Welcome | Sign In
ECommerceTimes.com
Security

Cyber-Crooks Ape Business Best Practices

Print Version
E-Mail Article
Reprints
Cyber-Crooks Ape Business Best Practices

Cyber-crime is a flourishing big business, and although the individuals driving its success may be keeping to the shadows, their handiwork is not. The latest malware tools causing headaches for legitimate businesses and users alike are the products of increasingly professional developers who offer such perks as regular updates and service agreements.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

A software tool is released with a performance guarantee and the promise of periodic updates. Another commercial application for the market? Not quite. Rather, this is emblematic of how malware writers are doing business these days.

"We definitely see much of the illegal online activity becoming more professional and adopting behavior and practices you would see in a legitimate company," said Javier Santoyo, senior manager of emerging technologies for Symantec (Nasdaq: SYMC) Security Response.

This insight into online criminal behavior is revealed in Symantec's newly released Internet Security Threat Report. One of its main findings is that cyber-criminals are adopting commercial practices in the development, distribution and use of malicious code and services.

Quality Assurance and Service Agreements

"There is quality assurance testing on these tools, for example," Santoyo told TechNewsWorld. "Many are even providing services . . . like updating the application or tool every time a new exploit is discovered."

Such updates are the reverse of what consumers receive from their antivirus protection vendors -- that is, instead of updating the software to protect against an exploit, the malware virus writers update the application to exploit the vulnerability.

One example is MPack, a professionally developed toolkit that installs malicious code on thousands of computers around the world and then monitors the success Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales of the attack through various metrics on its online password-protected control and management console, Symantec said.

Phishing toolkits have also become commercialized, with the top three most widely used phishing toolkits responsible for 42 percent of all phishing attacks detected during the reporting period, which ran from January to June 2007.

Attackers are also learning to adapt to the protective measures put in place by companies and consumers. Instead of trying to break through anti-malware defenses, Symantec found, they have been seeding malware on trusted sites that are widely visited, such as popular financial, social networking and career recruitment Web sites. Symantec said that 61 percent of all vulnerabilities disclosed were in Web applications.

Meeting a Need

These virus writers see themselves as providing a necessary service, Santoyo said. "They know that their tools will be used for illegal activities, but they see the end users -- the people who actually use their products -- as the real criminals."

Some of this insight was gathered through a series of interviews Symantec conducted with one of the hackers behind MPack. It is an occasional tactic the company uses to complement its own research on current malware trends, said Santoyo.

"They never give information that could reveal their identities or could help us thwart their activities," he noted. "Still, though, the interviews are invaluable in helping us keep a handle on what is happening."


Print Version E-Mail Article Reprints More by Erika Morphy


Related News Alerts

Symantec Activate Alert | Search Archives

More by Erika Morphy

Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter
November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network