CHKP Check Point Software Technologies Ltd.

June 2020’s Most Wanted Malware: Notorious Phorpiex Botnet Rises Again, Doubling Its Global Impact On Organizations

June 2020’s Most Wanted Malware: Notorious Phorpiex Botnet Rises Again, Doubling Its Global Impact On Organizations

Check Point Research finds sharp increase in attacks using the Phorpiex Botnet delivering new ‘Avaddon’ ransomware via malspam campaigns

SAN CARLOS, Calif., July 10, 2020 (GLOBE NEWSWIRE) -- Check Point Research, the Threat Intelligence arm of (NASDAQ: CHKP), a leading provider of cyber security solutions globally, has published its latest Global Threat Index for June 2020.  Researchers found that in the past month the Phorpiex botnet has been delivering the Avaddon ransomware, a new Ransomware-as-a-Service (RaaS) variant that emerged in early June, via malspam campaigns, causing it to jump up 13 places to 2nd in the Top Malware listing and doubling its impact on organizations worldwide compared to May.

As previously by Check Point researchers, Phorpiex is known for spreading large-scale sextortion malspam campaigns, as well distributing other malware families. The latest malspam messages distributed via Phorpiex try to entice recipients into opening a Zip file attachment by using a wink emoji in the email subject. If a user clicks on the file, the Avaddon ransomware is activated, scrambling data on the computer and demanding a ransom in return for file decryption.  In its 2019 research, Check Point found over a million Phorpiex-infected Windows computers. Researchers estimated the annual criminal revenue generated by Phorpiex botnet at approximately $500,000.

Meanwhile, the Agent Tesla remote access trojan and info-stealer continued to have a significant impact throughout June, moving up from 2nd place in May to 1st place, while the XMRig cryptominer remains in 3rd place for the second month running.

“In the past, Phorpiex, also known as Trik, was monetized by distributing other malware such as GandCrab, Pony or Pushdo, using its hosts to mine cryptocurrency, or for sextortion scams. It’s now being used to spread a new ransomware campaign,” said Maya Horowitz, Director, Threat Intelligence & Research, Products at Check Point. “Organizations should educate employees about how to identify the types of malspam that carry these threats, such as the latest campaign targeting users with emails containing a wink emoji, and ensuring they deploy security that actively prevents them from infecting their networks.”

The research team also warns that “OpenSSL TLS DTLS Heartbeat Information Disclosure” is the most common exploited vulnerability, impacting 45% of organizations globally, closely followed by “MVPower DVR Remote Code Execution” which impacts 44% of organizations worldwide. “Web Server Exposed Git Repository Information Disclosure” remains in third place, with a global impact of 38%.

Top malware families

*The arrows relate to the change in rank compared to the previous month.

This month Agent Tesla is the most popular malware with a global impact of 3% of organizations, closely followed by Phorpiex and XMRig affecting 2% of organizations each.

  1. ↑ Agent Tesla - Agent Tesla is an advanced RAT functioning as a keylogger and information stealer, which is capable of monitoring and collecting the victim's keyboard input, system clipboard, taking screenshots, and exfiltrating credentials belonging to of a variety of software installed on a victim's machine (including Google Chrome, Mozilla Firefox and Microsoft Outlook email client). 



  2. Phorpiex - Phorpiex is a botnet known for distributing other malware families via spam campaigns as well as fueling large-scale Sextortion campaigns.



  3. XMRig - XMRig is open-source CPU mining software used for the mining process of the Monero cryptocurrency, and first seen in the wild on May 2017.

Top exploited vulnerabilities

This month “OpenSSL TLS DTLS Heartbeat Information Disclosure” is the most common exploited vulnerability, affecting 45% of organizations globally, closely followed by “MVPower DVR Remote Code Execution” which impacts 44% of organizations worldwide. “Web Server Exposed Git Repository Information Disclosure” remains in third place, with a global impact of 38%.

  1. ↑OpenSSL TLS DTLS Heartbeat Information Disclosure (CVE-2014-0160; CVE-2014-0346) - An information disclosure vulnerability exists in OpenSSL. The vulnerability is due to an error when handling TLS/DTLS heartbeat packets. An attacker can leverage this vulnerability to disclose memory contents of a connected client or server.



  2. MVPower DVR Remote Code Execution – A remote code execution vulnerability that exists in MVPower DVR devices. A remote attacker can exploit this weakness to execute arbitrary code in the affected router via a crafted request.



  3. Web Server Exposed Git Repository Information Disclosure – An information disclosure vulnerability has been reported in Git Repository. Successful exploitation of this vulnerability could allow an unintentional disclosure of account information.

Top mobile malware families

This month Necro is the most popular malware, following by Hiddad and Lotoor.

  1. Necro - Necro is an Android Trojan Dropper. It is capable of downloading other malware, showing intrusive ads and stealing money by charging paid subscriptions.



  2. Hiddad - Hiddad is an Android malware, which repackages legitimate apps and then releases them to a third-party store. Its main function is to display ads, but it can also gain access to key security details built into the OS.



  3. Lotoor - Lotoor is a hacking tool that exploits vulnerabilities on the Android operating system to gain root privileges on compromised mobile devices.

Check Point’s Global Threat Impact Index and its ThreatCloud Map is powered by Check Point’s ThreatCloud intelligence, the largest collaborative network to fight cybercrime which delivers threat data and attack trends from a global network of threat sensors. The ThreatCloud database inspects over 2.5 billion websites and 500 million files daily, and identifies more than 250 million malware activities every day.

The complete list of the top 10 malware families in June can be found on the .

