Education Top Sector Hit by Trojans

digital trojan horse

The openness of education networks poses the sector's greatest cybersecurity threat, according to a company that produces anti-malware software. According to a new analysis of its customer data, Malwarebytes has found that the education sector was the largest target for adware and trojans, and second among verticals for being hit with ransomware. Forty-three percent of threats on education devices were identified as adware, 25 percent as trojans and 3 percent as backdoors.

The analysis was done between January and June 2019 on devices identified as being in education settings around the world and running Malwarebytes' on-premise programs and cloud services. While the focus was on findings for the first half of 2019, the company also examined data collected in 2018 to understand the threat landscape of the 2018-2019 school year.

In the area of adware, the most common adware families detected were SearchEncrypt, Spigot and IronCore. Together these comprised about 15 percent of the threats detected. The company considered the first two of those "relatively minor compromises."

The bigger concern was trojans. And according to the analysis, more than one in three compromises were detected on devices plugging in as a guest on the network. Trojans across all industries were on the rise last year, up 132 percent from the previous year. In education specifically, trojans represented nearly 30 percent of all detections in devices owned by schools. Also, the company reported, 33 percent of non-institution-owned devices carried trojans; in the United States specifically the share was 27 percent.

The most common trojans detected were Emotet, TrickBot and Trace, making up more than 11 percent of all compromises.

Emotet appeared to be even more pervasive among non-institution-owned devices (14 percent) than those owned by the institution (5 percent).

TrickBot for its part uses EternalBlue, one of the SMB vulnerabilities leaked by the ShadowBrokers Group last year, to exploit unpatched systems. Infected machines attempt to spread TrickBot laterally via brute force of domain credentials." TrickBot, which represented almost 6 percent of all identified compromises in education, was described by Malwarebytes as a "nasty information stealer that can download components for specific malicious operations, such as keylogging and lateral movement within a network."

The company warned that these two trojans "may be even more pervasive than the metrics indicate." If its own technology didn't stop certain activities in their tracks, the counts could be doubled. Those include flagging malicious PDF or Office documents containing hidden scripts that have been opened or a manual script such as PowerShell that has been activated. "If these detections were, indeed, the result of further attempts at spreading Emotet or TrickBot, then Trojan detections may actually represent up to 40 percent of all detections in the industry," the company noted.

"Because of their network-hopping use of brute force attacks and use of exploits, education is particularly vulnerable to these particular attacks, due to the huge volume of guest devices connecting to their networks," the company concluded.

For more detail, visit the Malwarebyte blog.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • circuit patterns

    Anthropic Intros Lower-Cost Claude Sonnet 5

    Anthropic has launched Claude Sonnet 5, positioning the model as its most autonomous mid-tier offering to date and a lower-cost alternative to its flagship Opus 4.8 system. The company said the model can plan multi-step tasks, operate tools such as browsers and terminals, and complete agentic work at a level that previously required larger and more expensive models.

  • Abstract Network of Blue and Orange Lines

    Tech Industry Leaders Launch Alliance for AI Agent Security

    NVIDIA and 36 other industry partners are targeting agent security across multi-vendor clouds by combining open technologies for workload identity, agent controls, vulnerability scanning, and software supply-chain security.

  • digital brain integrating legal regulation and security interface

    Survey: Agentic AI Moves from Pilot Phase to Production, Bringing Governance to the Forefront

    A new report from Caylent, an AI-focused Amazon Web Services Premier Tier Services Partner, found that enterprises are already moving agentic AI beyond pilots and into production environments. At the same time, organizations are putting strict conditions around autonomy, making governance and control the next major challenge for enterprise AI adoption.

  • Abstract background with digital shield made of data particles glowing blue blocking against cyber attacks

    AI Attacks Push Organizations Toward Autonomous Cybersecurity Defense

    Artificial intelligence is raising the stakes of cyber conflict as attackers use the technology to accelerate reconnaissance, uncover vulnerabilities, and launch attacks faster than many security teams can respond, according to a new report from agentic AI security company Kai.