Fortinet has recently announced its March 2010 Threatscape report. It showed
domination of ransomware threats with nine of the detections in the malware top
ten list resulting in either scareware or ransomware infesting the victim's PC.
Fortinet has observed that the primary drivers behind these threats to be two
of the most notorious botnet 'loaders'-Bredolab and Pushdo. Another important
finding is the aggressive entrance of a new Zero-day threat in FortiGuard's top
10 attack list, 'MS.IE.Userdata. Behavior.Code.Execution', which accounted for
25 percent of the detected activity last month.
SMS-based ransomware high activity: A new Ransomware Threat, W32/DigiPog.EP
appeared in Fortinet's top 10 Malware list. DigiPog is an SMS blocker using
Russian language, locking out a system and aggressively killing off popular
applications like Internet Explorer and Firefox until an appropriate code is
entered into a field provided to the user. To obtain the code, a user must send
an SMS to the provided number, receiving a code in return. Upon execution,
DigiPog will register the user's MAC address with its server. It is the first
time that SMS-based Ransomware enters Fortinet's top 10 list, showing that the
rise of Ransomware is well on its way.
Botnets-the competition gets tough: While the infamous Bredolab and
Pushdo botnets can be identified behind the strong Ransomware activity this
month, a challenger has been particularly active this month. Sasfis, another
botnet loader, moved up eight positions in the top 100 attack list from last
month, landing just behind Gumblar and Conficker network activity in the fifth
position. Sasfis is the latest example of simplified botnets, which are used
heavily for malicious business services.
Zero-day attack forces in: A new zero-day threat has aggressively
entered into FortiGuard's top 10 attack list, 'MS.IE.Userdata.Behavior.
Code.Execution' (CVE-2010-0806, FortiGuard Advisory 2010-14). This triggers
vulnerability in Internet Explorer, making remote code execution through a
drive-by download possible. Accounting for one fourth of the detected activity
in March, this exploit was ranked #2 in the top 10 attacks last month and
remained very active, predominantly in Japan, Korea and the USA.
"Cybercriminals are clearly pursuing new ways to lure consumers and threaten
the enterprise at large. Troublesome zero-day exploits continue to attack
popular client-side software, while methods such as ransomware and crime as a
service help them increase their reach and make their attacks more effective
against end-users," said Derek Manky, Project Manager-Cyber Security and Threat
Research, Fortinet. "With cybercrime techniques getting more sophisticated every
day, it is critical to educate users on the importance of having the right
security software and patches in place. These can help protect consumers and
organizations against known vulnerabilities, but also unknown ones such as
Zero-day threats," he added.
DQc News Bureau
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us