WatchGuard Finds Explosion of Attacks Targeting Leading Web Conference Solution

Network attacks targeting a vulnerability in the Cisco Webex Chrome extension have increased dramatically according to WatchGuard® Technologies. In its latest Internet Security Report for the last quarter of 2018, they were the second-most common network attack. The vulnerability was first disclosed and patched in 2017 and attacks were almost non-existent in early 2018, but WatchGuard detections grew by over 7,000 percent from Q3 to Q4.

The report also shows that phishing campaigns saw a dangerous increase in sophistication, with new attacks using advanced methods including threatening to release recordings of users visiting adult content online, customising emails for specific targets and creating fake banking login web pages. Based on data from tens of thousands of active WatchGuard Firebox appliances around the world, a new sextortion phishing attack was the second-most common attack detected in Q4 2018. It accounted for almost half of the unique malware hashes detected because the email phishing message is tailored to each recipient. The message claims the sender has infected the victim’s computer with a trojan and recorded them visiting adult websites, threatening to send these compromising images to their email contacts unless they pay a ransom.

“There was a noticeable increase in advanced phishing attacks targeting high-value information,” said Corey Nachreiner, CTO at WatchGuard Technologies. “Now more than ever, it’s vital for businesses to take the layered approach to security and deploy solutions that offer DNS-level filtering designed to detect and block potentially dangerous connections and automatically refer employees to resources that bolster phishing awareness and prevention. A combination of security controls and human training will help businesses avoid becoming hooked by phishing attacks.”

The other top findings from the report include:

  • 16.5 percent of all Fireboxes were targeted by CoinHive crypto miner – The most widespread malware variant in Q4 came from the popular CoinHive crypto miner family, showing that crypto mining remains a popular attack type. Two of the top ten most common pieces of malware detected were also crypto miners.
  • A major phishing attack leverages a fake bank page – Another widespread piece of malware in Q4 sent a phishing email with a fake, but highly realistic Wells Fargo login page to capture victim emails and passwords. Overall, WatchGuard saw a rise in sophisticated phishing attacks targeting banking credentials.
  • One ISP’s filtering error routed Google traffic through Russia and China for 74 minutes – The report includes a technical analysis of a Border Gateway Protocol (BGP) hijack in November 2018 thatinadvertently sent most of Google’s traffic through Russia and China for a short time. WatchGuard found that a Nigerian ISP called MainOne made a mistake in their routing filters, which then spread to Russian and Chinese ISPs and caused much of Google’s traffic to be routed through these ISPs unnecessarily. This accidental hijack highlights the underlying insecure standards that the internet is based on. A sophisticated attack targeting these flaws could have potentially catastrophic consequences.
  • Network attacks rise after historic lows in mid-2018 – Network attacks rose 46 percent by volume and 167percent in terms of unique signature hits in Q4 compared to Q3 2018. This follows a trend seen in previous years with attacks ramping up during the holiday season.

The 2018 Q4 ISR also includes a granular analysis of source code for the Exobot banking trojan. This highlysophisticated malware attempts to steal banking and financial information from Android devices. The WatchGuard Threat Lab’s analysis includes a list of the 150 sites such as Amazon, Facebook Paypal and Western Union that Exobot can automatically target, as well as a detailed look at the UI an attacker using Exobot would use to push commands to infected devices.

The insights, research and security best practices included in WatchGuard’s quarterly Internet Security Report help organisations of all sizes understand the current cyber security landscape and better protect themselves, their partners and customers from emerging security threats.

The finding are based on anonymised Firebox Feed data from over 42,000 active WatchGuard UTM appliances worldwide. In total, these Fireboxes blocked over 16 million malware variants (382 per device) and approximately 1,244,000 network attacks (29 per device) in Q4 2018.

For more information, download the full report here and to access live, real-time threat insights by type, region and date, visit WatchGuard’s Threat Landscape data visualisation tool today.

Ronan Leonard

Recent Posts

Kissing the sun: the mysteries of the solar wind

Using data collected by NASA's Parker Solar Probe during its closest approach to the sun, a University…

14 hours ago

New ARC Hub Launched to Accelerate Research-to-Impact Pathway

The Research Ireland ARC (Accelerating Research to Commercialisation) Hub for ICT was officially launched today…

15 hours ago

Disney+ Ireland to Launch Ad-Supported Plan in March

Disney+ in Ireland is set to launch a new ad-supported subscription plan on March 3. The…

1 day ago

5 Steps to a Truly Magnificent Speech: Lessons from Mark Carney

Did you watch Mark Carney’s presentation last week at Davos?  No, is probably your answer,…

1 day ago

Data Reveals Ireland’s Most Streaming-Obsessed Counties

With recent miserable weather keeping more people indoors, Virgin Media Ireland, Ireland’s leading telecommunications and entertainment provider, has analysed Google…

1 day ago

BelTech Returns to Spotlight a New Era of Software Engineering

Ireland’s leading technology conference, BelTech, will return on 5 March 2026, bringing together industry leaders,…

1 day ago

More about Irish Tech News


Irish Tech News are Ireland’s No. 1 Online Tech Publication and often Ireland’s No.1 Tech Podcast too.


You can find hundreds of fantastic previous episodes and subscribe using whatever platform you like via our Anchor.fm page here: https://anchor.fm/irish-tech-news


If you’d like to be featured in an upcoming Podcast email us at Simon@IrishTechNews.ie now to discuss.


Irish Tech News have a range of services available to help promote your business. Why not drop us a line at Info@IrishTechNews.ie now to find out more about how we can help you reach our audience.


You can also find and follow us on Twitter, LinkedIn, Facebook, Instagram, TikTok and Snapchat.