Home Office Security Gap – Tracking Cybercriminals
ESET has released its Threat Report for Q3 2020. The findings reveal that cybercriminals are intensifying their attacks on remote workers. The report documents over 7.1 million attacks targeting home-based employees across the DACH region (Germany, Austria, Switzerland) – a surge of approximately 390 percent compared to the Q2 2020 report.
Cybercriminals are sharpening their focus on home office environments. The Remote Desktop Protocol (RDP) remains the top target in Q3 as well. Roughly 7.1 million RDP-based attacks hit remote workers across the DACH region every day – a 390 percent increase since March. Android banking malware attacks also surged dramatically in Q3. Additionally, cybercriminals have recently ramped up their use of cryptocurrency miners. These are among the key findings from ESET’s Q3 2020 Threat Report, just published by the European IT security vendor.
“Our own surveys on how the coronavirus pandemic has reshaped the world of work show that around one-quarter of all German companies allow at least some employees to connect to corporate networks using personal hardware. That is disastrous – this shadow IT leaves infrastructure wide open to cybercriminals, like a barn door,” explains Michael Schröder, Security Business Strategy Manager DACH at ESET. “A 390 percent rise since March underscores starkly that criminals have identified this weakness across many organizations – and are exploiting it aggressively. IT decision-makers must act immediately.”
Over 7.1 Million Daily Attacks Targeting the RDP Protocol
According to a recent ESET survey, 26 percent of companies deploy personal devices – fully or partially – for employees working remotely. Introducing unknown devices into a corporate network poses an enormous security risk. Since March, cybercriminals have been highly active in exploiting this vulnerability to gain access to sensitive data and monetize it. In Germany, Austria, and Switzerland alone, there were on average roughly 7.1 million RDP-targeted attacks per day in September. Since March, such attacks have increased by approximately 390 percent.
The chart shows the sharp rise in attacks since March 2020. Source: ESET
Android Banking Malware Shows Alarming Growth
The Cerberus malware has been known since June 2019 and is an Android-specific banking trojan designed to steal online banking credentials. Following the splintering of the hacker group behind Cerberus, its source code was released freely online in August this year. Since then, anyone can adapt and deploy the malware for their own purposes – triggering a rapid spike in attack attempts.
Cryptocurrency Miners Make a Comeback
With Bitcoin’s exchange rate climbing, attackers have renewed their focus on cryptocurrency miners. These malicious programs secretly mine digital currencies in the background. During the pandemic, activity involving this type of malware declined – but has picked up speed again since August.
Key Facts
Damage volume: Cybercrime causes over €8 trillion in global damages annually.
Skills gap: More than 3.5 million cybersecurity professionals are missing worldwide.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What are the most common cyber threats facing businesses?
According to the BSI (Federal Office for Information Security) Situation Report, ransomware, phishing, DDoS attacks, and supply-chain compromises are the most frequent threats. For German companies, regulatory risks – including the GDPR and NIS2 Directive – add further complexity.
How much should a company invest in cybersecurity?
Industry experts recommend allocating 10 to 15 percent of the overall IT budget to cybersecurity. According to Bitkom, German companies currently spend an average of 14 percent. What matters most isn’t just the amount – but the strategic distribution across prevention, detection, and response.
Does every company need a CISO?
Not every organization requires a full-time Chief Information Security Officer – but every company does need clearly defined accountability for IT security at the executive leadership level. SMEs can engage an external CISO (Virtual CISO). Under NIS2, management-level responsibility for cybersecurity is now enshrined in law.
Related Articles
- DDoS Attacks Surpass 10-Million Mark for the First Time in 2020
- Security Is Possible Even Without an IT Department
- secIT by Heise 2026: The Security Roadshow for Admins and IT Decision-Makers
More from the MBF Media Network
TL;DR
- The report records over 7.1 million attacks on remote workers across the DACH region – a 390 percent increase over the Q2 2020 report.
- “A 390 percent rise since March underscores starkly that criminals have identified this weakness across many organizations – and are exploiting it aggressively.”
- “IT decision-makers must act immediately.” Over 7.1 million daily attacks target the RDP protocol. A recent ESET survey found that 26 percent of companies deploy personal devices for remote work…
- In Germany, Austria, and Switzerland alone, there were on average roughly 7.1 million RDP-targeted attacks per day in September.