Check Point’s Threat Prevention Resources are available at 

Follow Check Point Research via:

Blog:

Twitter:

About Check Point Research

Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber-attack data stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcement and various CERTs.

About Check Point Software Technologies Ltd.

Check Point Software Technologies Ltd. () is a leading provider of cyber security solutions to governments and corporate enterprises globally.  Check Point’s solutions protect customers from 5th generation cyber-attacks with an industry leading catch rate of malware, ransomware and advanced targeted threats. Check Point offers a multilevel security architecture, “Infinity Total Protection with Gen V advanced threat prevention”, this combined product architecture defends an enterprises’ cloud, network and mobile devices. Check Point provides the most comprehensive and intuitive one point of control security management system. Check Point protects over 100,000 organizations of all sizes.

MEDIA CONTACT:INVESTOR CONTACT:
Emilie Beneitez LefebvreKip E. Meintzer
Check Point Software TechnologiesCheck Point Software Technologies
 
EN
10/07/2020

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Check Point Software Technologies Ltd.

Check Point Software Technologies Ltd: 3 directors

Three Directors at Check Point Software Technologies Ltd sold 1,314,352 shares at between 218.330USD and 220.000USD. The significance rating of the trade was 100/100. Is that information sufficient for you to make an investment decision? This report gives details of those trades and adds context and analysis to them such that you can judge whether these trading decisions are ones worth following. Included in the report is a detailed share price chart which plots discretionary trades by all the...

Wedbush Research
  • Wedbush Research
DPZ DOMINO'S PIZZA INC.
SHAK SHAKE SHACK INC. CLASS A
DEI DOUGLAS EMMETT INC
HPP HUDSON PACIFIC PROPERTIES INC.
XENE XENON PHARMACEUTICALS INC
WING WINGSTOP INC.
WEN WENDY'S COMPANY
WDC WESTERN DIGITAL CORPORATION
VYGR VOYAGER THERAPEUTICS INC.
TXRH TEXAS ROADHOUSE INC.
TSLA TESLA INC
TRNO TERRENO REALTY CORPORATION
STKS ONE GROUP HOSPITALITY
STAG STAG INDUSTRIAL INC.
SIMON SILICON MOTION TECHNOLOGY CORPORATION SPONSORED ADR
SBUX STARBUCKS CORPORATION
PZZA PAPA JOHN'S INTERNATIONAL INC.
PEGA PEGASYSTEMS INC.
OFC CORPORATE OFFICE PROPERTIES TRUST
MCD MCDONALD'S CORPORATION
JACK JACK IN THE BOX INC.
IMAX IMAX CORPORATION
EGP EASTGROUP PROPERTIES INC.
EAT BRINKER INTERNATIONAL INC.
DIN DINE BRANDS GLOBAL INC.
DENN DENNY'S CORPORATION
CTMX CYTOMX THERAPEUTICS INC.
CHKP CHECK POINT SOFTWARE TECHNOLOGIES LTD.
CAKE CHEESECAKE FACTORY INCORPORATED
BXP BOSTON PROPERTIES INC.
BIIB BIOGEN INC.
ARDX ARDELYX INC
BJRI BJ'S RESTAURANTS INC.
FRX_CN FENNEC PHARMACEUTICALS
CMG CHIPOTLE MEXICAN GRILL INC.
DRI DARDEN RESTAURANTS INC.
WVE WAVE LIFE SCIENCES
PLYM PLYMOUTH INDUSTRIAL REIT INC.
MRSN MERSANA THERAPEUTICS
ISR ISORAY
AMZN AMAZON.COM INC.
AAPL APPLE INC.
RCKT ROCKET PHARMACEUTICALS
MSFT MICROSOFT CORPORATION
IBM INTERNATIONAL BUSINESS MACHINES CORPORATION
APLS APELLIS PHARMACEUTICALS
SRRK SCHOLAR ROCK HOLDING CORPORATION
YMAB Y-MABS THERAPEUTICS
TVTX TRAVERE THERAPEUTICS INC
PLTK PLAYTIKA HOLDING
RBLX ROBLOX
TNGX TANGO THERAPEUTICS
VERA INC
BROS VERA THERAPEUTICS INC
STRW DUTCH BROS INC
CAVA STRAWBERRY FIELDS REIT INC.
JBIO CAVA GROUP INC
JADE BIOSCIENCES
INC.
 PRESS RELEASE

Check Point Software Technologies Receives Common Criteria EAL4+ Certi...

Check Point Software Technologies Receives Common Criteria EAL4+ Certification for Quantum Firewall Software R82 Certification expands global assurance for Check Point’s security platform, supporting trusted deployment in high-assurance environments across more than 30 nations REDWOOD CITY, Calif., May 01, 2025 (GLOBE NEWSWIRE) -- . (NASDAQ: CHKP), a pioneer and global leader of cyber security solutions, today announced that its Quantum Firewall Software R82, the latest version of Check Point’s core network security software delivering advanced threat prevention and scalable policy mana...

 PRESS RELEASE

Check Point Research Launches AI Security Report: Exposing the Rise of...

Check Point Research Launches AI Security Report: Exposing the Rise of AI-Powered Cybercrime and Defenses New report unveils four key AI-driven cyber threats and how organizations can outsmart attackers in an AI-driven world SAN FRANCISCO, April 30, 2025 (GLOBE NEWSWIRE) -- RSA CONFERENCE, – (NASDAQ: CHKP), a pioneer and global leader of cyber security solutions, today launched its inaugural at RSA Conference 2025. This report offers an in-depth exploration of how cyber criminals are weaponizing artificial intelligence (AI), alongside strategic insights for defenders to stay ahead. A...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch