Posted in

Cybersecurity in the Year of the RAT

According to the Chinese zodiac, 2020 is the year of the rat. The first of the astrological animals, the cycle of 12 has begun again, and similarly, this year is associated with the opportunity for new beginnings. However, from a technological perspective, it seems that 2020 is also the year of the RAT (Remote Access Trojan), an opportunity for cybercriminals to visit chaos upon our lives all over again.

This year is likely to see a deeper integration of technology into more aspects of our lives. Between objects in the Internet of Things becoming more affordable to 5G networks beginning to establish a presence in our communities, there are certainly interesting areas to explore. But this also means that there is greater scope for unscrupulous actors to introduce malware, ransomware, and other attacks to our systems.

So what can we expect from cybersecurity in 2020? What are the potential areas of vulnerability, and how can we best address them? In a year that is intended to be one of new beginnings, how can we avoid falling at the first hurdle?

The Threats

Let’s cut to the chase ” what are the primary cybersecurity threats we’re facing this year? Well, the aforementioned RAT is a good place to start. These caused huge problems in 2019 and are set to continue their rise. In the simplest terms, these are malware programs that, when introduced to a system, provide the user with backdoor administrative access. There’s usually a clear financial motivation to cybercriminals using RATs, and methods to get this malware into the system last year include phishing lures such as job offers and tax-centric email campaigns.

Alongside RATs and other spyware, ransomware is expected to continue asserting dominance across our digital spaces. It is one of the most prevalent methods today, designed to remove access to systems until a ransom is paid. It’s a serious issue and has caused major disruption not just to individual companies, but to major cities. This must be an area of focus for companies and could benefit from breach attack simulations to assess the risk.

Methods of infection aren’t the only areas of concern. Device hijacking is a real risk this year, as our planet is predicted to be inhabited by upwards of 20.4 billion connected devices in the cognizant Internet of Things (IoT). We have embraced this technology in businesses, governments, and in our homes. Unfortunately, many IoT manufacturers fail to include security at the outset of their development, leaving weak spots that can be exploited. The potential for cybercriminals to gain access to devices that can record video and audio in sensitive environments, financial transactions, and personal data remains a very real issue this year.

The Targets

While cybersecurity risks are all around us, it’s relatively safe to say that cybercriminals aren’t targeting all of the people, all of the time. There are some pretty clear trends, weak spots that are identified by illicit actors, and exploited ” and these actors are constantly searching for these vulnerable points. When understanding who are the likely targets for cybercriminals, it can be useful to try and imagine how they think.

This year, healthcare is likely to remain a primary target. The medical industry is riddled with areas of vulnerability ” from a lack of cybersecurity training for staff to the trend for clinics to encourage workers to use their own devices for professional purposes. It is also one of the major targets for ransomware attacks, due to the likelihood of ransoms being paid swiftly in order for administrators to regain control of life-saving systems and data. There are certainly solutions available, with blockchain being posited as an option ideally suited to the safe distribution of large amounts of sensitive data ” medical and financial ” being handled. One of the huge positives of this method is that medical information and personal information are carried in separate chains, so in the unlikely event there’s a breach in a single chain, the damage is relatively limited.

This year is also a big political year, with the U.S. general election campaigns already ramping up. We can, therefore, expect political candidates, supporters, and voting systems being targets of cybercriminals. The automotive industry, too, could face threats, with development on autonomous vehicles continuing, and the rollout of 5G networks intended to support the minimal latency infrastructure needed.

The Strategies

Being aware of the threats and targets is useful, but it is essential to have a plan of action in order to protect ourselves against RATs and other prevalent 2020 cyberthreats. So, let’s look at the practical steps both businesses and individuals can take.

Many malware and ransomware attacks are made possible by staff behavior ” clicking on bad links, choosing weak passwords, visiting dangerous sites. Provide staff members with visual examples of the tactics cybercriminals use to dupe them. Show them how RATs and malware are often introduced via phishing emails, and that ransomware can be spread via email attachments. Reinforce protocols that only IT staff should be undertaking software downloads and updates.

The risks of cybercrime are constantly changing, with new versions of familiar tactics being introduced frequently. If you’re able to hire a cybersecurity team it is in your best interest to aim for diversity in the department. As in most other areas, this encourages a greater range of ideas, agility in remaining aware of the new risks, and adds strength by balancing various areas of expertise.

User experience, or UX, has become a major focus for a lot of businesses. Creating a unique design for a website or app is not just essential to avoid lawsuits or provide customers with an on-brand, tailored experience ” it has a place in a cybersecurity strategy, too. Applications can be tempting to cybercriminals as potential gateways to gain access to valuable data. By optimizing UX in company applications, you can help ensure that users are behaving in a secure manner, and guiding them through activities that prevent breaches.

Conclusion

The year of the rat is set to exemplify the idea of starting again. The year will also see many cybercriminals start their year afresh with new takes on familiar hacking strategies. By keeping wary of potential target areas, and developing smart strategies, we can help make certain that 2020 takes us on a positive path. 

Dan Matthews is a writer and content consultant from Boise, ID with a passion for tech, innovation, and thinking differently about the world. You can find him on Twitter and LinkedIn. 

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.