Kaspersky: SMEs under attack from malware disguised as legitimate tools
Source: Promo
Wednesday, 24.09.2025.
09:53
Wednesday, 24.09.2025.
09:53
(Photo: Blazej Lyjak/shutterstock.com)
Cybercriminals disguised malware and potentially unwanted applications (PUAs) as trusted tools such as ChatGPT, Microsoft Office applications and Google Drive, in order to penetrate SME networks without arousing suspicion.
The data showed that the size of the market was not necessarily proportional to the number of attacks, with the highest share of these attacks (40%) recorded in Austria, followed by Italy (25%) and Germany (11%).
Serbia, with a share of 1.6%, came in 7th place, indicating a relatively low level of targeting.
Distribution of malware and PUA attacks on SMEs that mimic legitimate applications in selected European countries (Photo: Kaspersky)
Backdoor and Downloader among most exploited threat types
The threats that most affect SMEs in Europe are backdoor attacks (24%), Trojans (17%) and not-a-virus: Downloaders (16%).
Most common threats targeting SMEs in Europe (Photo: Kaspersky)
“Small businesses face threats at the level of large corporations, and often have budgets typical of startups,” says Mark Rivero, lead security researcher at the Global Research and Analysis Team (GreAT) at Kaspersky. “The key is knowing where to focus your limited resources for maximum protection. The best defense against sophisticated malware is not the most expensive tool - it’s understanding the attackers’ mindset and closing the doors they are looking for.”
Practical cybersecurity advice
Small and medium-sized enterprises can significantly reduce cyber risks and protect business continuity by combining robust security solutions with high employee awareness. Key measures include:
• Implement security hardening: Strengthen existing systems by reducing the attack surface. This includes implementing strong authentication and authorization with strict password policies and multi-factor authentication, regularly updating software and patching vulnerabilities, encrypting data at rest and in transit, and maintaining reliable backups to protect against data loss or business interruption.
• Raising employee awareness: Organize regular training sessions to improve cyber literacy, focusing on safe email use, secure password management, recognizing phishing attempts, and proper handling of sensitive data.
• Using official software sources: Avoid downloading applications through browsers. All new software should come from trusted, official sources and be centrally installed by the IT team to prevent hidden threats.
• Controlling access to resources: Define clear rules for accessing email, shared folders, and online services, monitor user activity, and immediately revoke access when employees leave the company.
• Implementing specialized security solutions: Tools like KasperskyNext combine strong endpoint protection with EDR and XDR capabilities and are designed for corporate clients of any size and industry.
Kaspersky Next XDR Optimum is particularly suitable for SMEs with developed IT infrastructures, which are often managed by larger IT teams or smaller security departments.
For very small businesses that may not have an IT administrator, Kaspersky Small Office Security (KSOS) offers protection without the need for ongoing maintenance, through a simple “install and forget” setup.
For more information, including examples of phishing attacks affecting SMEs in Europe, read the full report.
Companies:
Kaspersky
Tags:
Kaspersky
KasperskyNext
Kaspersky Next XDR Optimum
cyber security
protection
cyber attacks
applications
Comments
Your comment
Most Important News
Full information is available only to commercial users-subscribers and it is necessary to log in.
Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno,
uz konsultacije sa našim ekspertima.

Izdanje Srbija
Serbische Ausgabe
Izdanje BiH
Izdanje Crna Gora