Habr•September 18, 2026•🇷🇺Translated from Russian

Network Traffic Analysis Reveals 75% Malware Threats Over 10 Months of Monitoring

Positive Technologies examined anonymized network traffic data collected over ten months to identify the most prevalent cyber threats. The analysis combined public incident reports, internal expertise, and results from PT Sandbox and PT Network Attack Discovery, covering the period from October 2025 to July 2026.

Malware Dominates Detected Threats

Malicious software represented 75% of all threats observed in network traffic. This category remains the primary attack method used against organizations regardless of industry. Within the malware samples, 50% were generic trojans, while 24% were information-stealing trojans. Of the spyware samples, 85% targeted credential theft and 15% focused on user activity monitoring.

Loaders and droppers accounted for 15% of malware detections, with 78% of that subset functioning as downloaders. Remote access trojans (RATs) made up 7%, including Remcos RAT and Async RAT. Ransomware comprised approximately 4% of samples, while worms were detected in only 2% of cases.

Potentially Unwanted Tools and Living-off-the-Land Binaries

Potentially unwanted tools represented 8% of detections. The most frequently observed utilities included PsExec, ProcDump, Mimikatz, and components from the NirSoft suite. These tools allow attackers to perform reconnaissance, credential dumping, and lateral movement while blending with legitimate administrative activity.

PowerShell-based frameworks such as PowerSploit and remote monitoring tools like UltraVNC were also identified. Network scanners such as Advanced IP Scanner appeared in reconnaissance phases.

Legacy Vulnerabilities and Delivery Methods

More than 96% of detected CVEs were at least three years old. Attackers continued to exploit CVE-2017-0199 and CVE-2017-11882 in Microsoft Office documents. Executable files accounted for 29% of detections, while Microsoft Office documents represented 26%.

Sector Distribution and Threat Actor Activity

The highest number of detections occurred in the financial sector (25%), followed by manufacturing (24%) and IT (24%). Signs of activity from known groups such as MustangPanda, TA505, and APT37 were recorded in the monitored traffic.

Related articles

Securitylab•Malware & Botnets

How Malware Evades Sandboxes: Detection Techniques and Defense Strategies

Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.

BoletimSec•Malware & Botnets

Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers

Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.

BoletimSec•Malware & Botnets

Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware

Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.

AntiMalware•Malware & Botnets

SC Malware on WordPress Restores Deleted Backdoors in Seconds via Eight Persistence Points

Researchers at Sucuri have analyzed the SC malware targeting WordPress sites, which rapidly restores any removed backdoor components through a minimum of eight interconnected persistence mechanisms. The infection hides across PHP configuration settings, hidden loaders, theme files, and plugins, with some elements executing before standard WordPress plugins load. Copies of the malicious code are also stored in the database and System V shared memory on supported servers, allowing full reinfection from surviving sources after file cleanup. The backdoor evades plugin listings, gathers site and administrator session data, deploys additional PHP code, and disables security plugins while injecting JavaScript for payment data theft in online stores. Command-and-control occurs through public Ethereum RPC gateways and smart contracts with multiple fallback channels. Sucuri warns that PHP caching of the loader directive can crash request handling if the referenced file is deleted without prior preparation, and recommends a sequenced cleanup process.