TrendAI™ Research
214 articles
-
BlogATF Reports Breach After Qilin Leak Site Appearance: Insights from TrendAI™
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has reportedly appeared on the Qilin ransomware group’s leak site. Explore how Qilin operates and what organizations can learn from its past tactics.
August 28th, 2026TrendAI™ Research
Read article -
ResearchSecurity 101: Virtual Patching
What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.
August 25th, 2026 5 minTrendAI™ Research
Read article -
BlogUK Power Facility Cyberattack Shutdown: What Critical-Infrastructure Operators and Defenders Need to Know
A reported cyberattack on a UK power-generation facility in July 2026 shows that even disruptions at a single site can raise broader questions about critical infrastructure resilience.
August 24th, 2026 6 minTrendAI™ Research
Read article -
BlogThe Architecture Behind $1B: How Customers Run TrendAI Vision One™ on AWS, and Secure Their AI Workloads
August 23rd, 2026TrendAI™ Research
Read article -
BlogMalicious Cyber Activity Targeting US Water Utilities: What Operators Need To Know
Disruption reported across at least seven states, from equipment left accessible online. The issue is largely a matter of configuration and access control, and here's what to fix first.
August 3rd, 2026 5 minTrendAI™ Research
Read article -
ResearchGoverning the Republic of AI Agents: The Framework Your AI Agents Already Need
AI agents have evolved from tools to autonomous participants in your organization, but governance has not kept pace. TrendAI™ proposes a six-pillar framework built to close that gap.
July 21st, 2026 2 minTrendAI™ Research
Read article -
ResearchAgentic AI’s Shadow Pipeline: Mapping the Attack Surface Behind Trusted Workflows
As enterprises connect AI agents to cloud infrastructure and production workflows, the cloud-to-agent pipeline is becoming a primary attack surface. This article maps the risks for tech, media, and communications organizations and outlines detection and security best practices.
July 17th, 2026TrendAI™ Research
Read article -
ResearchDriving Security at the Speed of AI Agents with NVIDIA DOCA
Agentic AI compresses exploit timelines from weeks to hours, and reactive security can't keep pace. TrendAI™, working with NVIDIA, delivers an isolated trust architecture purpose-built for AI infrastructure, hardening AI factories before attackers find a way in.
June 1st, 2026TrendAI™ Research
Read article -
ResearchEdge Under Siege: How State-Sponsored Actors Exploit Your Perimeter
Edge devices have become a primary entry point for state-sponsored espionage, giving attackers a cheaper, faster path to network access, credential theft, and traffic interception. Our report examines the threat landscape, economics, and actor activity driving this shift, along with what CISOs and security leaders can do to respond.
April 20th, 2026 12 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Agenda
Agenda has rapidly grown into one of the most prolific and dangerous ransomware operations, leveraging advanced techniques, cross-platform variants, and alliances with other major threat groups. Its aggressive double-extortion model and expanding victim base across critical industries make it a serious enterprise risk that demands proactive detection and defense.
March 18th, 2026 10 minTrendAI™ Research
Read article -
ResearchAI Security Starts Here: The Essentials for Every Organization
AI’s rapid growth brings new risks as well as opportunities. Strong security foundations are essential to ensure innovation remains safe, compliant, and resilient.
November 5th, 2025TrendAI™ Research
Read article -
ResearchRansomware Spotlight: DragonForce
DragonForce, a Ransomware-as-a-Service group first observed in 2023, rose to greater prominence in 2025 after a series of notable attacks linked to the group. Despite its unclear origins, what is evident is its rapid evolution and its aggressive, affiliate-driven model, marking it as a rising threat to watch out for.
October 29th, 2025 10 minTrendAI™ Research
Read article -
Vulnerabilities And ExploitsLessons in Resilience from the Race to Patch SharePoint Vulnerabilities
In this article, Trend Micro discusses how the fast-moving attacks using CVE-2025-53770 and CVE-2025-53771 have underscored the essential role of virtual patching and reliable intelligence in protecting organizations against evolving threats.
August 7th, 2025 4 minTrendAI™ Research
Read article -
ResearchTrend Micro State of AI Security Report 1H 2025
Trend Micro’s State of AI Security report explores how AI’s rapid adoption is transforming both business efficiency and cybercrime methods, highlighting novel threats and strategic defenses to help organizations adapt in an increasingly AI-driven world.
July 29th, 2025 30 minTrendAI™ Research
Read article -
ResearchThe Future of Social Engineering
Social engineering is a tactic that, at its core, creates a false narrative to exploit a victim’s credulity, greed, curiosity, or any other very human characteristics. Attackers continue to enhance existing social engineering and use new technologies.
March 17th, 2025 13 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Water Ouroboros
Water Ouroboros (aka Hunters International) is a Ransomware-as-a-Service (RaaS) group that first emerged in October 2023. It is suspected to be a possible spin-off of Hive ransomware, which had its activities disrupted by the Federal Bureau of Investigation (FBI) in January 2023.
March 5th, 2025 6 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Ransomhub
RansomHub is a young Ransomware-as-a-Service (RaaS) group tracked by Trend Micro as Water Bakunawa. Despite being a young ransomware group first detected in February 2024, RansomHub moves boldly by targeting larger enterprises more likely to pay ransoms.
December 20th, 2024TrendAI™ Research
Read article -
ResearchUnleashing Chaos: Real World Threats Hidden in the DevOps Minefield
Threat actors are actively looking for exposed .env files. These files have become ticking bombs deeply rooted inside DevOps practices. Our research paper uncovers the hidden dangers in DevOps using real-world examples.
December 12th, 2024 4 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: INC
INC ransomware has been observed to exploit CVE-2023-3519 and uses HackTool.Win32.ProcTerminator.A for defense evasion and HackTool.PS1.VeeamCreds for credential access in its different attack chains.
October 29th, 2024 6 minTrendAI™ Research
Read article -
ResearchThe Illusion of Choice: Uncovering Electoral Deceptions in the Age of AI
Elections are the cornerstone of modern democracy, an exercise where a populace expresses its political will through the casting of ballots. But as electoral systems adopt and embrace technology, this introduces significant cybersecurity risks, not only to the infrastructure supporting an election but also to the people lining up in polling booths.
September 19th, 2024 10 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: LockBit
The LockBit intrusion set, tracked by Trend Micro as Water Selkie, has one of the most active ransomware operations today. With LockBit’s strong malware capabilities and affiliate program, organizations should keep abreast of its machinations to effectively spot risks and defend against attacks.
May 7th, 2024 10 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: 8Base
Despite positioning themselves as penetration testers, 8Base ransomware threat actors profit off their victims that are significantly comprised of small businesses. In this feature, we investigate how the gang operates to gain insights on how organizations can protect systems better from compromises that could result in financial loss.
April 25th, 2024 9 minTrendAI™ Research
Read article -
ResearchApache APISIX In-the-wild Exploitations: An API Gateway Security Study
This article focuses on the Apache APISIX API gateway and its security implications.
March 8th, 2024 15 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Rhysida
The threat actors behind the Rhysida ransomware targeted multiple industries by posing as a cybersecurity team that offered to help its victims identify security weaknesses in their networks and systems. Although the group’s activity was first observed back in May 2023, its leak site was established as early as March 2023. Like other ransomware groups, it employs double extortion tactics to pressure its victims into paying a ransom demand in Bitcoin.
February 21st, 2024 7 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Trigona
After the shutdown of its leak site in October, we look at how ransomware group Trigona operated during its period of activity and discuss how enterprises can fortify their defenses against similar threats.
November 28th, 2023 6 minTrendAI™ Research
Read article -
ResearchSteering Clear of Security Blind Spots: What SOCs Need to Know
As technologies continue to evolve and expand, organizations experience a technological paradox: Their increasing interconnectivity means that they simultaneously become more distributed. Case in point, robust cloud and networking technologies support today’s widespread adoption of hybrid and remote work arrangements, allowing employees all over the globe to work remotely full time or at least part of the time.
