Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Tackling the malware machines

by The Gurus
November 28, 2014
in This Week's Gurus
Share on FacebookShare on Twitter

Take any movie where robots rise up against their human makers, and you’ll see fear and panic set in.
 
This happens in films such as The Terminator (1984), Screamers (1995), and I, Robot (2004). Why? Because robots operate on autopilot and are not constrained by human limitations: the need for food, water, or sleep. Similar can be said for certain types of malware.
 
Malware is neither exclusively driven by machines nor humans. From studying different types of malware we see both types are in action within the UK, penetrating networks and disrupting day-to-day business. Learning how malware operates is critical to deciding how best to combat.
 
Does malware sleep?
One of the most significant points to the rise of ‘malware machines’ is its activity at night. By looking at Skyhigh data, which is based on more than 13 million users, we discovered that malware activity occurred consistently regardless of time of day, and was actually 118 per cent more active at night when employees are sleeping.
 
The data, which was normalised across time zones, shows that 2,157 malware incidents occurred during non-working hours (8pm – 8am), as opposed to 987 malware incidents during working hours (8am – 8pm).
 
This underlines the need for security teams to be able to continuously monitor behaviour, regardless of when it happens. Just because we’re not at our desks doesn’t mean that the malware isn’t actively trying to penetrate the network. Failing to have continuous monitoring tools in place could leave malware undetected on the network for enough time to deepen its penetration into company systems. It’s critical that these sorts of attacks are identified and stopped early enough to protect corporate data as much as possible.
 
How can security teams combat tireless attackers? Activity monitoring pits machine against machine by relying on automated software to crunch big data. Effective monitoring analyses cloud traffic to identify abnormal behaviour.
 
Machine-learning algorithms establish a baseline for normal usage of each cloud service; factors for this benchmark include geographic location, number of uploads, size of uploads, and even the number of pages visited within a session on the cloud service.
 
These high-risk anomalies could be indicative of automated malware, as in the case of an infected Twitter account sending out 100,000 tweets in one day or a human attacker, such as an abnormally large download from an enterprise cloud service.
 
Hacking as a full-time job
Having continuous monitoring also allows security teams to better understand human-led malware activity. As FireEye’s recent findings confirmed, hackers in China had mobilised as part of the People’s Liberation Army Unit 61398 and were actively targeting US-based companies. The members of this highly-specialised operations unit stood out because, based on Dynamic DNS data captured by FireEye, they were highly consistent. They worked approximately from 8am to 5pm – highly typical of a person’s normal workday. Furthermore, 98 per cent of the connections occurred Monday through Friday. Even hackers get the weekend off!
 
Though they were not mindless drones working around th
e clock, these hackers acted as a highly organised force. According to FireEye, the team consisted of specialised workers who had assigned roles to play, from coders working on intrusion to sniffers collecting data once the target was breached.
 
These operations were more thought-out and tightly orchestrated than the activities of an amateur hacker poking around; they show an alarming amount of efficiency and focus. Monitoring allows an organisation to identify the characteristic of the threat – which, as in this case, may be far more persistent and adaptable than that from a malware machine – and build an effective response.
 
The importance of continuous monitoring
These observations – both of non-human and human hacking – show that malicious activity has become more sophisticated. The line between bot and human becomes blurred as both parties show a machine-like dedication to infiltrating their target companies.
 
Working to avoid detection while compromising as many systems as they can, these hackers literally treat intrusion as a full-time job. Except in this case, their salaries are made from the backs of the companies who are the unknowing victims. These findings illustrate the necessity of real-time alerts and close monitoring, because the frequency and timing of the attack may not be so intuitive.
 
 
Chau Mai, senior marketing manager at Skyhigh Networks

ShareTweet
Previous Post

Law enforcement, airlines and credit card companies swoop on 118 fraudsters

Next Post

Sony Pictures attack saw 894MB of data taken and staff locked out for 3 weeks

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol