To quote Larry Kudlow: Free market capitalism is the best path to prosperity! Matters of business and free enterprise are discussed on this blog. Included are company press releases, 3rd party news articles and videos, articles and videos pertaining to small business, and white collar crime.
Search This Blog
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts
Thursday, May 22, 2014
Friday, September 7, 2012
ESET Mobile Security Contains the Most Modern Security Components for Smartphones Says AV-Comparatives
Press release:
San Diego, CA, September 6, 2012
San Diego, CA, September 6, 2012
ESET Mobile Security Contains the Most Modern Security Components for Smartphones Says AV-Comparatives
Share
ESET, the leader in proactive protection celebrating 25 years of its technology this year, has scored an excellent review for its Android-based product in the latest Mobile Security Review by independent testing authority AV-Comparatives.
ESET Mobile Security for Android has scored high marks in all major categories, including both low battery usage and malware detection capabilities while also earning recognition as a top solution when it comes to detecting the most adware families.
AV-Comparatives analyzed the key functionalities of the feature-rich product, namely Antivirus, Antispam, Anti-Theft, SIM-matching, Remote Wipe and Remote Lock. The testing authority also recognized ESET for flawless installation of the product and, “a variety of setting options for Antivirus protection compared to other products.”
Most importantly, AV-Comparatives found that, “this product was one of few that made data recovery after a remote wipe completely impossible,” given that ESET Mobile Security overwrites the entire memory. “ESET Mobile currently contains the most modern security components for smartphones,” concluded AV-Comparatives in the report.
“A dedicated team of ESET Mobile Security developers has made every effort to develop the most advanced solution for protecting our customers on-the-go,” said ESET Product Manager for Mobile Security Miroslav Majtáz. “We are proud that an authority such as AV-Comparatives is recognizing our talent and technology.”
In the coming weeks, ESET is planning to release ESET Endpoint Security for Android – a mobile security solution for business customers with remote administration capabilities.
About ESET
ESET is on the forefront of security innovation, delivering trusted protection to make the Internet safer forbusinesses and consumers. IDC has recognized ESET as a top five corporate anti-malware vendor and one of the fastest growing companies in its category. Trusted by millions of users worldwide, ESET is one of the mostrecommended security solutions in the world. ESET NOD32 Antivirus consistently achieves the highest accolades in all types of comparative testing, and powers the virus and spyware detection in ESET Smart Security and ESET Cybersecurity for Mac. Sold in more than 180 countries, ESET’s global headquarters is in Bratislava, Slovakia, with distribution headquarters for North America located in San Diego, California. ESET also has offices in Buenos Aires, Prague, Krakow and Singapore and is represented by an extensive global partner network. For more information, visit http://www.eset.com/us or call +1 (619) 876-5400.
Tuesday, August 7, 2012
South Korea Has the Highest Percentage of Infected Computers, According to PandaLabs Q2 Report
AUG 07, 2012
South Korea Has the Highest Percentage of Infected Computers, According to PandaLabs Q2 Report
- Over six million new malware samples were created in Q2 2012
- Three out of every four malware infections are caused by Trojans
- New variant of the ‘Police Virus’ emerges
- The full report is available at http://press.pandasecurity.com/press-room/reports/
PandaLabs, Panda Security’s anti-malware laboratory, today published its Quarterly Report for Q2, analyzing the IT security events and incidents from April through June 2012. In the second quarter of 2012 alone, more than six million new malware samples were created, a similar figure to the first quarter.
South Korea Tops List of Infections per Country for First Time Ever
The average number of infected PCs across the globe stands at 31.63 percent, falling almost four percentage points compared to Q1, according to Panda Security’s Collective Intelligence data. South Korea led this ranking (57.30 percent of infected PCs) for the first time ever, up by almost three percentage points compared to Q1. China took the second spot (51.94 percent), followed by Taiwan and Bolivia. The list of least infected countries is dominated by European countries with nine out of the first ten places being occupied by them, the only exception being Uruguay. The top-ranked country is Switzerland (18.40 of infected PCs), followed by Sweden (19.07 percent), the only nations with fewer than 20 percent of computers infected. Norway, United Kingdom, Uruguay, Germany, Ireland, Finland, Hungary and Holland are the other eight countries with the least malware infections.
Luis Corrons, technical director of PandaLabs, states: “The list of least infected countries is dominated by some of the world’s most technologically advanced nations, with the sole exception of South Korea. Even though there may be other factors that influence these results, there seems to be a clear connection between technological development and malware infection rates.”
Countries with the most malware infections
Malware Statistics
Trojans continued to account for most of the new threats created this quarter (78.92 percent); worms took second place, comprising 10.78 percent of samples; followed by viruses at 7.44 percent. The last place was occupied by adware/spyware at 2.69 percent
Interestingly, viruses continued their decline, moving from second place in the 2011 Annual Report (14.24 percent) to third place (7.44 percent) this quarter. Worms maintained their second position, rising from 9.30 percent last quarter to almost 11 percent this quarter.