November 23rd, 2023 13 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Akira
This report spotlights Akira, a novel ransomware family with highly experienced and skilled operators at its helm.
October 5th, 2023 8 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Play
Play is shaping up to be a player on the rise within the ransomware landscape, with its operators likely to continue using the ransomware in future. We take a deep dive into its operations and offer ways in which organizations can shore up their defenses against this emerging threat.
July 21st, 2023 8 minTrendAI™ Research
Read article -
ResearchUnmasking Pig-Butchering Scams and Protecting Your Financial Future
This report delves into the nature of pig-butchering scams, how scammers carry out their operations, the new pig-butchering tactics we’ve observed in the wild, and what individuals can do to avoid falling for these fraudulent investments and dealing with massive amounts of debt.
June 22nd, 2023TrendAI™ Research
Read article -
ResearchRansomware Spotlight: TargetCompany
We detail everything you need to know about TargetCompany, a ransomware family with different monickers, including the evolution of its attack flow as it cemented its place in the threat landscape.
June 5th, 2023 8 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Royal
Backed by threat actors from Conti, Royal ransomware is poised to wreak havoc in the threat landscape, starting strong by taking a spot among the most prolific ransomware groups within three months since it was first reported. Combining new and old techniques and quick evolution, it is likely to remain a big player in the threat landscape in the future.
March 15th, 2023 7 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Magniber
The Magniber ransomware initially targeted only Asian countries when it was first detected in 2017. However, it resurfaced in 2021 and continues to operate today with expanded targets around the globe. Magniber remains a significant player in the threat landscape, with malicious attackers likely to continue using the ransomware in future.
January 26th, 2023 6 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Cuba
Cuba ransomware emerged on the scene with a spate of high-profile attacks in late 2021. Armed with an expansive infrastructure, impressive tools, and associated malware, Cuba ransomware is considered a significant player in the threat landscape, and is likely to remain so in the future through its continued evolution.
December 7th, 2022 7 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: BlackCat
Known for its unconventional methods and use of advanced extortion techniques, BlackCat has quickly risen to prominence in the cybercrime community. As this ransomware group forges its way to gain more clout, we examine its operations and discuss how organizations can shore up their defenses against it.
October 27th, 2022 8 minTrendAI™ Research
Read article -
ResearchUncovering Security Weak Spots in Industry 4.0 CNC Machines
The technological leaps of the Fourth Industrial Revolution may have made production machinery more efficient, but these have also put manufacturers in the crosshairs of cybercriminals. Our research tackles the risks that computer numerical control (CNC) machines now face as they’re integrated into today’s networked factories.
October 24th, 2022 4 minTrendAI™ Research
Read article -
ResearchLeaked Today, Exploited for Life: How Social Media Biometric Patterns Affect Your Future
The photos, videos, and audio posts we put online expose sensitive biometric patterns that can be abused by cybercriminals. These patterns are virtually unchangeable and can be used now or in future attacks.
October 18th, 2022 6 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Black Basta
A relative newcomer in 2022, the Black Basta ransomware group has wasted no time making a name for itself by upgrading its toolset and racking up its victim count around the world mere months since its ransomware was first detected. Learn more about this new ransomware and fortify your organization’s defenses against this threat.
September 1st, 2022 8 minTrendAI™ Research
Read article -
ResearchMetaworse? The Trouble with the Metaverse
Innovators are diving into a new and immersive virtual space, but with new technology comes new threats. We bring forward possible problematic issues that metaverse pioneers should be wary of.
August 8th, 2022 4 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: BlackByte
BlackByte is a ransomware group that has been building a name for itself since 2021. Like its contemporaries, it has gone after critical infrastructure for a higher chance of getting a payout. What techniques sets it apart?
July 5th, 2022 8 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: RansomEXX
RansomEXX is a ransomware variant that gained notoriety after a spate of attacks in 2020 and continues to be active today. With its targeted nature and history for choosing high-profile victims, we shine our spotlight on RansomEXX to reveal its tactics, techniques, and procedures.
May 17th, 2022 9 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: AvosLocker
AvosLocker is a relatively new ransomware variant that sports the staples of modern ransomware, namely a layered extortion scheme that begins with stolen data. We shed light on this emerging ransomware family and its key techniques.
April 4th, 2022 8 minTrendAI™ Research
Read article -
ResearchProbing the Activities of Cloud-Based Cryptocurrency-Mining Groups
Our research into cloud-based cryptocurrency mining sheds light on the malicious actor groups involved in this space, their ongoing battle for cloud resources, and the actual extent of the impact of their attacks.
March 29th, 2022 7 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Hive
Hive ransomware is one of the new ransomware families in 2021 that poses significant challenges to enterprises worldwide. We take an in-depth look at the ransomware group’s operations and discuss how organizations can bolster their defenses against it.
March 18th, 2022 7 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Clop
We take a closer look at the operations of Clop, a prolific ransomware family that has gained notoriety for its high-profile attacks. We review this ransomware group’s constantly changing schemes and discuss how companies can shore up defenses against this threat.
February 22nd, 2022 12 minTrendAI™ Research
Read article -
ResearchHidden Scams in Malicious Scans: How to Use QR Codes Safely
The popularity of QR codes has created fertile ground for malicous actors to spruce up their malware tool kit for scams that steal not only personal information but also hard-earned assets that are impossible to recover once lost. We take a closer look at the different QR code-related scams and provide helpful tips on how to use QR codes safely.
February 9th, 2022 8 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: REvil
Now that the reign of REvil has come to an end, it's time to regroup and strategize. What can organizations learn from REvil’s tactics? We review the rise, downfall, and future of its operations using insights into the group's arsenal and inner inner workings.
December 20th, 2021 9 minTrendAI™ Research
Read article -
ResearchRansomware Spotlight: Conti
Assumed to be the successor of the Ryuk ransomware, Conti is currently one of the most notorious active ransomware families used in high-profile attacks. Know all about this ransomware family and protect your company against this threat.
December 1st, 2021 7 minTrendAI™ Research
Read article -
ResearchInvestigating the Emerging Access-as-a-Service Market
We examine an emerging business model that involves access brokers selling direct access to organizations and stolen credentials to other malicious actors.
November 30th, 2021 30 minTrendAI™ Research
Read article -
ResearchThe Most Common Cloud Misconfigurations That Could Lead to Security Breaches
Using Trend Micro Cloud One™ – Conformity data, we looked at the top 10 Amazon Web Services (AWS) and Microsoft Azure services with the highest misconfiguration rates with regard to the implementation of Cloud Conformity rules.
October 25th, 2021 13 minTrendAI™ Research
Read article -
ResearchIoT and Ransomware: A Recipe for Disruption
Ransomware can impact industrial operations in the bid to cause disruptions. Organizations need to reevaluate the security of their IoT environments in the face of such a threat.
September 28th, 2021 8 minTrendAI™ Research
Read article -
ResearchIoT Security Issues, Threats, and Defenses
As the IoT continues to influence more environments and settings, we review what IoT security is and why it remains essential today.
July 22nd, 2021 9 minTrendAI™ Research
Read article -
ResearchTeamTNT Activities Probed: Credential Theft, Cryptocurrency Mining, and More
Our research sheds light on the tools and techniques used by TeamTNT and the potential impact of the group’s sundry malicious activities.
July 20th, 2021 3 minTrendAI™ Research
Read article -
ResearchTrends and Shifts in the Underground N-Day Exploit Market
Our two-year research provides insights into the life cycle of exploits, the types of exploit buyers and sellers, and the business models that are reshaping the underground exploit market.
July 13th, 2021 4 minTrendAI™ Research
Read article -
ResearchModern Ransomware's Double Extortion Tactics and How to Protect Enterprises Against Them
Modern ransomware like Nefilim present new challenges and security concerns for enterprises across the world. How do these new families differ from traditional ransomware? And what can organizations do to mitigate risks?
