November threat activity featured GitHub-hosted ransomware, healthcare-targeting, and (surprise) election-themed attacks

November threat activity featured GitHub-hosted ransomware, healthcare-targeting, and (surprise) election-themed attacks

Zscaler ThreatLabZ team releases "2020 State of Encrypted Attacks" report

Cybercriminals ramped up activity in the past month, launching attacks linked thematically to the U.S. federal election, bombarding new healthcare-industry targets with ransomware assaults, and even hiding malware in plain sight on legitimate hosts like GitHub. The Zscaler ThreatLabZ cybersecurity research team headed by Deepen Desai, CISO and VP Security Research & Operations tracked it all:

  • ThreatLabZ researchers discovered destructive malware disguised as an MSI installer binary hosted on GitHub, of all places. ThreatLabZ engineers reverse-engineered the malware code, and traced its source back to Chinese state-sponsored hackers. More on their detective work here.
  • Healthcare and the public health sector are active ransomware targets, as noted in a joint cybersecurity advisory from various government organizations

The recent 2020 United States election sparked numerous election-themed scams and campaigns that involved malware, redirectors, fake domains, and fake surveys.

Underlining the latest threats, ThreatLabZ just released its annual “2020 State of Encrypted Attacks” report. This report examines the massive volume of data transactions across Zscaler’s Zero Trust Exchange, and highlights several findings:

  • 80% of all traffic uses SSL/TLS encryption by default.
  • SSL/TLS-encrypted threats increased by 260% in the last nine months.
  • Cloud services like Google Drive, OneDrive, AWS, or Dropbox were used in 30% of all SSL-based attacks.
  • Since the start of the year, the healthcare industry faced 1.6 billion encrypted threats.
  • Ransomware attacks delivered via encrypted web traffic increased five times over the last six months.

You can download an infographic breakdown of the report results on Zscaler’s website.

No alt text provided for this image

Learn more about the report’s findings, and to download the results, read Deepen’s article on the latest November 2020 ThreatLabZ research. 

Enterprises must inspect encrypted SSL/TLS traffic to protect against attacks, period. Unfortunately, legacy on-premises security tools can’t scale to effectively decrypt, inspect, and re-encrypt traffic. That limitation carries immense risk to enterprises relying on legacy security.

Zscaler’s Zero Trust Exchange is the largest cloud  native security platform in the world, and processes more than 140 billion transactions per day (10x Google searches), and effectively blocks more than 100 million threats per day. Zscalers' cloud native-proxy architecture allows to accommodate traffic spikes and fully inspect SSL/TLS encrypted traffic for security & threat prevention using features like DLP, Sandbox, CASB, & CSPM all without compromising performance.

Among its extensive monitoring of the global Zscaler Zero Trust Exchange, the ThreatLabZ team produces the Global Internet Threats Insights dynamic dashboard. For more information on Zscaler ThreatLabZ cybersecurity research, check out our published reports here.

And a reminder: Zenith Live 2020, the premier virtual cloud summit, kicks off next month with sessions on how to secure enterprise digital transformation with scalable SSL inspection of all traffic. 

💬 Hans Vargas-Silva

Information Security Leader | Purdue @CERIAS alumni | Life-long Learner | Board Member & Community Volunteer | Immigrant | Husband and Father

4y

Very interesting, thank you for sharing Jay Chaudhry.

Like
Reply
David Thackshire

Cyber Security Engineer

4y

Scary stuff, thank heavens the zscaler team has our back

Like
Reply
Raghu Rao

Parallel Entrepreneur, Investor & Fund Partner, Strategic Advisor and NACD CERT Certified Board Director

4y
Like
Reply

To view or add a comment, sign in

More articles by Jay Chaudhry

  • Lessons Learned from the State of Silicon Valley Start-ups

    Lessons Learned from the State of Silicon Valley Start-ups

    I recently read a compelling article in Business Insider entitled, “Silicon Valley is bracing for a ‘Darwinian moment…

    11 Comments
  • Dispatch from Zenith Live Berlin

    Dispatch from Zenith Live Berlin

    On the heels of a successful @Zscaler #ZenithLive user conference in Las Vegas last month, we continued our momentum…

    2 Comments
  • Updates from Zenith Live ‘23

    Updates from Zenith Live ‘23

    It was fantastic to see everyone at Zenith Live ‘23 this week in Las Vegas where customers, partners, media and…

    7 Comments
  • Zenith Live 2023: Redefining Secure Digital Transformation

    Zenith Live 2023: Redefining Secure Digital Transformation

    Technology leaders, IT practitioners, security analysts, and other industry watchers will soon gather at Zscaler's…

  • Observations from RSAC 2023

    Observations from RSAC 2023

    We recently wrapped up an exciting and highly engaging week at #RSAC. I couldn’t be more energized and inspired by the…

    3 Comments
  • Making a Positive Impact By Giving Back

    Making a Positive Impact By Giving Back

    When I founded Zscaler over 15 years ago, I wanted to build an iconic technology company that would fundamentally…

    10 Comments
  • Reflections on My Trip to India

    Reflections on My Trip to India

    This month, I had the opportunity to visit several cities in India to interact with customers, partners and Zscaler…

    9 Comments
  • Observations from My Trip to Japan

    Observations from My Trip to Japan

    I have been meaning to return to Japan since it is a critical country for us, so I was excited to have the opportunity…

    4 Comments
  • Sincere Thanks to Zscaler Customers & Partners

    Sincere Thanks to Zscaler Customers & Partners

    As we begin 2023, I want to express my sincere thanks and appreciation to our Customers and Partners for their…

    14 Comments
  • Zscaler Once Again Recognized on 2022 Deloitte Technology Fast 500 List

    Zscaler Once Again Recognized on 2022 Deloitte Technology Fast 500 List

    One of only three companies in the Bay Area to have made the list five years in a row I am extremely proud of the…

    30 Comments

Insights from the community

Others also viewed

Explore topics