When it comes to the number of infections caused by each malware category, Trojans once again topped the ranking, accounting for more infections than in the first quarter (76.18 percent compared to 66.30 percent). Viruses came second (7.82 percent), followed by worms (6.69 percent). “It is interesting to note that worms have only caused six percent of infections despite accounting for almost 11 percent of all new malware”, says Corrons.“The figures corroborate what is well known: massive worm epidemics have become a thing of the past and have been replaced by an increasing avalanche of banking Trojans and specimens such as the Police Virus.”
The Quarter at a Glance
In the report, PandaLabs highlights several top security incidents that occurred during Q2: the proliferation and evolution of the so-called ‘Police Virus’ from scareware to ransomware, and Flame, a cyber-espionage virus that has become one of the highlights of the year.
The report also covers the latest cases of cyber-crime, such as a hacker attack on Wikipedia users, the exploitation of a major security hole in Iran’s banking system, and the new ways found by law enforcement agencies to fight data theft. Finally, it includes information about the latest attacks on mobile phones and social networking sites, the cyber-espionage operations between nations such as the United States and Yemen, or the traditional cyber-conflict between North and South Korea.
PandaLabs advises all users to keep their computers adequately protected with a solution like Panda Security’s free Panda Cloud Antivirus.
The quarterly report can be downloaded from: http://press.pandasecurity.com/press-room/reports/
Saturday, August 4, 2012
Saturday, March 31, 2012
Malware, Phishing Gather in North America
In its annual review of global security threats, Websense says a major trend it observed last year is that more malware connections, hosting and phishing appear to be occurring in the United States and Canada.
"50 percent of malware connections lead to the U.S.," says Charles Renert, vice president of Websense Security Labs. According to the 2012 Websense Threat Report, Canada's malware ranking has also zoomed upward in the past year, so the country now clocks in at No. 2 at 13.2 percent. The countries in the top five ranking include Germany at 5.4 percent, the Netherlands at 4.9 percent and China at 4.1 percent.
China and Russia used to be much bigger in the rankings, according to Websense, but since organizations have been more often blocking IP ranges for these countries, cybercriminals have turned to getting malware closer to their victims by exploiting trusted networks, such as social-networking sites. (See also "Best Security Suites: PC Bodyguards.")
For more, click the link below:
http://www.pcworld.com/article/252909/malware_phishing_gather_in_north_america.html#tk.nl_bdx_h_crawl
Saturday, March 24, 2012
How to Avoid Malware
Here is an article from the archives that looks like it could still be helpful.
http://www.pcworld.com/article/210891/how_to_avoid_malware.html?tk=rel_news
Tuesday, February 21, 2012
News Release from Panda Security
FEB 16, 2012
One Bot To Rule Them All
- The Ainslot.L bot scans computers and removes any other bots it finds
- It spreads in a fake email purporting to come from UK clothing company CULT
- The message is very well crafted to avoid raising suspicion
PandaLabs, the anti-malware laboratory of Panda Security –The Cloud Security Company– has reported on a new bot called Ainslot.L. This malware is designed to log user activities, download additional malware and take control of the system. Additionally, it acts as a banker Trojan, stealing log-in information related to banks. It also scans the computer looking for and removing other bots so that it becomes the only bot on the system.
“The fact that Ainslot.L removes other bots from infected systems definitely caught our attention”, explained Luis Corrons, technical director of PandaLabs. “It eliminates all competition, leaving the computer at its mercy. It reminds us of the popular ‘Highlander’ movies, – There can be only one –.”
It spreads in a fake email purporting to come from UK clothing company CULT. The message, which is very well crafted, informs users that they have placed a £200 order on CULT’s online store and the invoice amount will be charged to their credit card. The text includes a link to view the order which actually downloads the bot onto the computer.
According to Corrons, “Phishing emails are not usually so well done. There is no doubt that this time fraudsters have been very careful to try to make these messages look as real as possible to get as many bites as they can”.
More information is available in the PandaLabs Blog.
Monday, February 20, 2012
Criminals Exploit Stolen Customer Data
Excerpt from an article in The New York Times
Monday, February 20, 2012
Criminals Exploit Stolen Customer Data From Stratfor
By SOMINI SENGUPTA
It began as a case of political hacktivism. Late last year, under the banner of the loose collective known as Anonymous, hackers broke into the systems of Stratfor Global Intelligence Service, a company that analyzes geopolitical risks worldwide. They stole the names, e-mail addresses and credit card numbers of thousands of its subscribers and posted them online for all to see.
