HomeIntelligenceBrief
BREACH BRIEF⚪ Informational ThreatIntel

ESET Highlights Top Malware Types of 2020 on Antimalware Day

ESET released a 2020 malware‑trend summary covering cryptomining torrents, hidden‑app Android threats, IoT botnets, trojanized macOS apps, and malicious email exploits. The briefing underscores the need for continuous anti‑malware control monitoring to satisfy audit‑ready evidence requirements.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 eset.com
Severity
Informational
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
eset.com

ESET Highlights Top Malware Types of 2020 on Antimalware Day

What Happened – On 3 Nov 2020 ESET published a recap of the most prevalent malware families seen in 2020 as part of its third Antimalware Day campaign. The release spotlights five threat categories – cryptomining torrents, hidden‑app Android malware, IoT botnets, trojanized macOS applications, and malicious email attachments exploiting Microsoft Office.

Why It Matters for Trust & Control Assurance

  • Continuous threat‑intelligence feeds are a core input for a control‑assurance program; they enable organizations to map emerging malware tactics to existing security controls and prove coverage during audits.
  • Demonstrating that anti‑malware controls are regularly updated against the latest threat landscape satisfies a control objective common to SOC 2, ISO 27001, NIST CSF and others – “maintain effective protection against malicious software.”
  • Verisq’s Control Mapping capability can ingest this intel, auto‑correlate it with your control inventory, and generate defensible evidence for auditors.

Who Is Affected – Consumers, small‑to‑medium businesses, and enterprise IT environments across all sectors that rely on endpoint, mobile, or IoT devices.

Recommended Actions

  • Verify that endpoint detection and response (EDR) solutions are configured to detect the five highlighted malware families.
  • Incorporate the 2020 threat trends into your risk register and update the corresponding control mappings.
  • Capture evidence of anti‑malware policy enforcement (e.g., logging, alerting, remediation) for audit readiness.

Technical Notes

  • Malicious torrents – KryptoCibule cryptominer, clipboard hijacking, crypto‑wallet theft.
  • Android hidden‑app – Deceptive apps that hide icons, serve full‑screen ads, and exfiltrate data.
  • IoT botnets – Insecure devices recruited into large‑scale DDoS networks.
  • Mac trojan – Modified Kattana trading app stealing cookies, wallets, screenshots.
  • Malicious email – Office‑based exploits delivering payloads via phishing attachments.

Source: ESET Antimalware Day 2020 press release

📰 Original Source
https://www.eset.com/int/about/newsroom/press-releases/announcements/eset-celebrates-antimalware-day-2020-1/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →