Log in
Log in
Or log in with
GoogleGoogle
Twitter Twitter
Facebook Facebook
Apple Apple     
Sign up
Or log in with
GoogleGoogle
Twitter Twitter
Facebook Facebook
Apple Apple     

CHECK POINT SOFTWARE TECHNOLOGIES LTD.

(CHKP)
  Report
Delayed Nasdaq  -  01:00 2022-11-25 pm EST
132.41 USD   +0.71%
11/25Check Point Software Launches Cyberup : Israel's Premier Accelerator Hub for Cybersecurity Start-ups
AQ
11/23Check Point Software Launches CyberUp Program to Bolster Startups
MT
11/23Check Point Software Launches Cyberup : Israel's Premier Accelerator Hub for Cybersecurity Start-ups
AQ
SummaryQuotesChartsNewsRatingsCalendarCompanyFinancialsConsensusRevisionsFunds 
SummaryMost relevantAll NewsAnalyst Reco.Other languagesPress ReleasesOfficial PublicationsSector news

August's Top Malware: Emotet Knocked off Top Spot by FormBook while GuLoader and Joker Disrupt the Index

09/14/2022 | 06:01am EST

SAN CARLOS, Calif., Sept. 14, 2022 (GLOBE NEWSWIRE) -- Check Point Research (CPR), the Threat Intelligence arm of Check Point® Software Technologies Ltd. (NASDAQ: CHKP), a leading provider of cyber security solutions globally, has published its latest Global Threat Index for August 2022. CPR reports that FormBook is now the most prevalent malware, taking over from Emotet, which has held that position since its reappearance in January.

FormBook is an Infostealer targeting Windows OS which, once deployed, can harvest credentials, collect screenshots, monitor and log keystrokes as well as download and execute files according to its command and control (C&C) orders. Since it was first spotted in 2016, it has continued to make a name for itself, marketed as a Malware as a Service (MaaS) in underground hacking forums, known for its strong evasion techniques and relatively low price.

August also saw a rapid increase in GuLoader activity, which resulted in it being the fourth most widespread malware. GuLoader was initially used to download Parallax RAT but has since been applied to other remote access trojans and infostealers such as Netwire, FormBook and Agent Tesla. It is commonly distributed through extensive email phishing campaigns, that lure the victim into downloading and opening a malicious file, allowing the malware to get to work.

Additionally, Check Point Research reports that Joker, an Android spyware, is back in business and has claimed third place in the top mobile malware list this month. Once Joker is installed, it can steal SMS messages, contact lists and device information as well as sign the victim up for paid premium services without their consent. Its rise can partially be explained by an uplift in campaigns as it was recently spotted to be active in some Google Play Store applications.

“The shifts that we see in this month’s index, from Emotet dropping from first to fifth place to Joker becoming the third most prevalent mobile malware, is reflective of how fast the threat landscape can change,” said Maya Horowitz, VP Research at Check Point Software. “This should be a reminder to individuals and companies alike, of the importance of keeping up to date with the most recent threats as knowing how to protect yourself is essential. Threat actors are constantly evolving and the emergence of FormBook shows that we can never be complacent about security and must adopt a holistic, prevent-first approach across networks, endpoints and the cloud.”

CPR also revealed this month that the Education/Research sector is still the most targeted industry by cybercriminals globally. With Government/Military and Healthcare taking second and third place as the most attacked sectors. “Apache Log4j Remote Code Execution” returns to first place as the most exploited vulnerability, impacting 44% of organizations worldwide, after overtaking “Web Server Exposed Git Repository Information Disclosure” which had an impact of 42%.

Top malware families

*The arrows relate to the change in rank compared to the previous month.

FormBook is the most widespread malware this month impacting 5% of organizations worldwide, followed by AgentTesla with an impact of 4% and XMRig with 2%.

