Redwood City, Calif.-based Avast has released its annual Threat Landscape Report, detailing what the company sees as the biggest security trends facing consumers (and by extension their financial institutions) in 2019.
The Dawn of Adversarial AI
Avast foresees the emergence of a class of attacks known as “DeepAttacks” that use AI-generated content to evade AI security controls. In 2018, the company observed many examples where researchers used adversarial AI algorithms to fool humans. Examples include the fake video of former President Barack Obama created by Buzzfeed in which President Obama is seen delivering fake sentences, in a convincing fashion.
Avast also cited examples of adversarial AI deliberately confounding the smartest object detection algorithms, such as fooling an algorithm into thinking that a stop sign was a 45-mph speed limit sign.
In 2019, Avast predicts DeepAttacks will be deployed more commonly in an attempt to evade both human detection and smart defenses.
IoT Threats Will Become More Sophisticated
The trend toward smart devices will be so pronounced in the coming years that it will become difficult to buy appliances or home electronics that are not connected to the internet.
Research has shown that security is often an afterthought in the manufacturing of these devices. While the big name smart devices often do come with embedded security options, some producers skimp on security either to keep costs low for consumers or because they are not experts in security. Considering a smart home is only as secure as its weakest link, this is a mistake. History tends to repeat itself, so Avast expects to see IoT malware evolve and become more sophisticated and dangerous, simliar to how PC and mobile malware developed.
Router Attacks Will Advance
Routers have proven to be a simple and fertile target for a growing wave of attacks. Moreover, the characteristics of these attacks have also changed.
In 2019, the company predicts an increase in hijacking of routers used to steal banking credentials, for example, where an infected router injects a malicious HTML frame to specific web pages when displaying on mobile. This new element could ask mobile users to install a new banking app, for instance, and this malicious attacks will then capture authentication messages. Routers will continue to be used as targets of an attack, not just to run malicious scripts or spy on users, but also as an intermediate link in chain attacks.
The Evolution of Mobile Threats
In 2019, well known tactics such as advertising, phishing and fake apps will continue to dominate the mobile threat landscape. In 2018, Avast tracked and flagged countless fake apps using its apklab.io platform. Some were even found on the Google Play Store. Fake apps are the zombies in mobile security — becoming so ubiquitous that they barely even make the headlines as new fake apps pop up to take the place of ones already flagged for removal. They will continue to persist as a trend in 2019, exacerbated by fake versions of popular app brands doing their rounds on the Google Play Store.
In 2018, the return of banking Trojans was also particularly pronounced on the mobile side, growing 150 percent year-on-year, from 3 percent to over 7 percent of all detections Avast sees worldwide. While perhaps not a big shift in terms of the overall volume, Avast believes that cybercriminals are finding banking to be a more reliable way to make money than cryptomining.
“This year, we celebrated the 30th anniversary of the World Wide Web. Fast forward 30 years, and the threat landscape is exponentially more complex, and the available attack surface is growing faster than it has at any other point in the history of technology,” said Ondrej Vlcek, president of consumer at Avast.
“PC viruses, while still a global threat, have been joined by a multitude of malware categories that deliver more attacks,” Vlcek continued. “People are acquiring more and varied types of connected devices, meaning every aspect of our lives could be compromised by an attack. Looking ahead to 2019, these trends point to a magnification of threats through these expanding threat surfaces.”
The Avast Threat Labs team sees roughly 1 million new files a day and prevents 2 billion attacks every month. This volume provides insights into the most prevalent threats, as well as the ability to map trends to predict future attacks. The view the full report, click here.