June 8th, 2021 14 minTrendAI™ Research
Read article -
ResearchThe Nightmares of Patch Management: The Status Quo and Beyond
We discuss the challenges that organizations face in managing endpoint and server patches.
April 7th, 2021 13 minTrendAI™ Research
Read article -
ResearchReturn to Sender: Preventing Ransomware While Working From Home
Many employees have set up makeshift work spaces in their homes. This could leave them more susceptible to ransomware attacks that take advantage of vulnerabilities in unsecured spaces.
April 5th, 2021 3 minTrendAI™ Research
Read article -
ResearchSecurity 101: Protecting Serverless and Container Applications with RASP (Runtime Application Self-Protection)
This article zeroes in on certain security considerations that developers need to know and the ways that they can build the best defense for container-based and serverless applications through runtime application self-protection (also known as RASP).
March 23rd, 2021 7 minTrendAI™ Research
Read article -
ResearchExploiting AI: How Cybercriminals Misuse and Abuse AI and ML
We discuss the present state of the malicious uses and abuses of AI and ML and the plausible future scenarios in which cybercriminals might abuse these technologies for ill gain.
November 19th, 2020TrendAI™ Research, United Nations Interregional Crime and Justice Research Institute (UNICRI), Europol’s European Cybercrime Centre (EC3)
Read article -
ResearchCOVID-19 Used in Malicious Campaigns
Threat actors take advantage of the spread of COVID-19 for malicious campaigns. Goods and services related to the virus also appear in underground marketplaces and cybercriminal forums.
November 11th, 2020 23 minTrendAI™ Research
Read article -
ResearchRyuk 2020: Distributing Ransomware via TrickBot and BazarLoader
Starting this year, Ryuk began using another dropper called BazarLoader (also known as BazarBackdoor), which is primarily distributed via phishing emails that contain either malicious attachments or links to websites that host malware.
November 4th, 2020 4 minTrendAI™ Research
Read article -
ResearchOperation Earth Kitsune: Tracking SLUB’s Current Operations
A watering hole campaign we dubbed as Operation Earth Kitsune is spying on users’ systems through compromised websites. Using SLUB and two new malware variants, the attacks exploit vulnerabilities including those of Google Chrome and Internet Explorer.
October 19th, 2020TrendAI™ Research
Read article -
ResearchShedding Light on Security Considerations in Serverless Cloud Architectures
Serverless computing is not immune to risks and threats. Our security research provides a comprehensive analysis of the possible attack scenarios that could compromise serverless services and deployments.
August 11th, 2020 7 minTrendAI™ Research
Read article -
ResearchLost in Translation: When Industrial Protocol Translation goes Wrong
This research paper looks at protocol gateways, which translate various protocols used by different industrial devices and machinery, and provides insight into the security issues and vulnerabilities found in these devices as well as ways to secure them.
August 5th, 2020 4 minTrendAI™ Research
Read article -
ResearchUnveiling the Hidden Risks of Industrial Automation Programming
The legacy programming environments of widely used industrial machines could harbor virtually undetectable vulnerabilities and malware. Our security analysis of these environments reveals critical flaws and their repercussions for smart factories.
August 4th, 2020 6 minTrendAI™ Research, Politecnico di Milano
Read article -
ResearchRansomware Report: Avaddon and New Techniques Emerge, Industrial Sector Targeted
In this report, we discussed new ransomware family Avaddon, updates on techniques of other ransomware, and our latest figures.
July 8th, 2020 7 minTrendAI™ Research
Read article -
ResearchCaught in the Crossfire: Defending Devices From Battling Botnets
As cybercriminals compete for dominance in their bid to create powerful botnets, users can make their own stand against warring sides by understanding how botnet malware works and securing their devices.
July 7th, 2020 4 minTrendAI™ Research
Read article -
ResearchCyberattacks from the Frontlines: Incident Response Playbook for Beginners
In the event of a cyberattack a strong incident response plan can get a business running again with minimal damages. Understand the response process in this playbook.
June 24th, 2020 10 minTrendAI™ Research
Read article -
ResearchMillions of IoT Devices Affected by Ripple20 Vulnerabilities
The internet of things (IoT) landscape will be critically affected by the recently discovered Ripple20 vulnerabilities. This group of 19 bugs could potentially hit millions of IoT devices across many different industries.
June 22nd, 2020 1 minTrendAI™ Research
Read article -
ResearchLemon Duck Cryptominer Spreads through Covid-19 Themed Emails
We have come across a PowerShell script (mailer script) that distributes the Lemon Duck cryptominer through a new propagation method: Covid-19-themed emails with weaponized attachments.
June 3rd, 2020 4 minTrendAI™ Research
Read article -
ResearchSmart Yet Flawed: IoT Device Vulnerabilities Explained
Are your smart devices vulnerable? Here are common vulnerabilities found in IoT devices and how to secure against them.
May 28th, 2020 5 minTrendAI™ Research
Read article -
ResearchQakbot Resurges, Spreads through VBS Files
We have seen events that point to the resurgence of Qakbot, a multi-component, information-stealing threat first discovered in 2007.
May 25th, 2020 6 minTrendAI™ Research
Read article -
ResearchPhishing Site Uses Netflix as Lure, Employs Geolocation
A phishing site was found using a spoofed Netflix page to harvest account information, credit card credentials, and other PII.
May 19th, 2020 2 minTrendAI™ Research
Read article -
ResearchCloud Security: Key Concepts, Threats, and Solutions
When it comes to cloud computing security, or simply, cloud security, what are the builders’ responsibilities? How can developers and administrators ensure cloud security? This primer discusses the key concepts of cloud security and which areas need to be protected using flexible and comprehensive security solutions.
May 14th, 2020 11 minTrendAI™ Research
Read article -
ResearchThreats and Consequences: A Security Analysis of Smart Manufacturing Systems
Through a thorough analysis of an actual smart manufacturing environment, our in-depth security research explores several attack vectors that could be used by threat actors to launch unconventional attacks on smart manufacturing systems.
May 11th, 2020 8 minTrendAI™ Research
Read article -
ResearchSecurity 101: How Fileless Attacks Work and Persist in Systems
Many attackers are switching from file-based malware to memory-based attacks to improve their stealth. “Fileless,” “zero-footprint,” or “living off the land” threats use legitimate applications to carry out malicious activities.
April 30th, 2020 4 minTrendAI™ Research
Read article -
ResearchGroup Behind TrickBot Spreads Fileless BazarBackdoor
A campaign propagates a new malware named ‘BazarBackdoor’, a fileless backdoor reportedly created by the same threat actors behind TrickBot.
April 27th, 2020 3 minTrendAI™ Research
Read article -
ResearchNefilim Ransomware Threatens to Expose Stolen Data
New ransomware variant Nefilim is distributed through exposed Remote Desktop Protocol (RDP) and threatens to release stolen data to the public.
March 23rd, 2020 2 minTrendAI™ Research
Read article -
ResearchOperation DRBControl: Uncovering a Cyberespionage Campaign Targeting Gambling Companies in Southeast Asia
The DRBControl campaign attacks its targets using a variety of malware and techniques that coincide with those used in other known cyberespionage campaigns.
February 18th, 2020 4 minTrendAI™ Research
Read article -
ResearchPuerto Rico Loses Millions in Email Scam
The hacked email account of a finance employee was exploited to steal millions of dollars from the Puerto Rico government.
February 18th, 2020 2 minTrendAI™ Research
Read article -
ResearchMisconfigured AWS S3 Bucket Leaks 36,000 Inmate Records
Over 30K records of US inmates were inadvertently exposed through a leaky AWS S3 cloud storage bucket.
