Cybercriminals Target Small Businesses Through Common Productivity Software

With the extensive use of popular productivity tools, they have become prime targets for cybercriminals. Their widespread adoption results in a broad attack surface, making it easier for hackers to access vast amounts of sensitive information.

When these tools are compromised, attackers can infiltrate multiple organizations, disrupt operations, and leverage the compromised trust to deploy malware or exfiltrate personal data.

Kaspersky Lab’s recent research has revealed that cybercriminals are increasingly exploiting small and medium-sized businesses (SMBs) through these commonly used productivity applications.

The surge in digital technology and the financial constraints faced by SMBs have made them more vulnerable to cybersecurity threats. Kaspersky’s 2024 threat analysis, informed by Kaspersky Security Network telemetry, indicates a notable rise in malicious activity targeting SMB-specific applications.

For UK-based SMBs, robust cybersecurity measures are crucial, given that around 50% are expected to experience cyber-attacks annually. This scenario underscores the necessity for effective technological defenses and a strong organizational culture geared toward security.

The following applications were examined in the study:

  • Microsoft Excel
  • Microsoft Outlook
  • Microsoft PowerPoint
  • Salesforce
  • Microsoft Word
  • Microsoft Teams
  • QuickBooks
  • Microsoft Exchange
  • Skype for Business
  • ClickUp
  • Hootsuite
  • ZenDesk

Between January and April 2024, malware and unwanted software targeted 2,402 SMB users, with 4,110 distinct malicious files identified—a significant 8% increase from the previous year. Excel, once ranked fourth for targeted applications in 2023, has now become the most exploited. The total number of infections in the SMB sector rose by 5%, reaching 138,046 during this timeframe.

Trojans remain the predominant threat, as attackers favor malware that mimics legitimate programs, making detection more challenging. Particularly concerning is the rise in DangerousObject attacks—newly identified malicious software samples that have seen the most significant year-over-year increase.

This escalation highlights the evolving nature of cyber threats and the need for advanced, adaptable security solutions for SMBs.

Employee negligence and phishing attacks continue to pose significant risks. Cybercriminals utilize various deceptive tactics, including fake emails, websites, and social media profiles, to trick users into revealing personal information.

Delivery services, insurance platforms, and Microsoft-related services are frequently targeted. Additionally, social media account breaches can damage reputations and compromise customer data.

Often, spam targeting SMBs offers dubious services that may seem enticing but are ultimately untrustworthy.

To mitigate these threats, SMBs should invest in comprehensive cybersecurity solutions, implement strict access controls, regularly update security measures, and provide ongoing employee training to recognize and avoid cyber threats.

More Articles & Posts