Welcome | Sign In
ECommerceTimes.com
Malware

Report: Money Makes Malware World Go Round

Print Version
E-Mail Article
Reprints
Report: Money Makes Malware World Go Round

The days of malware purely for the sake of notoriety are officially over. For some time, hackers have been more interested in making money than in making mischief, but Symantec now reports that virtually every attack on the Internet is associated with some type of personal data theft.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

Data theft has become the raison d'etre for malware on the Internet, according to the latest figures released by security vendor Symantec (Nasdaq: SYMC).

As in previous years, the vendor reported upticks in data thefts, malware and phishing scams. What is different about this year, said Alfred Huger, vice president of engineering at Symantec Security Response, is that data theft has become the norm.

"The trend has always been there -- hackers have always been interested in financial gain," he told TechNewsWorld. "Now, though, it seems that every piece of malicious code on the Internet somehow ties back to data theft."

The trend became solid in 2006, Huger said, and developed into a visible underground economy in the last six months.

For the first time, Symantec followed the trade of stolen personal information on underground economy servers. It found these servers are used by hackers and criminal organizations to sell stolen data including social security numbers, credit cards, personal identification numbers (PINs), and e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse address lists.

Price points were shockingly low for such information, according to Symantec. U.S.-based credit cards with a card verification number were available for between US$1 and $6 while a complete identity -- including a U.S. bank account, credit card, date of birth and government-issued identification number -- was available for between $14 and $18.

Scams More Sophisticated

Online scams, usually perpetrated through e-mail fraud, are increasing and becoming more sophisticated, Symantec found, and are often timed to coincide with specific events.

During the second half of 2006, spam made up 59 percent of all monitored e-mail traffic. Thirty percent of all spam related to the financial services industry -- for example, so-called pump-and-dump scams.

Over the last six months of 2006, Symantec tracked a total of 166,248 unique phishing messages -- an average of 904 per day. That figure reflects a 6 percent increase over the first six months of 2006.

For the first time, Symantec tracked the impact a phishing attack had when it was sent on a certain day or around a certain event.

An average of 27 percent fewer unique phishing messages were sent on weekends than on weekdays, when 961 were sent on average. This trend indicates that phishing activity mirrors the business week, with attackers attempting to mimic a legitimate company's e-mail practices, Symantec said.

Phishing activity increased during major holidays and other high-profile events, Symantec observed, such as the FIFA World Cup, with attackers crafting theme-specific social engineering ruses.

Tax Season

Indeed, hackers are now gearing up for tax season -- the mother lode of special event phishing, Paul Henry, vice president of technology evangelism at Secure Computing, told TechNewsWorld.

"Phishing scams are becoming more sophisticated -- that is very clear," he said.

This year's tax filing season is likely to be the riskiest so far, Henry noted, pointing to the increased number of hackers trying to gain financial information, the increased number of people filing returns online from unsecured personal computers, and the increased number of drive-by phishing attacks. Drive-by attacks use malicious code to corrupt an ISP (Internet service provider) so that a user who types in an address -- say the IRS Web site, for example -- is redirected to a malicious site.

"This in particular is very frightening, because the common sense advice to people to avoid fraud is to type in the address manually. Now that safeguard is gone," Henry said.

Other findings from the Symantec report:

  • More than 6 million distinct bot-infected computers were identified worldwide during the second half of 2006, representing a 29 percent increase from the previous period. However, the number of command-and-control servers used to relay commands to the bots decreased by 25 percent, suggesting that bot network owners are consolidating and increasing the size of their existing networks.
  • Trojans made up 45 percent of the top 50 malicious code samples -- a 23 percent increase over the first six months of 2006.
  • Twelve zero-day vulnerabilities during the second half of 2006 were documented, a significant increase from the one zero-day vulnerability documented in the first half of 2006.


Print Version E-Mail Article Reprints More by Erika Morphy


Related News Alerts

Symantec Activate Alert | Search Archives

More by Erika Morphy

Cisco Adds New Technologies to Collaboration Tool Chest
November 09, 2009
Cisco has launched new collaboration tools designed to make it easier for businesses to work closely with their partners without creating security risks. They also provide a receptive platform for the increased use of video and social media in the enterprise. Cisco introduced three new network devices to support the collaboration tools.
Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network