ESET Highlights Top Malware Types of 2020 on Antimalware Day
What Happened – On 3 Nov 2020 ESET published a recap of the most prevalent malware families seen in 2020 as part of its third Antimalware Day campaign. The release spotlights five threat categories – cryptomining torrents, hidden‑app Android malware, IoT botnets, trojanized macOS applications, and malicious email attachments exploiting Microsoft Office.
Why It Matters for Trust & Control Assurance
- Continuous threat‑intelligence feeds are a core input for a control‑assurance program; they enable organizations to map emerging malware tactics to existing security controls and prove coverage during audits.
- Demonstrating that anti‑malware controls are regularly updated against the latest threat landscape satisfies a control objective common to SOC 2, ISO 27001, NIST CSF and others – “maintain effective protection against malicious software.”
- Verisq’s Control Mapping capability can ingest this intel, auto‑correlate it with your control inventory, and generate defensible evidence for auditors.
Who Is Affected – Consumers, small‑to‑medium businesses, and enterprise IT environments across all sectors that rely on endpoint, mobile, or IoT devices.
Recommended Actions
- Verify that endpoint detection and response (EDR) solutions are configured to detect the five highlighted malware families.
- Incorporate the 2020 threat trends into your risk register and update the corresponding control mappings.
- Capture evidence of anti‑malware policy enforcement (e.g., logging, alerting, remediation) for audit readiness.
Technical Notes –
- Malicious torrents – KryptoCibule cryptominer, clipboard hijacking, crypto‑wallet theft.
- Android hidden‑app – Deceptive apps that hide icons, serve full‑screen ads, and exfiltrate data.
- IoT botnets – Insecure devices recruited into large‑scale DDoS networks.
- Mac trojan – Modified Kattana trading app stealing cookies, wallets, screenshots.
- Malicious email – Office‑based exploits delivering payloads via phishing attachments.