  1. ↑ FormBook – FormBook is an Infostealer targeting Windows OS and was first detected in 2016. It is marketed as a Malware as a Service (MaaS) in underground hacking forums for its strong evasion techniques and relatively low price. FormBook harvests credentials from various web browsers, collects screenshots, monitors and logs keystrokes and can download and execute files according to orders from its C&C.
  2. AgentTesla - AgentTesla is an advanced RAT functioning as a keylogger and information stealer, which is capable of monitoring and collecting the victim’s keyboard input, system keyboard, taking screenshots and exfiltrating credentials to a variety of software installed on a victim’s machine (including Google Chrome, Mozilla Firefox and the Microsoft Outlook email client).
  3. XMRig – XMRig is open-source CPU software used to mine Monero cryptocurrency. Threat actors often abuse this open-source software by integrating it into their malware to conduct illegal mining on victim’s devices.

Top Attacked Industries Globally 

This month the Education/Research sector remained in first place as the most attacked industry globally, followed by Government/Military and Healthcare.

  1. Education/Research
  2. Government/Military
  3. Healthcare

Top Exploited Vulnerabilities 

This month, “Apache Log4j Remote Code Execution” is the most common exploited vulnerability, impacting 44% of organizations globally, followed by “Web Server Exposed Git Repository Information Disclosure” which dropped from first place to second with an impact of 42%. “Web Servers Malicious URL Directory Traversal” remains in the third place, with a global impact of 39%.

  1. Apache Log4j Remote Code Execution (CVE-2021-44228) - A remote code execution vulnerability exists in Apache Log4j. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.
  2. Web Server Exposed Git Repository Information Disclosure - An information disclosure vulnerability has been reported in Git Repository. Successful exploitation of this vulnerability could allow unintentional disclosure of account information.
  3. ↔ Web Servers Malicious URL Directory Traversal (CVE-2010-4598,CVE-2011-2474,CVE-2014-0130,CVE-2014-0780,CVE-2015-0666,CVE-2015-4068,CVE-2015-7254,CVE-2016-4523,CVE-2016-8530,CVE-2017-11512,CVE-2018-3948,CVE-2018-3949,CVE-2019-18952,CVE-2020-5410,CVE-2020-8260) - There exists a directory traversal vulnerability on different web servers. The vulnerability is due to an input validation error in a web server that does not properly sanitize the URI for the directory traversal patterns. Successful exploitation allows unauthenticated remote attackers to disclose or access arbitrary files on the vulnerable server.

Top Mobile Malwares 

This month AlienBot is the most prevalent Mobile malware, followed by Anubis and Joker.

  1. AlienBot – AlienBot is a banking Trojan for Android, sold underground as a Malware-as-a-Service (MaaS). It supports keylogging, dynamic overlays for credentials theft, as well as SMS harvesting for 2FA bypass. Additional remote control capabilities are provided by using a TeamViewer module.
  2. Anubis – Anubis is a banking Trojan malware designed for Android mobile phones. Since it was initially detected, it has gained additional functions including Remote Access Trojan (RAT) functionality, keylogger and audio recording capabilities as well as various ransomware features. It has been detected on hundreds of different applications available in the Google Store.
  3. Joker - An Android Spyware in Google Play, designed to steal SMS messages, contact lists and device information. Furthermore, the malware can also sign the victim up for paid premium services without their consent or knowledge.

Check Point’s Global Threat Impact Index and its ThreatCloud Map is powered by Check Point’s ThreatCloud intelligence. ThreatCloud provides real-time threat intelligence derived from hundreds of millions of sensors worldwide, over networks, endpoints and mobiles. The intelligence is enriched with AI-based engines and exclusive research data from Check Point Research, The Intelligence & Research Arm of Check Point Software Technologies.

The complete list of the top ten malware families in July can be found on the Check Point blog.

Follow Check Point Research via: 
Blog: https://research.checkpoint.com/
Twitter: https://twitter.com/_cpresearch_

About Check Point Research
Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber-attack data stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcement and various CERTs.