February 12th, 2020 3 minTrendAI™ Research
Read article -
ResearchResearchers Use Smart Light Bulbs to Infiltrate Networks
Researchers discovered a vulnerability in smart light bulbs that can allow hackers to install malware and infect other IoT devices.
February 6th, 2020 3 minTrendAI™ Research
Read article -
ResearchOver 30 Million Stolen Credit Card Records Being Sold on the Dark Web
Cybercriminals were found selling over 30 million credit card details from around 40K U.S. states and 100 countries.
January 30th, 2020 5 minTrendAI™ Research
Read article -
ResearchUnsecured AWS S3 Bucket Found Leaking Data of Over 30K Cannabis Dispensary Customers
An unsecured Amazon S3 bucket was found leaking the data of more than 30,000 individuals. It was discovered to have exposed 85,000 files that included records with sensitive personally identifiable information (PII).
January 27th, 2020 3 minTrendAI™ Research
Read article -
ResearchMalicious Script Plagues Over 2,000 WordPress Accounts, Redirects Visitors to Scam Sites
Over 2,000 WordPress sites were compromised by a malicious script that redirects visitors to scam sites, gains admin access, and installs fake plugins.
January 24th, 2020TrendAI™ Research
Read article -
ResearchSextortion Scheme Claims Use of Home Cameras, Demands Bitcoin or Gift Card Payment
A new sextortion scheme threatens to expose nude videos supposedly captured via victims' mobile phones and home cameras.
January 22nd, 2020 3 minTrendAI™ Research
Read article -
ResearchFake Company, Real Threats: Logs From a Smart Factory Honeypot
To determine threat actors' degree of knowledge in compromising a smart factory, we deployed our most elaborate honeypot to date. The incidents we observed show the kinds of attacks that can easily affect poorly secured manufacturing environments.
January 21st, 2020 4 minTrendAI™ Research
Read article -
ResearchMobile Banking Trojan FakeToken Resurfaces, Sends Offensive Messages Overseas from Victims’ Accounts
An updated version of mobile malware FakeToken was found sending massive numbers of offensive messages to foreign countries.
January 16th, 2020 2 minTrendAI™ Research
Read article -
ResearchInto the Battlefield: A Security Guide to IoT Botnets
We recap the history and recent campaigns of IoT botnets to help users defend against the different malware competing for control and resources of regular smart devices.
December 19th, 2019 14 minTrendAI™ Research
Read article -
ResearchCheats, Hacks, and Cyberattacks: Threats to the Esports Industry in 2019 and Beyond
Esports competitions continue to gain momentum, making the entities involved more attractive targets for cybercrime.
October 29th, 2019 3 minTrendAI™ Research
Read article -
ResearchPutting the Eternal in EternalBlue: Mapping the Use of the Infamous Exploit
In 2017, EternalBlue was the driving force behind one of the nastiest ransomware outbreaks on record. And despite available fixes, it is still being used by malware today—from ransomware to widespread cryptocurrency miners.
October 18th, 2019 4 minTrendAI™ Research
Read article -
ResearchSecurity 101: Zero-Day Vulnerabilities and Exploits
A zero-day attack exploits an unpatched vulnerability. Until a patch becomes available, it is often a race between threat actors trying to exploit the flaw and vendors or developers rolling out a patch to fix it.
October 2nd, 2019 9 minTrendAI™ Research
Read article -
ResearchThe Risks of Open Banking: Are Banks and their Customers Ready for PSD2?
Our research highlights the current and new risks that the financial industry will have to defend against, and predict how cybercriminals will abuse and attack Open Banking.
September 17th, 2019 3 minTrendAI™ Research
Read article -
ResearchTexas Municipalities Hit by REvil/Sodinokibi Paid No Ransom, Over Half Resume Operations
Cybercriminals who held to ransom the files of 22 Texas local government units for a combined ransom amount of US$2.5 million did not get a single cent, according to Texas state officials.
September 10th, 2019 3 minTrendAI™ Research
Read article -
ResearchUnusual CEO Fraud via Deepfake Audio Steals US$243,000 From UK Company
An unusual case of CEO fraud used a deepfake audio, an artificial intelligence (AI)-generated audio, and was reported to have conned US$243,000 from a U.K.-based energy company.
September 5th, 2019 3 minTrendAI™ Research
Read article -
ResearchBEC Scam Costing Almost US$11 Million Leads to FBI Arrest of Nigerian Businessman
The CEO of the Invictus Group of Companies, Obinwanne Okeke, has reportedly been arrested by the FBI after he was accused of conspiracy to commit computer and wire fraud.
August 20th, 2019 4 minTrendAI™ Research
Read article -
ResearchThe Rising Tide of Credential Phishing: 2.4 Million Attacks Blocked by Trend Micro Cloud App Security in 2019 1H
Credential phishing continues to be a bane for organizations. In the first half of 2019, the Trend Micro™️ Cloud App Security™️ solution caught 2.4 million attacks of this type — a 59% increase from 1.5 million in the second half of 2018.
August 14th, 2019 4 minTrendAI™ Research
Read article -
ResearchReport: Huge Increase in Ransomware Attacks on Businesses
According to a new report, ransomware attacks against businesses increased by 363% percent year-over-year. There has also been a greater number of ransomware attacks targeting different public sectors and local governments since the start of 2019.
August 12th, 2019 3 minTrendAI™ Research
Read article -
ResearchRisks Under the Radar: Understanding Fileless Threats
Hackers use fileless threats to take advantage of existing applications and attack systems. Here we discuss noteworthy events, techniques, and best practices that can help identify fileless threats and defend against attacks.
July 29th, 2019 13 minTrendAI™ Research
Read article -
ResearchMalicious Spam Campaign Uses ISO Image Files to Deliver LokiBot and NanoCore
A malicious spam campaign conducted in April used ISO image files to deliver the notorious LokiBot and NanoCore trojans.
June 28th, 2019 4 minTrendAI™ Research
Read article -
ResearchContainer Security: Examining Potential Threats to the Container Environment
The rise in adoption of containers means a greater need for security awareness. Our infographic details the various threats that container users could encounter at each stage of the development pipeline.
May 14th, 2019 6 minTrendAI™ Research
Read article -
ResearchWhat You Need To Know About Tax Scams
Tax season is upon us (again), and so are IRS tax scammers. How prepared are you when it comes to filing your taxes and defending against IRS tax fraud? Learn more about these scams and how you can protect yourself.
April 8th, 2019 8 minTrendAI™ Research
Read article -
ResearchSecurity in the Era of Industry 4.0: Dealing With Threats to Smart Manufacturing Environments
As manufacturing companies continue to adopt Industry 4.0, many environments could still be falling short on security with outdated systems, unpatched vulnerabilities, and unsecure files that leave them vulnerable to attacks.
April 3rd, 2019 5 minTrendAI™ Research
Read article -
ResearchGoogle and Facebook Fraudster Pleads Guilty to $100 million Scam
A business email compromise (BEC) scheme took more than $100 million from Facebook and Google. Legitimate-looking invoices, contracts and more fooled the two tech companies and they wired millions to the fraudsters over a period of years.
March 26th, 2019 2 minTrendAI™ Research
Read article -
ResearchGlobal Telecom Crime Undermining Internet Security: Cyber-Telecom Crime Report
As the field of telecommunication continues to evolve, so should its security. Understanding its current threat landscape can help reduce the impact of crimes like telecom fraud and prepare us for future threats in the age of the IoT.
March 21st, 2019 4 minTrendAI™ Research, Europol’s European Cybercrime Centre (EC3)
Read article -
ResearchWhat You Need to Know About the LockerGoga Ransomware
The systems of Norsk Hydro were reportedly struck by LockerGoga ransomware. Here's what you need to know about this threat and how to defend against it.
March 20th, 2019 7 minTrendAI™ Research
Read article -
ResearchExamining Ryuk Ransomware Through the Lens of Managed Detection and Response
Trend Micro‘s Managed Detection and Response (MDR) and Incident Response teams investigated two separate Ryuk attacks with seemingly little in common with each other.
