This quarter saw a rise in reports of malware (malicious software) infections. For individuals, malware’s impact can be devastating — they can lose large amounts of money, personal data, and access to their important accounts.

Businesses impacted by malware can face expensive downtime, extra costs for recovering their systems and information, damage to their reputation, and a loss of customer trust.

What is malware?

Malware, or malicious software, is a blanket term for any kind of computer software that has malicious intent to harm your device. Malware can be used in many ways – some examples include:

  • to encrypt your computer so you can’t use it (ransomware),
  • to secretly observe the computer user’s activities without permission (spyware),
  • to attach itself to another program and then replicate itself, infecting other computer programs with its own code (virus).

One type that represents a significant cybercrime trend worldwide is information stealing malware (or ‘infostealers’). These programs silently steal passwords, browser cookies, banking credentials, cryptocurrency-wallet data, and authentication tokens from infected devices to be sold on underground markets or used to launch ransomware attacks.

The motives of malware can vary depending on its type. It can be an attempt to make money off you, sabotage the systems on your device to prevent you from working, make a political statement, or in some instances, simply be an example of gaining bragging rights.

Malware most commonly accesses your device’s system through the internet or email. Anytime you are connected online you are vulnerable to malware. Rather than relying on a single piece of malware, attackers increasingly use malware as one component of a broader fraud operation designed to steal identities, compromise accounts, and monetize access at scale.

Getting creative 

Cyber criminals are becoming increasingly creative in their attempts to trick internet users into exposing themselves to malware. The following are just a handful of recent malware incidents where New Zealanders were tricked into granting access to malware.

‘Free’ tai chi and social dancing classes

Fraudulent Facebook groups advertise free local activities such as tai chi or social dancing were revealed to be a sophisticated scam. The Facebook groups encourage those interested to download an app in order to book a place in a free class. What the users don’t realise was that these apps contained hidden malware allowing scammers to access people’s bank accounts and other personal information.

Fake job ads 

Scammers use fake job opportunities advertised on social media to trick people into downloading malware to their devices. After showing interest in a job on social media platforms such as Facebook, job seekers are often asked to continue the conversation on messaging apps like WhatsApp or Telegram. As part of the ‘application process’ the job seeker is then sent a link to download another app. Once installed this app may appear to freeze or display a system update. While this is happening, scammers gain access to the device to collect sensitive information.

Fake tech support 

Scammers will make contact, pretending to be from well-known tech companies (such as Microsoft, Chorus, Spark, or Google) in an attempt to convince victims that there is an issue with their device or internet connection and they can fix it. Using these scare tactics, they will then redirect their target to a fake website or ask for device/personal information that will allow them to install malware on their device that acquires bank and credit card details, and other sensitive information.  

Fake friends on Discord

On Discord, an online social media app popular amongst the video game community, scammers are installing infostealer malware by posing as a user’s friend and asking them to play a game with them or suggesting they check out a video game mod. When the user accepts, infostealer malware is installed on their device, stealing their personal information such as logins to email and other services.

Protect yourself

There are multiple ways to ensure that your device and information are kept protected from malware. By following the below tips, you can help to lower your level of risk.

  • Strong passwords – Use long, strong, and unique passwords along with two-factor authentication (2FA). Using a password manager in combination with 2FA can be a big help. 
  • Avoid pop-up ads – Don’t click on any ads that pop-up while you are browsing the internet.
  • Be vigilant with emails – Avoid opening any email attachments or clicking on any links in emails from unknown senders.
  • Be wary of strange links – Avoid clicking on any links in emails, texts and social media messages that look strange, incorrect, or are from someone you don’t know.
  • Downloads – Never download software from untrustworthy websites, or peer-to-peer file transfer networks.
  • Keep patches up-to-date – Make sure your operating system, browsers, and apps are patched and up-to-date.
  • Watch for strange behaviour – Odd system activity such as computer fans spinning too hard for no reason, network slowdowns, or unknown pop-ups can be warning signs of malware infection.
  • Back up your data – By regularly backing up your data you ensure that you are covered should your files become damaged, encrypted, or otherwise inaccessible.

Report It

If you are the victim or target of a malware infection, be sure to report it using the reporting form on the NCSC website.

Reporting an incident can help not only you, but others as well.

For further information and guidance on how to protect your organisation from cyber threats, visit the Protect your organisation section of the NCSC website. 

SEE ALL QUARTERLY REPORTS
Top