Netskope report highlights tech threats for retail sector

By: Retail4Growth Bureau

Last updated : April 05, 2024 12:18 pm



The Netskope Threat Labs report, which focused on cloud threats in the retail sector, finds that IoT botnets, remote access tools and infostealers were the key malware families deployed by attackers targeting retail in the past year.


Netskope Threat Labs, from Netskope - a global SASE player  that helps organisations apply zero trust principles and AI/ML innovations to protect data and defend against cyber threats, has published its latest research report focused on cloud threats in the retail sector. The report finds that IoT botnets, remote access tools and infostealers were the key malware families deployed by attackers targeting retail in the past year. It says Retail has also undergone a shift over the past year from predominantly Google Cloud-based applications towards Microsoft apps like Outlook. 

Key findings include: 

○      Infostealers also feed into the wider cybercrime ecosystem with attackers selling harvested credentials and personal financial details.

○      IoT devices are often overlooked as a security risk, but can be effective in providing visual or sensor information that can assist in cybercrime, or even abused to launch DDoS attacks against other targets. 

○      Similarly, remote access trojans (RAT) were popular as they allow access to browsers and remote cameras, sending information to attackers or receiving commands. 

○      Since the leak of Mirai malware’s source code, the number of variants of this malware has increased considerably and poses a risk to retail as a sector with multiple vulnerable endpoints. 

○      Microsoft Suite increasingly a target: In last year’s report, Google applications were far more popular in the retail sector than in other industries, but over the past year the researchers have seen a resurgence of Microsoft’s popularity. This is particularly evident for storage with the gap between OneDrive and Google Drive widening over the past year, with the average percentage of users shifting from 43% to 51% for OneDrive and falling from 34% to 23% for Google Drive. The report says Microsoft OneDrive remains the most popular cloud application for malware delivery across all sectors including retail. 

○      In retail, attacks via Outlook are more successful than in other sectors - retail sees twice as many malware downloads via Outlook (10%) as other industry averages (5%). 

○      Social media applications like X (12%), Facebook (10%) and Instagram (1.5% for uploads) were all more popular in retail than other industry averages. 

Speaking on the findings, Paolo Passeri, Cyber Intelligence Principal at Netskope said;  

“It’s surprising that the retail sector still finds itself specifically targeted with botnets like Mirai as attackers look to compromise vulnerable or misconfigured IoT devices across retail locations and abuse them to dramatically amplify the effect of a Distributed Denial of Service (DDoS) attack. Mirai is not a particularly recent threat, and since its discovery in 2016, there are now multiple variants used today. The fact that attackers continue to use it to target IoT devices shows that too many organisations continue to dangerously overlook the security posture of their internet-connected devices. This poses a significant risk not only for the targets of the attacks launched from the IoT botnet but also for the organisation whose IoT devices are enslaved into the botnet, since their exploitation can easily lead to outages that impact the functioning of the business. 

“The fact that botnets like Mirai and infostealers like Quakbot continue to be among the top methods attackers use to target retail organisations shows security leaders still have much to do to fortify their infrastructure and endpoints. Fortunately, following fundamental cyber hygiene best practices like inspecting web and cloud traffic and ensuring you can block malicious traffic and isolate compromised endpoints or domains will reduce the risk that you fall victim to these attackers.”   

Netskope Threat Labs recommends enterprises in the retail sector review their security posture and make several recommendations for best practices to counter these threats, which includes:

The report is based on anonymised usage data collected about a retail sector subset of Netskope’s 2,500+ customers, all of whom give prior authorisation for their data to be analysed in this manner.

Netskope Threat Labs cyber threat retail technology SASE cyber security Botnets

First Published : April 05, 2024 12:08 pm

Related Viewpoints

Luxury vinyl tiles market worth $35.9 billion, says report

A glimpse of seamless retail in this ‘Chicago of China’

POS software market to see 9.57% CAGR in 7 years, says this report