September 4, 2019 By David Bisson 2 min read

Attackers launched 356,000 attempts to target users with school-themed malware files during the 2018–19 academic year.

Kaspersky Lab took a look back at the 2018–19 academic year and observed 356,000 instances in which bad actors attempted to target its users with school- and student-themed malware attacks.

Researchers determined that 233,000 of those attempts were instances in which 74,000 Kaspersky customers downloaded malicious school essays, and 122,000 attacks in which over 30,000 users tried to download what they thought were textbooks. English language and math textbooks were some of the top subjects attackers exploited to prey on students, but threat actors also used natural sciences and foreign languages as lures for their fake academic texts.

The researchers found that some malware families were more prevalent than others in these attacks. The Worm.Win32 Stalk.a worm earned the top spot for its ability to spread to other devices via the local network and email. In second place was Win32.Agent.ifdx, followed by WinLNK.Agent.gen and the MediaGet torrent app downloader in third and fourth places, respectively.

A Larger Effort to Target the Education Sector

The attack attempts detected by Kaspersky Lab factor into criminals’ ongoing efforts to target the education sector with malware.

Back in May 2019, Coventry Local Schools canceled classes for a day after Trickbot affected its network. In July, the governor of Louisiana declared a state of emergency after three separate school districts reported digital infections, as reported by AP News. That was just a few days before Houston County Schools told WTVY it had pushed back the first day of classes for the 2019–20 academic school year for the second time in a week following a ransomware attack.

Protecting Students Against School-Themed Malware

Security professionals can help protect students against school-themed malware by using the buy-in of school administrators to build a security awareness training program for the student populace. To make the program successful, security personnel can use tools such as the NIST Framework and gamification to cater to the culture of their school’s student body.

More from

CISA releases landmark cyber incident reporting proposal

2 min read - Due to ongoing cyberattacks and threats, critical infrastructure organizations have been on high alert. Now, the Cybersecurity and Infrastructure Security Agency (CISA) has introduced a draft of landmark regulation outlining how organizations will be required to report cyber incidents to the federal government.The 447-page Notice of Proposed Rulemaking (NPRM) has been released and is open for public feedback through the Federal Register. CISA was required to develop this report by the Cyber Incident Reporting for Critical Infrastructure Act of 2022…

Ransomware payouts hit all-time high, but that’s not the whole story

3 min read - Ransomware payments hit an all-time high of $1.1 billion in 2023, following a steep drop in total payouts in 2022. Some factors that may have contributed to the decline in 2022 were the Ukraine conflict, fewer victims paying ransoms and cyber group takedowns by legal authorities.In 2023, however, ransomware payouts came roaring back to set a new all-time record. During 2023, nefarious actors targeted high-profile institutions and critical infrastructure, including hospitals, schools and government agencies.Still, it’s not all roses for…

What should an AI ethics governance framework look like?

4 min read - While the race to achieve generative AI intensifies, the ethical debate surrounding the technology also continues to heat up. And the stakes keep getting higher.As per Gartner, “Organizations are responsible for ensuring that AI projects they develop, deploy or use do not have negative ethical consequences.” Meanwhile, 79% of executives say AI ethics is important to their enterprise-wide AI approach, but less than 25% have operationalized ethics governance principles.AI is also high on the list of United States government concerns.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today