March 14th, 2019 7 minTrendAI™ Research
Read article -
ResearchSecuring Smart Homes and Buildings: Threats and Risks to Complex IoT Environments
The evolution of smart homes and smart buildings into complex IoT environments reflects the continuing developments in home and industrial automation. Security should not be left behind as increased complexity also means new threats and risks.
March 5th, 2019 6 minTrendAI™ Research
Read article -
ResearchAttacks Against Industrial Machines via Vulnerable Radio Remote Controllers: Security Analysis and Recommendations
Radio frequency (RF) technology is being used in operations to control various industrial machines. However, the lack of implemented security in RF communication protocols could lead to production sabotage, system control, and unauthorized access.
January 15th, 2019 8 minTrendAI™ Research
Read article -
ResearchRansomware MongoLock Immediately Deletes Files, Formats Backup Drives
We found a wave of MongoLock ransomware attacks that immediately deletes important files upon infection and scans the backup drives for data deletion.
January 8th, 2019 3 minTrendAI™ Research
Read article -
ResearchSecurity 101: Defending Against Fileless Malware
Fileless threats aren’t as visible compared to traditional malware and employ a variety of techniques to stay persistent. Here's a closer look at how fileless malware work and what can be done to thwart them.
December 20th, 2018 12 minTrendAI™ Research
Read article -
ResearchMQTT and CoAP: Security and Privacy Issues in IoT and IIoT Communication Protocols
We looked into MQTT brokers and CoAP servers around the world to assess IoT protocol security. Learn how to prevent risks and secure machine-to-machine (M2M) communications over MQTT and CoAP in our research.
December 4th, 2018 6 minTrendAI™ Research, Eurecom and Politecnico di Milano (POLIMI)
Read article -
ResearchHacker Infects Node.js Package to Steal from Bitcoin Wallets
A Node.js module with nearly two million downloads a week was compromised after the library was injected with malicious code programmed to steal bitcoins in wallet apps.
November 29th, 2018 3 minTrendAI™ Research
Read article -
ResearchCryptocurrency-mining Malware Targets Linux Systems, Uses Rootkit for Stealth
We recently encountered a cryptocurrency-mining malware affecting Linux systems. It is notable for being bundled with a rootkit component that hides the malicious process’ presence from monitoring tools.
November 8th, 2018 6 minTrendAI™ Research
Read article -
ResearchCritical Infrastructures Exposed and at Risk: Energy and Water Industries
Securing energy and water should remain top priority in the continuing integration of the industrial internet of things in these critical sectors.
October 30th, 2018 5 minTrendAI™ Research
Read article -
ResearchVirtual Patching: Patch Those Vulnerabilities before They Can Be Exploited
The average organization takes over 30 days to patch operating systems and software, and longer for more complex business applications and systems. This infographic shows how virtual patching solutions can help mitigate threats from vulnerabilities.
October 25th, 2018 4 minTrendAI™ Research
Read article -
ResearchLoJax UEFI Rootkit Used in Cyberespionage
Security researchers came across a Unified Extensible Firmware Interface (UEFI) rootkit in the wild being used for cyberespionage. Named LoJax, the rootkit is reportedly packaged with other tools that modifies the system’s firmware to infect it with malware.
October 1st, 2018 3 minTrendAI™ Research
Read article -
ResearchData Breaches 101: How They Happen, What Gets Stolen, and Where It All Goes
Data breaches take time and a lot of effort to pull off, but successful breaches can affect not just organizations, but also millions of people. Learn what a data breach is, what types of data is usually stolen, and what happens to stolen data.
August 10th, 2018 6 minTrendAI™ Research
Read article -
ResearchOver 200,000 MikroTik Routers Compromised in Cryptojacking Campaign
Security researchers uncovered a cryptojacking campaign that exploits a vulnerability in MikroTik routers to inject a malicious version of Coinhive. Here’s what you need to know.
August 3rd, 2018 3 minTrendAI™ Research, TrendAI Rese
Read article -
ResearchFileless Malware PowerGhost Targets Corporate Systems
A new fileless malware utilizes Powershell and EternalBlue via WMI for propagation, infecting workstations and servers connected to a local server with a cryptocurrency miner and a DDos tool. Significant infections have been detected in North America and Europ
July 30th, 2018 2 minTrendAI™ Research
Read article -
ResearchFBI Report: Global BEC Losses Exceeded US$12 Billion in 2018
The Federal Bureau of Investigation (FBI) issued a public service announcement (PSA) regarding the continued increase of Business Email Compromise (BEC) scams, which total global losses have already reached over US$12 billion in 2018.
July 18th, 2018 2 minTrendAI™ Research
Read article -
ResearchThe Rise and Fall of Scan4You
We delved into the rise and fall of Scan4You, the largest counter antivirus service in the underground, its operators, and the ties that bind them to other cybercriminals.
May 16th, 2018 4 minTrendAI™ Research
Read article -
ResearchExposed Video Streams: How Hackers Abuse Surveillance Cameras
IP surveillance cameras provide certain conveniences, but control of this can fall into the wrong hands. What threats are there for these devices and what can be done to minimize risk?
May 8th, 2018 10 minTrendAI™ Research
Read article -
ResearchCurbing the BEC Problem Using AI and Machine Learning
Due to BEC’s evolving and treacherous nature, run-of-the-mill best practices and security solutions have become weak to withstand attacks. Find out how advanced solutions that utilize artificial intelligence and machine learning help in defending against BEC.
April 16th, 2018 5 minTrendAI™ Research
Read article -
ResearchExposed Devices and Supply Chain Attacks: Overlooked Risks in Healthcare Networks
This research examines the oft-overlooked infection vectors in today’s healthcare networks: exposed medical devices and supply chain attacks.
April 5th, 2018 2 minTrendAI™ Research
Read article -
ResearchTesla and Jenkins Servers Fall Victim to Cryptominers
Vulnerable enterprise servers are being compromised by individuals or groups looking for resources to mine cryptocurrency. The latest victims are automobile-maker Tesla and users of Jenkins servers.
February 21st, 2018 3 minTrendAI™ Research
Read article -
ResearchNorth Korean Hackers Allegedly Exploit Adobe Flash Player Vulnerability (CVE-2018-4878) Against South Korean Targets
In a security alert posted on its website on January 31, The South Korean Computer Emergency Response Team (KR-CERT) warned of a zero-day vulnerability in Adobe Flash player that could be maliciously exploited.
February 2nd, 2018 3 minTrendAI™ Research
Read article -
ResearchDigital Vandals: Exploring the Methods and Motivations behind Web Defacement and Hacktivism
Activists have traditionally used physical signs and catchy slogans to promote their political agenda, but the internet offers a significantly broader audience, so these activities have since moved online.
January 22nd, 2018 8 minTrendAI™ Research
Read article -
ResearchDelving into the World of Business Email Compromise (BEC)
We looked at BEC-related incidents over a span of nine months to see emerging and present trends from BEC incidents, examine the tools and techniques used by cybercriminals, and analyze the data to give us an overall picture of what BEC looks like today.
January 18th, 2018 3 minTrendAI™ Research
Read article -
ResearchMeltdown and Spectre Intel Processor Vulnerabilities: What You Need to Know
Microsoft, Linux, Google, and Apple started rolling out patches addressing design flaws in processor chips that security researchers named Meltdown and Spectre. What are they, and how can they affect users?
January 4th, 2018 3 minTrendAI™ Research
Read article -
ResearchData on 123 Million US Households Exposed Due to Misconfigured AWS S3 Bucket
A year that saw major data breaches, including some notable ones from companies like Uber and Equifax, just saw another breach that will likely rank as among 2017’s most notable incidents.
