In 2019, the number of unique malicious objects detected by Kaspersky’s web antivirus solution rose by an eighth, compared to last year — reaching 24,610,126.
This growth was mainly influenced by a 187% rise in web skimmer files. Other threats, such as backdoors and banking Trojans detected in-lab, also grew, while the presence of miners dropped by more than a half. These trends have demonstrated a shift in the type of threats used by attackers on the web who search of more effective ways to target users, according to the Kaspersky Security Bulletin: Statistics of the Year report.
In 2018, unique malicious objects (including scripts, exploits and executable files) detected by Kaspersky’s web antivirus solution totaled 21,643,946, rising to 24,610,126 this year. The growth accounts for an increase in the number and variety of HTML pages and scripts with hidden data loading – usually used by unscrupulous advertisers. Yet, most notably, the growth was also partially caused by online skimmers (sometimes referred to as sniffers) – where scripts are embedded by attackers in online stores and used to steal users’ credit card data from websites.
The growth of online skimmers’ unique files (scripts and HTML) detected by Kaspersky web antivirus equaled 187%, reaching 510,000. At the same time the number of threats detected by web antivirus have risen five-fold (by 523%), totaling 2,660,000 in 2019. Web skimmers also entered the top 20 malicious objects detected online, taking 10th place in the overall ranking. The share of new Backdoors and banking Trojan files, among all types of threats detected in-lab, also grew by 134% and 61% to reach 7,644,402 and 739,551 respectively.
Nevertheless, the number of unique malicious URLs detected by Kaspersky web antivirus halved in comparison to 2018 (50.5%) – from 554,159,621 to 273,782,113. This shift was largely caused by significant decrease of hidden web miners, even though several detections related to them (including Trojan.Script.Miner.gen, Trojan.BAT.Miner.gen, Trojan.JS.Miner.m), can still be seen in the top 20 web malware threats.
The presence of programs that secretly generate cryptocurrency on users’ computers (called ‘local’ miners) has also been steadily declining over the year: the number of users’ computers affected by attempts to install miners dropped by 59%, from 5,638,828 to 2,259,038.
85% of web threats were detected as malicious URL – this detection name is used to identify links from Kaspersky’s black list. It includes links to web pages containing redirects to exploits, sites with exploits and other malicious programs, botnet command and control centers, extortion websites, and others.
Verdict | %* | |
1 | Malicious URL | 85.40% |
2 | Trojan.Script.Generic | 5.89% |
3 | Trojan.Script.Miner.gen | 3.89% |
4 | Trojan-Clicker.HTML.Iframe.dg | 0.65% |
5 | Trojan.BAT.Miner.gen | 0.26% |
6 | Trojan-Downloader.JS.Inor.a | 0.22% |
7 | Trojan.PDF.Badur.gen | 0.21% |
8 | DangerousObject.Multi.Generic | 0.21% |
9 | Trojan-Downloader.Script.Generic | 0.17% |
10 | Trojan-PSW.Script.Generic | 0.15% |
11 | Trojan.Script.Agent.gen | 0.15% |
12 | Hoax.HTML.FraudLoad.m | 0.13% |
13 | Exploit.Script.Generic | 0.08% |
14 | Trojan.Script.Agent.bg | 0.07% |
15 | Trojan.Multi.Preqw.gen | 0.06% |
16 | Exploit.MSOffice.CVE-2017-11882.gen | 0.06% |
17 | Trojan-Downloader.JS.SLoad.gen | 0.05% |
18 | Hoax.Script.Loss.gen | 0.05% |
19 | Trojan.JS.Miner.m | 0.05% |
20 | Trojan-Downloader.VBS.SLoad.gen | 0.04% |
* The share of all malware web attacks detected on the computers of users
Read more about annual threat statistics on Securelist.com.
In order to stay protected, Kaspersky recommends the following:
- Pay close attention to and don’t open any suspicious files or attachments received from unknown sources
- Do not download and install applications from untrusted sources
- Do not click on any links received from unknown sources and suspicious online advertisements
- Create strong passwords and don’t forget to change them regularly
- Always install updates. Some of them may contain critical security issues fixes
- Ignore messages asking to disable security systems for office software or antivirus software
- Use a robust security solution appropriate to your system type and devices, such as Kaspersky Internet Security or Kaspersky Security Cloud
The statistics report is part of the Kaspersky Security Bulletin 2019. To learn more about threat predictions for 2019, read our reports, which are available here.
Story of the year: Ransomware vs cities in 2019: 174 and counting and APT review: what the world’s threat actors got up to in 2019 are also available on Securelist.com.