Use of Malware Decreases in Cyber Attacks as Exploit Usage Skyrockets

Stu Sjouwerman | Mar 10, 2023

Use of Malware Decreases in Cyber Attacks as Exploit Usage SkyrocketsNew data on cyberattacks from last quarter provides a lens of what kinds of attack techniques to expect to see from cyber attackers this year.

Cybercriminals are responding to changes in cybersecurity measures. According to cybersecurity vendor Nuspire’s Q4 2022 and Year in Review Threat Report, malware is on its way out, botnets are down and exploits are becoming the hot new focus.

According to the report, malware usage declined by 35% from Q3 to Q4 – Nuspire attributes this to Microsoft disabling of VBA macros within Office documents, rendering the use of such droppers useless. Nuspire did mention that phishing will continue and, despite the sizable dip in Q4, 2022 overall still saw a nearly 7% increase in malware use over the previous year.

malware usage declined by 35% from Q3 to Q4 2022

Source: Nuspire

In contrast, exploits grew massively in popularity – to the tune of 104.6% growth from Q3 to Q4 of last year, with 2022 as a whole experiencing a 92% growth in exploits over the previous year.

104.6% exploit growth from Q3 to Q4

Source: Nuspire

These shifts in technique show that cybercriminals aren’t stifled at all by improvements in cybersecurity; instead they simply shift to where the greatest opportunity lies to see a successful attack.

With phishing still very much on the rise – despite the nearly extinct use of VBA macros – attackers need to rely on social engineering to trick victims into downloading malicious exploits and malware – something thwarted by Security Awareness Training designed to educate users on what cyberattacks look and act like, so they don’t become their next victim.

Topics: Phishing Malware

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.