December 20th, 2017 2 minTrendAI™ Research
Read article -
ResearchCities Exposed in Shodan
Western European, UK, French, German, and US cities exposed. Are your connected devices searchable on the internet? Find out what you are risking.
November 28th, 2017 4 minTrendAI™ Research
Read article -
ResearchUber Breach Exposes the Data of 57 Million Drivers and Users
In a highly publicized data breach incident, rideshare application Uber announced that the personal information of 57 million customers and drivers were potentially compromised in October 2016.
November 22nd, 2017 4 minTrendAI™ Research
Read article -
ResearchCoinhive Miner Emerges as the 6th Most Common Malware
A new report reveals Coinhive's reach after it ranked the coin miner as the 6th most common malware in the world.
November 15th, 2017 2 minTrendAI™ Research
Read article -
ResearchHigh-Tech Highways
Intelligent Transportation Systems are slowly being adopted all over the world. Securing the future of transportation from cyberattacks should be a top priority.
October 24th, 2017 3 minTrendAI™ Research
Read article -
ResearchBest Practices: Securing Your Mobile Device
The number of mobile phone users around the world is projected to exceed the five billion mark by 2019. Since cybercriminals usually cast wide nets to reach more potential victims, mobile users should protect their devices early on to defend against threats.
October 10th, 2017 5 minTrendAI™ Research
Read article -
ResearchThe Middle Eastern and North African Underground: Where Culture and Cybercrime Meet
The Middle Eastern and North African (MENA) underground is characterized by its ironic mix of ideology and felony. We take a look at its inner workings, available wares, and the unique sense of brotherhood shared by its players.
October 10th, 2017 3 minTrendAI™ Research
Read article -
ResearchBest Practices: How to Secure Your Social Media Accounts
The leading social media platforms have billions of users, and the number keeps getting bigger every year. Learn how to keep your social media accounts secure.
October 4th, 2017 5 minTrendAI™ Research
Read article -
ResearchRed Alert 2.0 Android Trojan Spreads Via Third Party App Stores
A spate of new attacks targeting the Android operating system have been discovered using a banking trojan named Red Alert 2.0.
September 20th, 2017 2 minTrendAI™ Research
Read article -
ResearchBest Practices: Deploying an Effective Firewall
There is no panacea for building a hacker-proof firewall, but there are things that can be done to streamline its management. These best practices provide a starting point for managing your firewall—so you and your company don’t get burned.
September 14th, 2017 5 minTrendAI™ Research
Read article -
ResearchBest Practices: Backing Up Data
In a data-driven world where information is often a company’s most valuable asset, protecting data is more important than it’s ever been.
September 7th, 2017 5 minTrendAI™ Research
Read article -
ResearchBest Practices: Securing Sysadmin Tools
Legitimate tools used by IT/system administrators have become valuable cybercriminal targets because of the privilege they provide for greater network access. Here are some best practices for mitigating the abuse of sysadmin tools.
September 5th, 2017 4 minTrendAI™ Research
Read article -
ResearchA Shift in the ATM Malware Landscape: From Physical to Network-based Attacks
ATM malware has become a mainstay in many cybercriminals’ arsenal due to its capability to steal money. In our joint efforts with Europol’s EC3, we explain in detail how criminals continue to leverage different ATM malware families and attack types.
September 5th, 2017 4 minTrendAI™ Research, Europol’s European Cybercrime Centre (EC3)
Read article -
ResearchPatching Problems and How to Solve Them
Can we fix the lag between patch releases and actual implementation? Current events reveal that patching should be made a definite priority. We provide a guide on how to manage patching for enterprises and large organizations.
August 30th, 2017 4 minTrendAI™ Research
Read article -
ResearchFrequently Asked Questions: The Petya Ransomware Outbreak
The Petya ransomware family has reemerged, becoming one of the most impactful yet. Is it similar to WannaCry? Does it have a kill switch? Here are some frequently asked questions about the threat.
June 28th, 2017 7 minTrendAI™ Research
Read article -
ResearchWhat do Hackers do with Your Stolen Identity?
Identity theft is currently a gold mine for cybercriminals—one that reached an all-time high in 2016, with up to $16 billion worth of losses caused by fraud and identity theft. But what exactly happens with the stolen information?
June 21st, 2017 9 minTrendAI™ Research
Read article -
ResearchErebus Linux Ransomware: Impact to Servers and Countermeasures
A South Korean web hosting company was hit by a Linux version of the Erebus ransomware. Here’s what you need to know about the threat and what sysadmins can do to defend against it.
June 15th, 2017 5 minTrendAI™ Research
Read article -
ResearchSecuring Smart Cities
Cities around the world are getting smarter, but are they being designed with security in mind?
May 30th, 2017 20 minTrendAI™ Research
Read article -
ResearchThe State of SCADA HMI Vulnerabilities
A complete discussion of the different vulnerability categories, including case studies of vulnerable SCADA HMIs. The paper also provides a guide for vulnerability researchers, as well as vendors on quick and efficient bug discovery.
May 23rd, 2017 3 minTrendAI™ Research
Read article -
ResearchProtecting Home Networks: Start by Securing the Router
As home routers add more features, securing them becomes more difficult. End users should be aware of the effects of compromise, and how to protect their home routers.
May 18th, 2017 5 minTrendAI™ Research
Read article -
ResearchWannaCry/Wcry Ransomware: How to Defend against It
Here’s what you need to know about this ongoing threat and what you can do to protect against it.
May 13th, 2017 5 minTrendAI™ Research
Read article -
ResearchRogue Robots: Testing the Limits of an Industrial Robot’s Security
The modern world relies heavily on industrial robots. But is the current robotics ecosystem secure enough to withstand a cyber attack?
May 3rd, 2017 5 minTrendAI™ Research
Read article -
ResearchMalware Using Exploits from Shadow Brokers Leak Reportedly in the Wild
Exploits found in the trove of malware recently leaked by hacking group Shadow Brokers are reportedly being used to install ransomware and backdoor. Are your systems protected?
April 26th, 2017 6 minTrendAI™ Research
Read article -
ResearchFrom Espionage to Cyber Propaganda: Pawn Storm's Activities over the Past Two Years
This paper takes a look at Pawn Storm's operations within the last two years, and how the group has expanded their activities from espionage to the use of cyber propaganda tactics.
April 25th, 2017 2 minTrendAI™ Research
Read article -
ResearchRansomware Recap: Expanding Distribution Methods
This week's recap highlights new distribution methods that make ransomware more unpredictable in terms of how they infect their victims.
April 25th, 2017 4 minTrendAI™ Research
Read article -
ResearchBrickerBot Malware Emerges, Permanently Bricks IoT Devices
A recently uncovered malware Brickerbot is making the rounds with the capability to permanently brick Internet of Things (IoT) devices. How can it be mitigated?
April 19th, 2017 4 minTrendAI™ Research
Read article -
ResearchShadow Brokers Leaks Hacking Tools: What it Means for Enterprises
Hacking group Shadow Brokers recently leaked a new trove of information-stealing tools and exploits targeting Windows systems and servers. What does this mean for enterprises?
April 18th, 2017 5 minTrendAI™ Research
Read article -
ResearchInfosec Guide: Dealing with Threats to a Bring Your Own Device (BYOD) Environment
This Infosec Guide will tackle the primary threats organizations face when implementing BYOD programs, as well as best practices and solutions to mitigate these threats.
April 17th, 2017 7 minTrendAI™ Research
Read article -
ResearchOperation Cloud Hopper: What You Need to Know
A global cyberespionage campaign has been uncovered compromising managed IT service providers, using them as in-betweens to attack their targets. Here’s what you need to know.
April 10th, 2017 4 minTrendAI™ Research
Read article -
ResearchThe Michelangelo Virus, 25 Years Later
The Michelangelo virus scare remains a significant turning point for computer security, 25 years after its supposed major impact,
March 6th, 2017 3 minTrendAI™ Research
Read article -
ResearchUS Cities Exposed in Shodan
An in-depth analysis of Shodan data reveals how some of the biggest US cities fare in terms of exposed cyber assets, what this means in terms of security, and how home users and organizations can protect their data.