About Check Point Software Technologies Ltd. 
Check Point Software Technologies Ltd. (www.checkpoint.com) is a leading provider of cyber security solutions to corporate enterprises and governments globally. Check Point Infinity´s portfolio of solutions protects enterprises and public organizations from 5th generation cyber-attacks with an industry leading catch rate of malware, ransomware and other threats. Infinity comprises three core pillars delivering uncompromised security and generation V threat prevention across enterprise environments: Check Point Harmony, for remote users; Check Point CloudGuard, to automatically secure clouds; and Check Point Quantum, to protect network perimeters and datacenters, all controlled by the industry’s most comprehensive, intuitive unified security management. Check Point protects over 100,000 organizations of all sizes.

MEDIA CONTACT:INVESTOR CONTACT: 
Emilie Beneitez LefebvreKip E. Meintzer
Check Point Software TechnologiesCheck Point Software Technologies
press@us.checkpoint.comir@us.checkpoint.com

Primary Logo

Source: Check Point Software Technologies INC

2022 GlobeNewswire, Inc., source Press Releases

All news about CHECK POINT SOFTWARE TECHNOLOGIES LTD.
11/25Check Point Software Launches Cyberu : Israel's Premier Accelerator Hub for Cybersecurity ..
AQ
11/23Check Point Software Launches CyberUp Program to Bolster Startups
MT
11/23Check Point Software Launches Cyberu : Israel's Premier Accelerator Hub for Cybersecurity ..
AQ
11/17Check Point Software Technologies : is Now Available on the Software Licensing Program wit..
PU
11/11Check Point Software's Cybersecurity : Expect More Global Attacks, Government Regulation, ..
AQ
11/10Check Point Software's Cybersecurity : Expect More Global Attacks, Government Regulation, ..
AQ
11/08October 2022's Most Wanted Malware : AgentTesla Knocks Formbook off Top Spot and New Text4..
AQ
11/02Macquarie Initiates Check Point Software Technologies at Neutral With $129 Price Target
MT
11/01Network Perception and Check Point Software Technologies Ltd. Partner to Tighten the Se..
CI
10/28Morgan Stanley Adjusts Price Target on Check Point Software Technologies to $125 From $..
MT
More news
Analyst Recommendations on CHECK POINT SOFTWARE TECHNOLOGIES LTD.
More recommendations
Financials (USD)
Sales 2022 2 327 M - -
Net income 2022 779 M - -
Net cash 2022 3 609 M - -
P/E ratio 2022 21,6x
Yield 2022 -
Capitalization 16 606 M 16 606 M -
EV / Sales 2022 5,58x
EV / Sales 2023 5,07x
Nbr of Employees 5 642
Free-Float 38,5%
Chart CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Duration : Period :
Check Point Software Technologies Ltd. Technical Analysis Chart | MarketScreener
Full-screen chart
Technical analysis trends CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Short TermMid-TermLong Term
TrendsBullishBullishNeutral
Income Statement Evolution
Consensus
Sell
Buy
Mean consensus HOLD
Number of Analysts 30
Last Close Price 132,41 $
Average target price 137,23 $
Spread / Average Target 3,64%
EPS Revisions
Managers and Directors
Gil Shwed Chief Executive Officer & Director
Tal Payne Chief Financial Officer
Jerry T. Ungerman Chairman
Sharon Schusheim Chief Information Officer & VP-Information System
Yoav Z. Chelouche Independent Director
Sector and Competitors
1st jan.Capi. (M$)
CHECK POINT SOFTWARE TECHNOLOGIES LTD.12.80%16 606
SANGFOR TECHNOLOGIES INC.-42.10%6 391
KNOWBE4, INC.7.72%4 360
DARKTRACE PLC-11.28%2 956
BLACKBERRY LIMITED-45.60%2 785
HANGZHOU DPTECH TECHNOLOGIES CO.,LTD.-46.84%1 299