla malware, Check Point revealed.
Across the month, the education and research sectors were the most-targeted industries, followed closely by the government, military and healthcare sectors.
Top Mobile Malwares
Mobile malware also increased in popularity throughout October, according to Check Point’s findings.
Notably, Anubis was ranked as the most prevalent mobile malware, followed by Hydra and Joker.
Anubis is a banking Trojan malware designed for Android mobile phones. Since it was initially detected, it has gained additional functions including RAT functionality, keylogger and audio recording capabilities, as well as various ransomware features.
The app has been detected on hundreds of different applications available in the Google Store.
Similarly, Joker is an Android spyware commonly found in Google Play and designed to steal SMS messages, contact lists and device information.
The malware can also sign the victim up for paid premium services without their consent or knowledge.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