February 15th, 2017 7 minTrendAI™ Research
Read article -
ResearchBest Practices: Identifying and Mitigating Phishing Attacks
Despite being one of the oldest scams on the internet, phishing continues to be a significant problem for both individuals and organizations. Here are some methods to identify and deal with potential phishing attempts.
February 10th, 2017 7 minTrendAI™ Research
Read article -
ResearchSecurity 101: Business Process Compromise
Past events show that attackers don't just target people, but processes as well. Enterprises should be aware of the of rising possibility of Business Process Compromises.
February 1st, 2017 6 minTrendAI™ Research
Read article -
ResearchSecuring Your Routers Against Mirai and Other Home Network Attacks
Cybercriminals can turn unsecure home routers into slaves for their botnets or even abuse them to steal banking credentials. Know about your router’s hidden weaknesses and the many ways you can defend your homes and businesses against these threats.
January 31st, 2017 4 minTrendAI™ Research
Read article -
ResearchInfoSec Guide: Mitigating Email Threats
Email remains an important communication tool for business organizations. Unfortunately, its widespread use also makes it an ideal platform for cybercrime. Here are some tips for dealing with email-based threats.
January 30th, 2017 7 minTrendAI™ Research
Read article -
ResearchA Rundown of the Biggest Cybersecurity Incidents of 2016
The most notable cybersecurity incidents of the past year, from the biggest data breaches and most expensive attacks to the most persistent attackers and impactful malware.
December 18th, 2016 17 minTrendAI™ Research
Read article -
ResearchYahoo Discloses 2013 Breach that Exposed Over One Billion Accounts
Yahoo disclosed yet another breach that exposed 1 billion user accounts in August 2013. This comes shortly after it announced a smaller but significant hack last September.
December 15th, 2016 3 minTrendAI™ Research
Read article -
ResearchThe Cybercriminal Roots of Selling Online Gaming Currency
The sale of online gaming currencies, while not illegal, has been found to have cybercriminal ties. This research paper covers how cybercriminals use the profits from the trade of these virtual currencies to fund other attacks.
October 10th, 2016 2 minTrendAI™ Research
Read article -
ResearchAre Pagers Leaking Your Patients’ PHI?
With a little SDR knowledge and a $20 USB dongle, attackers can read unencrypted pager messages from tens of kilometers away. Who still uses pagers in this day and age? Healthcare facilities. Goodbye, PHI.
September 26th, 2016 2 minTrendAI™ Research
Read article -
Research500 Million Yahoo Users Affected by Data Breach – Password Change Recommended
Yahoo users are prompted to change passwords as a massive breach compromises 500 million accounts.
September 23rd, 2016 3 minTrendAI™ Research
Read article -
ResearchEnterprise Network Protection: Protecting Data through Network Segmentation
An enterprise guide on network segmentation; how it works to secure large enterprise networks, why it's needed, and examples of some of the most widely used network models for different industries.
September 14th, 2016 3 minTrendAI™ Research
Read article -
ResearchRansomware-as-a-Service: Ransomware Operators Find Ways to Bring in Business
Cybercriminals are taking cues from legitimate enterprises and focusing on growing their operations. Different variations of ransomware-as-a-service show the evolving nature of the business.
September 2nd, 2016 6 minTrendAI™ Research
Read article -
ResearchRansomware 101: What, How, and Why
This infographic shows how ransomware has evolved, how big the problem has become, and ways to avoid being a ransomware victim.
June 14th, 2016 3 minTrendAI™ Research
Read article -
ResearchBillion-Dollar Scams: The Numbers Behind Business Email Compromise
Business Email Compromise schemes are one of the biggest threats to companies to date. One carefully crafted email sent to the right person can cost a company millions of dollars. How is it done and what makes it so effective?
June 9th, 2016 6 minTrendAI™ Research
Read article -
ResearchMarcher Android Banking Malware Now Targeting UK Customers
Developers of the Android-based banking trojan Marcher updated the malware, adding major banks in United Kingdom to its list of targets.
June 3rd, 2016 3 minTrendAI™ Research
Read article -
ResearchAustrian Aeronautics Company Loses Over €42 Million to BEC Scam
Austria-based Fischer Advanced Composite Components AG (FACC), a major designer and manufacturer of aircraft components and systems, falls prey to a business email compromise (BEC) scheme that cost the company over 42 million euros in losses.
May 26th, 2016 3 minTrendAI™ Research
Read article -
ResearchKeeping Digital Assets Safe: The Need for Data Classification
This primer discusses the importance of data classification, and how organizations can implement these strategies to reduce the effects should a data breach occur.
May 20th, 2016 2 minTrendAI™ Research
Read article -
Research2012 Linkedin Breach had 117 Million Emails and Passwords Stolen, Not 6.5M
Long time users of Linkedin users may very well need to change their passwords once more as a cybercriminal puts the email addresses and passwords of 117 million users up for sale.
May 18th, 2016 2 minTrendAI™ Research
Read article -
ResearchCryptXXX, 7ev3n Ransomware Get Major Updates
Newly-discovered ransomware strains, CryptXXX and 7ev3n, get major updates from malware authors.
May 11th, 2016 5 minTrendAI™ Research
Read article -
ResearchDark Motives Online: An Analysis of Overlapping Technologies Used by Cybercriminals and Terrorist Organizations
Research on the common technologies used by cybercriminals and terrorists to benefit their cause, from the services they abuse to the tools they’ve homebrewed to streamline activities.
May 3rd, 2016 11 minTrendAI™ Research
Read article -
ResearchReveton Ransomware Descendant, CryptXXX Discovered
A new ransomware strain, CryptXXX, was recently discovered making its rounds since the tail-end of March.
April 20th, 2016 4 minTrendAI™ Research
Read article -
ResearchLocky Ransomware Strain Led Kentucky Hospital to an “Internal State of Emergency”
Kentucky-based Methodist Hospital announced a ransomware attack that led to an “internal state of emergency.”
March 24th, 2016 4 minTrendAI™ Research
Read article -
ResearchThe Angler Connection: Massive Malvertising Campaign Linked to Angler Exploit Kit and BEDEP
Top news sites, entertainment portals, and political commentary sites were affected by a massive malvertising campaign related to the Angler Exploit Kit.
March 16th, 2016 3 minTrendAI™ Research
Read article -
ResearchInternet of Things: Connected Life Security
The world is now more connected than ever. Gartner predicts 25 billion connected devices will be in use by 2020. How is this increased convenience affecting our privacy and security across the globe?
February 19th, 2016 3 minTrendAI™ Research
Read article -
ResearchNew Crypto-Ransomware Locky Uses Malicious Word Macros
A new crypto-ransomware type called Locky has been discovered riding on document-based macros and using infection techniques borrowed from the notorious banking malware DRIDEX.
February 19th, 2016 3 minTrendAI™ Research
Read article -
ResearchFrequently Asked Questions: BlackEnergy
What we know about BlackEnergy, a Trojan known to have been used in attacks on Ukraine power providers that caused a massive outage in late 2015.
February 11th, 2016 2 minTrendAI™ Research
Read article -
ResearchOperation Pawn Storm: Fast Facts and the Latest Developments
Operation Pawn Storm is an active economic and political cyber-espionage operation that has targeted high-profile entities from government institutions to media personalities. Here are its latest developments.
January 16th, 2016 3 minTrendAI™ Research
Read article -
ResearchAscending the Ranks: The Brazilian Cybercriminal Underground in 2015
Trend Micro's latest visit to the Brazilian cybercriminal underground reveals its latest trends and available services, from online banking malware to tutorial classes for new cybercriminals.
