Doubling Up on AV Fails to Protect 40% of Users from Malware Attacks

  /     /     /  
Publicated : 22/11/2024   Category : security


Doubling Up on AV Fails to Protect 40% of Users from Malware Attacks


Traditional signature-based antivirus solutions are falling short on protecting endpoints, even when there are two or more deployed.



Nearly 40% of users who had multiple, traditional antivirus solutions loaded on their endpoints faced a malware attack during the first half of the year, a Malwarebytes report revealed today.
The Mapping AV Detection Failures report, which scanned nearly 10 million endpoints, found a number of malware attacks occurred despite having two or more traditional, or signature-based, antivirus solutions installed.
The takeaway for enterprises is [that] the most basic threats have not been caught by the AV they have deployed, says Marcin Kleczynski, Malwarebytes CEO. Yet, they continue to use these and grow desensitized.
He adds CISOs and other IT security leaders may be adopting a common assumption that no one ever gets fired for using antivirus software from the industry leaders, especially when analysts rate them high on the effectiveness scale in comparative reports. Antivirus pen tests and how the software reacts in a live attack are likely to lead to vastly different results, Kleczynski notes.
Malware that Sneaks Past AV
Ransomware, botnets, and Trojans are able to slip past traditional antivirus solutions to varying degrees, the report says.
Ransomwares
Hidden Tear
compromised nearly 42% of machines with traditional AV, while Cerber hit 18%, the reports states. Cerber is also proving it can outsmart even next-gen solutions after researchers found it can
evade machine-learning detection systems
.
As for botnets, IRCBot averted AV detection in 62% of users computers that were compromised, while Kelihos evaded AV detection in 27% of the machines.
Often, botnets do not come with an infection signature that would be noticed, Kleczynski says. Kelihos comes and go and its one of the most common threats this year. Its very difficult to detect it as malware that is signature based.
Kelihos and the Internet Relay Chat (IRC) botnets are indeed hardy. The resiliency of Internet Relay Chat
(IRC) botnets was noted even back in 2015
and
Kelihos even further in 2012
.
Fileless malware, meanwhile,
continues to avert AV detection
and infected 17.8% of the endpoints scanned in the first half of the year, while DNSChanger was just as sneaky in 17.5% of the cases, the
repor
t states.
Fileless attacks are on the rise, Kleczynski says. In the old days, when you build AV you scan every file written to the disk and you find the signature and delete the malware. But now, youre not writing the threat onto the disk. Its in the browser, or Excel document or in memory.
The four top traditional AV companies failed to protect 39.1% of users against all malware attacks, according to the report. Without revealing the four vendors, Kleczynski says some are taking steps to adopt new next-gen AV techniques, such as behavioral based AV. However, he notes that the transition will take time.
Related Content:
Do Antivirus Companies Whitelist NSA Malware?
AVPass Sneaks Malware Past Android Antivirus Apps
20 Endpoint Security Questions You Never Thought to Ask
Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity
agenda here
.
 

Last News

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security

▸ Travel agency fined £150,000 for breaking Data Protection Act. ◂
Discovered: 23/12/2024
Category: security

▸ 7 arrested, 3 more charged in StubHub cyber fraud ring. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Doubling Up on AV Fails to Protect 40% of Users from Malware Attacks