Researchers discover the ‘biggest web malware threat’
Sophos says that one particular strain of malware is infecting the largest percentage of websites.

A new web-based threat is claimed to blow all web-based malware out of the water', after it was found to be six times more prevalent than its nearest rival.
SophosLabs researchers said that malware it calls Troj/JSRedir-R' accounted for 42 per cent of all malicious infections found on websites between the 6 and 13 May.
This was far more than its nearest rival Mal/Iframe-F', which only made up seven per cent of infections.
Sophos said that JSRedir-R was usually found on legitimate websites behind difficult to understand JavaScript.
The malware would attempt to download malicious content from third-party sites without the knowledge of the user.
Sophos security analyst Graham Cluley said on his blog that for this malware to overtake Mal/Iframe-F in the web malware charts was "quite an event".
He warned website owners to make sure sites were properly protected to prevent hackers from injecting malicious code into pages.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He said: "No-one should be in any doubt that the web is the primary vector by which hackers are trying to infect computers today."
Sophos virus and spam researcher Paul Baccas also issued advice if a website was found to be infected.
Last month IT PRO reported on how criminals are targeting the web browser as the 'weak link' in the security chain.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
96% of SMBs are missing critical cybersecurity skills – here's why
News The skills shortage hits SMBs worse as they often suffer from a lack of budget and resources
By George Fitzmaurice
-
Sophos Firewall Virtual review: Affordable network protection for those that like it virtualized
Reviews Extreme network security that's cheaper than a hardware appliance and just as easy to deploy
By Dave Mitchell
-
MSPs are struggling with cyber security skills shortages
News A shortage of tools and difficulties keeping pace with solutions were also ranked as key issues for MSPs
By George Fitzmaurice
-
Nearly 70 software vendors sign up to CISA’s cyber resilience program
News Major software manufacturers pledge to a voluntary framework aimed at boosting cyber resilience of customers across the US
By Solomon Klappholz
-
Sophos and Tenable team up to launch new managed risk service
News The new fully managed service aims to help organizations manage and protect external attack surfaces
By Daniel Todd
-
Ransomware groups are using media coverage to coerce victims into paying
News Threat actors are starting to see the benefits of a more sophisticated media strategy for extracting ransoms
By Solomon Klappholz
-
Shrinking cyber attack “dwell times” highlight growing war of attrition with threat actors
News While teams are becoming more proficient at detecting threats, attackers are augmenting their strategies
By Ross Kelly
-
Cyber security in the retail sector
Whitepapers Retailers need to ensure their business operations and internal data aren't breached
By ITPro