Skip to content
June 27, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Check Point Announces Top 10 Most Popular Malware in March 2018
  • Malware

Check Point Announces Top 10 Most Popular Malware in March 2018

Do Son April 18, 2018 5 minutes read
Add as a preferred
source on Google

In the newly released Global Malware Threat Impact Index report, Check Point, a network security company, pointed out that the number of cyberattacks against cryptocurrencies has surged throughout March. Among them, more and more cybercriminals have begun to use the modified XMRig mining program to carry out malicious mining activities.

XMRig was originally a legitimate open-source mining program with multiple updated versions that support 32-bit and 64-bit Windows and Linux operating systems. However, based on its open source nature, several malicious versions have been used by cybercriminals in the past few months to install in the victim’s system without permission to gain illegal profits.

On the other hand, XMRig’s mining behavior exploits the CPU resources of the computer itself and does not involve any web browser interactions. In other words, cybercriminals can use malware developed based on the XMRig mining program to mine money without the victim opening any web pages.

In addition to slowing down the speed of computers or servers, malicious software developed based on XMRig infects a device and starts looking for other devices on the same network to complete self-replication. This can cause serious security threats to victims.

After appearing for the first time in May 2017, XMRig is constantly being revised and updated by cybercriminals, and finally entered Check Point’s list of the top ten most popular malware programs in the world (ranked eighth, affecting 5% of the global organization).

Due to the impact of 18% of the global organization, Coinhive, which also mines malware for cryptocurrencies, has remained at the top spot for the fourth consecutive month. In second place is the exploit tool Rig ek (affects 17%), while another cryptocurrency mining malware, Cryptoloot, came in third (affecting 15%).

Top 10 Most Popular Malware in March 2018

*The arrows relate to the change in rank compared to the previous month.

  1. ↔ Coinhive – Crypto Miner designed to perform online mining of Monero cryptocurrency when a user visits a web page without the user’s knowledge or approval the profits with the user. The implanted JavaScript uses great computational resources of the end users to mine coins and might crash the system.
  2. ↑ Rig ek – Exploit Kit first introduced in 2014. Rig delivers Exploits for Flash, Java, Silverlight and Internet Explorer. The infection chain starts with a redirection to a landing page that contains JavaScript that checks for vulnerable plug-ins and delivers the exploit
  3. ↓ Cryptoloot – Crypto-Miner, using the victim’s CPU or GPU power and existing resources for crypto mining – adding transactions to the blockchain and releasing new currency. It is a competitor to Coinhive, trying to pull the rug under it by asking less percents of revenue from websites.
  4. ↑ Roughted – Large scale Malvertising used to deliver various malicious websites and payloads such as scams, adware, exploit kits and ransomware. It can be used to attack any type of platform and operating system, and utilizes ad-blocker bypassing and fingerprinting in order to make sure it delivers the most relevant attack.
  5. ↓ Jsecoin – JavaScript miner that can be embedded in websites. With JSEcoin, you can run the miner directly in your browser in exchange for an ad-free experience, in-game currency and other incentives
  6. ↔ Fireball – Browser-hijacker that can be turned into a full-functioning malware downloader. It is capable of executing any code on the victim machines, resulting in a wide range of actions from stealing credentials to dropping additional malware.
  7. ↑ Andromeda – Modular bot used mainly as a backdoor to deliver additional malware on infected hosts, but can be modified to create different types of botnets.
  8. ↑ XMRig– XMRig is an open-source CPU mining software used for the mining process of the Monero cryptocurrency, and first seen in-the-wild in May 2017.
  9. ↓ Necurs – Botnet used to spread malware by spam emails, mainly Ransomware and Banking Trojans.
  10. ↑ Conficker – Worm that allows remote operations and malware download. The infected machine is controlled by a botnet, which contacts its Command & Control server to receive instructions.

 March’s Top 3 ‘Most Wanted’ mobile malware:

  1. Lokibot –  Android banking Trojan and info-stealer, which can also turn into a ransomware that locks the phone.
  2. Triada – Modular Backdoor for Android which grants superuser privileges to downloaded malware.
  3. Hiddad– Android malware which repackages legitimate apps then releases them to a third-party store.

The three most popular security vulnerabilities in March 2018

Oracle WebLogic WLS Security Component Remote Code Execution Vulnerability (CVE-2017-10271), global impact rate of 26% – It resides in Oracle WebLogic’s WLS component, derived from Oracle WebLogic’s incorrect approach to processing xml decoding, successful use May cause remote code execution.

SQL injection vulnerabilities, global impact rate of 19% – Injecting SQL queries into the input from the client to the application, taking advantage of the specificity of the database to gain more information or more permissions.

Microsoft Windows HTTP.sys Remote Code Execution Vulnerability (MS15-034: CVE-2015-1635), Global Impact Rate is 12% – Vulnerability is caused by HTTP.sys handling malicious HTTP headers in a wrong way. Successful exploitation will result in Remote Code Execution.

Related coverage

  • QBot Resurfaces: New BackConnect Malware Signals a Dangerous Evolution
  • Iranian “Dream Job” Campaign Targets Aerospace Industry with SnailResin Malware
  • Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
  • Kaspersky Reveals Lazarus’ Sophisticated Techniques in Targeting Software Vendors
  • Predator Spyware Resurges: New Infrastructure, Evasion Tactics, and Mozambique Customer Uncovered

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: top 10 Popular Malware

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-42208
    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version...
  • CVE-2018-1273CVSS 9.8
    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a...
  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-12569
    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The...
  • CVE-2026-28496CVSS 9.4
    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template...
  • CVE-2026-21509CVSS 7.8
    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a...
  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-12415CVSS 9.8
    The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due...
  • CVE-2026-28701CVSS 9.8
    Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote...
  • CVE-2026-53576CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-49869CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-54350CVSS 10.0
    Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor...
  • CVE-2026-54352CVSS 9.6
    Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at...
  • CVE-2026-52785CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52782CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52780CVSS 9.6
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-46386CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to , the official...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.