Mobile Malware And IoT Attacks Surge, Zscaler Report Reveals
Mobile Malware And IoT Attacks Surge, Zscaler Report Reveals
Zscaler, Inc has released its 2024 Mobile, IoT, and OT Threat Report, revealing alarming trends in cyber threats from June 2023 to May 2024. The findings underscore the urgency for organisations to reevaluate and secure their mobile devices, IoT devices, and operational technology (OT) systems.
Zscaler 公司發佈了其 2024 年度移動、物聯網和運營技術(OT)威脅報告,揭示了從 2023 年 6 月到 2024 年 5 月之間網絡威脅的令人震驚的趨勢。結果強調了機構有必要重新評估和保護其移動設備、物聯網設備和運營技術系統的緊迫性。
The report identifies over 200 malicious apps on the Google Play Store, which collectively have more than 8 million installs globally. Zscaler's cloud platform blocked 45% more IoT malware transactions compared to the previous year, highlighting the continued spread of botnets across IoT devices.
報告發現在 Google Play 商店上有超過 200 個惡意應用程序,全球安裝量超過 800萬。與前一年相比,Zscaler 的雲平台阻止了比以往多 45% 的物聯網惡意軟件交易,突顯了殭屍網絡在物聯網設備上持續傳播的情況。
"Cybercriminals are increasingly targeting legacy exposed assets, often acting as gateways to IoT and OT environments, leading to data breaches and ransomware attacks," said Deepen Desai, Chief Security Officer at Zscaler. "Mobile malware and AI-driven vishing attacks are adding to this threat, making it crucial for organisations to adopt AI-powered zero trust solutions to shut down all potential attack vectors."
「網絡犯罪分子越來越多地以傳統的暴露資產爲目標,通常充當物聯網和運營技術環境的入口,導致數據泄露和勒索軟件攻擊。」 Zscaler 首席安全官 Deepen Desai 表示。「移動惡意軟件和 AI 驅動的釣魚攻擊也增加了這種威脅,機構採用基於人工智能的零信任解決方案以關閉所有潛在攻擊向量變得至關重要。」
The report also highlights the financial motivation behind mobile malware, with cyberattacks becoming more profitable, particularly through extortion and the sale of stolen personal data. Singapore has emerged as the second most targeted country in the APJ region by mobile malware, following India. The rise in spyware in the region has surged by 77% year-on-year. Anatsa, a well-known Android banking malware, has affected over 650 financial institutions, specifically targeting users in countries like Singapore, Germany, Spain, Finland, and South Korea.
報告還強調了移動惡意軟件背後的金融動機,隨着網絡攻擊變得越來越有利可圖,尤其是通過勒索和出售被盜個人數據。新加坡已成爲亞太地區第二大移動惡意軟件攻擊目標國,緊隨印度之後。該地區間諜軟件的增長率同比激增了 77%。Anatsa,一種知名的 Android 銀行病毒,已經影響了超過 650 家金融機構,特別針對新加坡、德國、西班牙、芬蘭和韓國等國家的用戶。
Singapore also ranks as the second most impacted country globally by IoT attacks, following the United States. It accounts for 5.3% of all IoT attacks globally. The report outlines the top countries most affected by IoT attacks: the United States (81.3%), Singapore (5.3%), the United Kingdom (2.8%), Germany (2.7%), and Canada (2%).
新加坡也是全球物聯網攻擊第二受影響最嚴重的國家,僅次於美國。全球所有物聯網攻擊中,新加坡佔比達 5.3%。報告列出了受物聯網攻擊影響最大的國家:美國(81.3%)、新加坡(5.3%)、英國(2.8%)、德國(2.7%)和加拿大(2%)。
Industries most vulnerable to these threats include technology, education, and manufacturing. The education sector saw a significant 136% increase in blocked mobile malware transactions. Manufacturing, for the second consecutive year, experienced the highest volume of IoT malware attacks, accounting for 36% of all IoT malware blocks observed.
最容易受到這些威脅的行業包括科技、教育和製造業。教育部門的被阻止移動惡意軟件交易數量顯著增加了 136%。製造業在連續第二年經歷了最多物聯網惡意軟件攻擊,佔所有物聯網惡意軟件攔截的 36%。
The report also draws attention to the growing risks associated with OT systems. Once isolated from the internet, OT and cyber-physical systems have become integrated into enterprise networks, creating a large attack surface for external threats. Zscaler highlights the need for organisations to secure their mobile endpoints, IoT devices, and OT systems to mitigate the risks of cyberattacks.
該報告還引起對Ot系統日益增長風險的關注。曾經與互聯網隔離的Ot和網絡物理系統已經整合到企業網絡中,爲外部威脅創造了龐大的攻擊面。Zscaler強調組織需要確保其移動終端、Iot設備和Ot系統以減輕網絡攻擊風險。
In response, Zscaler advocates for the adoption of zero trust architecture, enabling secure access from any device, location, and application. This approach reduces cyber risks while supporting hybrid work environments, remote access, and the use of IoT and OT connectivity.
作爲回應,Zscaler主張採用零信任架構,實現從任何設備、地點和應用的安全訪問。這種方法降低了網絡風險,同時支持混合工作環境、遠程訪問以及Iot和Ot連接的使用。
The 2024 report underscores the critical need for organisations to enhance their security measures to protect against these evolving and pervasive cyber threats.
該2024年報告強調了組織加強安全措施以防範這些不斷演變和普遍的網絡威脅的關鍵性需求。
譯文內容由第三人軟體翻譯。