January 12th, 2016 3 minTrendAI™ Research
Read article -
ResearchSecurity 101: Business Email Compromise (BEC) Schemes
The Federal Bureau of Investigation (FBI) released a public service announcement earlier this year warning about Business Email Compromise (BEC) schemes. Here’s what you need to know, and what you can do to prevent attacks.
January 11th, 2016 8 minTrendAI™ Research
Read article -
ResearchFirst Malware-Driven Power Outage Reported in Ukraine
Malware found in power suppliers' systems may be responsible for causing a massive power outage in Ukraine.
January 6th, 2016 4 minTrendAI™ Research
Read article -
ResearchSpear Phishing 101: What is Spear Phishing?
The objective of spear phishing and phishing are ultimately the same—to trick a target into opening an attachment or click on a malicious embedded link. But what is spear phishing? Learn more from this article.
September 24th, 2015 4 minTrendAI™ Research
Read article -
ResearchFollow the Data: Dissecting Data Breaches and Debunking the Myths
A decade's worth of breaches has led to this. Forward-looking threat researcher Numaan Huq analyzes what has happened to the stolen data affecting major US industries. We map out the probabilities; see where the information goes and how much it's sold.
September 22nd, 2015 9 minTrendAI™ Research
Read article -
ResearchFBI Warns Public on Dangers of the Internet of Things
The FBI released a Public Service Announcement that warns about the potential security risks of the IoT. Learn more about these risks and their real-life consequences.
September 17th, 2015 3 minTrendAI™ Research
Read article -
ResearchVirtual Patching in Mixed Environments: How It Protects You
A primer on the advantages of implementing virtual patching to protect systems against unpatched vulnerabilities.
August 20th, 2015 2 minTrendAI™ Research
Read article -
ResearchHacktivism 101: A Brief History and Timeline of Notable Incidents
While not done for profit, hacktivism has forced companies and organizations to face critical security challenges. Find out what it is and how it evolved from being the “Internet’s voice” to one of today's biggest security threats.
August 17th, 2015 5 minTrendAI™ Research
Read article -
ResearchThe Gaspot Experiment: How Gas-Tank-Monitoring Systems Could Make Perfect Targets for Attackers
In the US and other locations worldwide, gas stations are primarily privately owned. While most of them have been modernized, there are still a lot of risks tied to their business, especially those that are connected to the Internet.
August 6th, 2015 2 minTrendAI™ Research
Read article -
ResearchSecurity On-The-Go: Setting up a Virtual Private Network (VPN)
There are privacy and security risks involved in connecting to public or 'free' Wi-fi hotspots. Here's a 4-step guide to setting up a virtual private network (VPN) for the times when you have to connect to unfamiliar networks.
June 24th, 2015 2 minTrendAI™ Research
Read article -
ResearchGoing Deeper: Exploring the Deep Web
An in-depth look into the duality of the Deep Web—how its anonymity allows free communication and the trade of illegal goods and services. See how it impacts the real world today, and how it could evolve over the next few years.
June 22nd, 2015 2 minTrendAI™ Research
Read article -
ResearchThe Case for Making BYOD Safe
BYOD networks can benefit both the workers and the company, but it also presents a number of potential risks. This infographic details the challenges of balancing employee freedom, functionality, and security on BYOD.
May 29th, 2015 2 minTrendAI™ Research
Read article -
ResearchHow Operation Tropic Trooper Infiltrates Secret Keepers
This research paper offers a look into "Operation Tropic Trooper", an ongoing targeted attack campaign that uses old infiltration tactics to steal state and industry secrets since 2012.
May 14th, 2015 2 minTrendAI™ Research
Read article -
ResearchGone Phishing: How Phishing Leads to Hacked Accounts and Identity Theft
Phishing continues to be a popular method used by cybercriminals to trick users into giving out their personal information and credentials. Before you become a victim, learn about popular phishing techniques, and how to spot a phishing attempt.
May 6th, 2015 6 minTrendAI™ Research
Read article -
ResearchIdentity Theft and the Value of Your Personal Data
How dangerous is it to leave your personal information—your name, your social security number, your credit card and financial details, even your email address and phone number—where other people can access them?
April 30th, 2015 3 minTrendAI™ Research
Read article -
ResearchRansomware: What It Is and How You Can Protect Yourself
Ransomware is a type of malware that locks your computer screen and prevents you from accessing your files until you pay a “ransom”. Learn more about this type of malware and how you can prevent likely attacks.
April 21st, 2015 5 minTrendAI™ Research
Read article -
ResearchWorld Backup Day: What, When, Where and Why You Need to Back up and How to do it
Observe World Backup Day by learning why you should back up, what to back up, where to store them, when you should do it, and how to do it.
March 31st, 2015 5 minTrendAI™ Research
Read article -
ResearchMalvertising: When Online Ads Attack
Cybercriminals are increasingly using malicious advertisements as a platform for spreading malware. Find out how they work how you can protect yourself from these online threats.
March 19th, 2015 3 minTrendAI™ Research
Read article -
ResearchRocket Kitten Showing Its Claws: Operation Woolen-GoldFish and the GHOLE campaign
This research paper offers a look into the activities and methods used by Rocket Kitten, a group behind cyber attacks on Israeli and European organizations
March 19th, 2015 4 minTrendAI™ Research
Read article -
ResearchOperation Arid Viper: Bypassing the Iron Dome
This Trend Micro paper unearths two separate but linked malware campaigns—Operation Arid Viper and Advtravel. Operation Arid Viper targets specific Israeli organizations using infrastructure in Germany with ties to Gaza in Palestine.
February 16th, 2015 2 minTrendAI™ Research
Read article -
ResearchMillions Affected in Anthem Breach, Healthcare Companies Prime Attack Targets
Tens of millions of current and former customers and employees of Anthem Inc., the second largest health insurance provider in the United States, are reportedly affected in a targeted attack.
February 10th, 2015 3 minTrendAI™ Research
Read article -
ResearchThe Hack of Sony Pictures: What We Know and What You Need to Know
While Sony recovers from the massive hack, we continue to monitor investigations and developments. Here's a rundown of what happened, what was stolen, who’s being implicated, and tips on how you can defend against likely attacks. [updated]
December 8th, 2014 3 minTrendAI™ Research
Read article -
ResearchFrom Cybercrime to Cyberspying: Using Limitless Keylogger and Predator Pain
A Trend Micro research paper that reveals the operations and cybercriminals behind Predator Pain and Limitless Keylogger, which are malware toolkits that are easily obtained from underground forums.
November 11th, 2014 2 minTrendAI™ Research
Read article -
ResearchPawn Storm Espionage Attacks Use Decoys, Deliver SEDNIT
This Trend Micro paper unravels a series of attacks that targets military officials and defense contractors. Dubbed as “Operation Pawn Storm,” the group of threat actors use two known attack vectors: spear phishing emails and a network of phishing websites.
October 22nd, 2014 2 minTrendAI™ Research
Read article -
ResearchWhat to Consider When Buying a Smart Device
Buying into the Internet of Things starts out with smart home devices. Unfortunately, connecting your home devices to the Internet has its drawbacks. Here are some important factors to consider before buying smart devices for the home.
August 4th, 2014TrendAI™ Research
Read article -
ResearchPLEAD Campaign Attacks Taiwan Ministries
The PLEAD campaign is the second attack to target entities in Taiwan in the first half of 2014. Taiwanese agencies were also targeted in May using a Microsoft Word zero-day vulnerability.
July 27th, 2014TrendAI™ Research
Read article -
Research.Bit Domain Used To Deliver Malware and other Threats
For many users, .com is the only domain that matters. But when cybercriminals start using .bit, a new kind of top-level domain (TLD) for malicious activities, people are bound to take notice.
November 19th, 2013 1 minTrendAI™ Research
Read article -
BlogHacking Tools, Survey Scam Target Facebook Users
June 6th, 2012 3 minTrendAI™ Research
Read article