That information apparently became lucre for criminals with commercial goals. Stratfor customers began receiving e-mails from what, at first glance, looked like Stratfor. An attached PDF file came with what looked like Stratfor letterhead. It warned of the risk of "harmful software" and asked the user to download an antivirus program by clicking on an embedded link. As it turns out, the link downloaded a piece of malicious software. It was detected by Microsoft's Malware Protection Center, which posted about it on its blog this week.
It's a classic example of what is known as social engineering -- tricking unsuspecting Internet users into downloading malware that can in turn be used to extract financial gain. The social engineering messages are often disguised as e-mails from friends and associates.
Monday, February 20, 2012
Criminals Exploit Stolen Customer Data From Stratfor
By SOMINI SENGUPTA
It began as a case of political hacktivism. Late last year, under the banner of the loose collective known as Anonymous, hackers broke into the systems of Stratfor Global Intelligence Service, a company that analyzes geopolitical risks worldwide. They stole the names, e-mail addresses and credit card numbers of thousands of its subscribers and posted them online for all to see.
That information apparently became lucre for criminals with commercial goals. Stratfor customers began receiving e-mails from what, at first glance, looked like Stratfor. An attached PDF file came with what looked like Stratfor letterhead. It warned of the risk of "harmful software" and asked the user to download an antivirus program by clicking on an embedded link. As it turns out, the link downloaded a piece of malicious software. It was detected by Microsoft's Malware Protection Center, which posted about it on its blog this week.
It's a classic example of what is known as social engineering -- tricking unsuspecting Internet users into downloading malware that can in turn be used to extract financial gain. The social engineering messages are often disguised as e-mails from friends and associates.
Monday, February 13, 2012
Beware of Valentine's Day Malware Distribution
News release from Panda Security:

Desktop wallpaper displayed by Valentin.E.
Beware of Valentine’s Day Malware Distribution Campaigns, PandaLabs reports
- Here are some examples of malware that used social engineering to infect users on this festive occasion
- PandaLabs offers tips to avoid computer viruses on Valentine’s Day
Malware that uses events like Valentine’s Day, Christmas or Halloween as a lure to trick users and infect computers is now a well-established feature of the IT security calendar. Once again, this year it will be no surprise to see numerous emails in circulation with links for downloading romantic greeting cards, videos, gift ideas, or Facebook and Twitter messages related to Valentine’s Day.
Social engineering is cyber-crooks’ preferred technique for deceiving users. In these cases it basically involves obtaining confidential information from users by convincing them to take a series of actions. Crimeware and social engineering go hand-in-hand: a carefully selected social engineering ploy convinces users to hand over their data or install a malicious program which captures information and sends it on to the fraudsters.
Cyber-crooks, however, are also exploiting other channels, such as Facebook, Twitter or Google+, and given the access to millions of users that these social networks provide, they have become just as popular among the criminal fraternity for spreading malware as email.
A new Facebook attack has recently been discovered that uses users’ walls to spread. An apparently harmless message invites users to install a Valentine’s Day theme on Facebook. However, if the user clicks the wall post, they are redirected to a page where they are prompted to install the theme. This installs a malware file which, once run, displays ads from other websites. It also downloads an extension that monitors Web activities and redirects sessions to survey pages that request sensitive information like phone numbers.
Some weeks ago, the PandaLabs blog reported on a link included in a Twitter profile that took users to a dating site: http://pandalabs.pandasecurity.com/sex-lies-and-twitter/. Special dates like Valentine’s Day can see a proliferation of malicious Twitter posts used to steal users’ confidential data and empty their bank accounts through social engineering.
Here is a collection of some of the Valentine’s Day-themed malware campaigns detected by PandaLabs, the anti-malware laboratory of Panda Security, in recent years:
Waledac.C: This worm spread by email trying to pass itself off as a greeting card. The email message included a link to download the card. However, if the user clicked the link and accepted the subsequent file download they were actually letting the Waledac.C worm into their computer. Once it infected the computer, the worm used the affected user’s email to send out spam.
I Love.exe you: This was a RAT (Remote Access Trojan) that gave attackers access to the victim’s computer and all their personal information. The Trojan allowed the virus creator to access target computers remotely, steal passwords and manage files.
Nuwar.OL: This worm spread in email messages with subjects like “I love You So Much”, “Inside My Heart” or “You in My Dreams”. The text of the email included a link to a website that downloaded the malicious code. The page was very simple and looked like a romantic greeting card with a large pink heart. Once it infected a computer, the worm sent out a large amount of emails, creating a heavy load on networks and slowing down computers.
Website that downloaded the Nuwar.OL worm
Valentin.E: This worm spread by email in messages with subjects like “Searching for True Love” or “True Love” and an attached file called “friends4u”. If the targeted user opened the file, a copy of the worm was downloaded. Then, the worm sent out emails with copies of itself from the infected computer to spread and infect more users.
Storm Worm: This worm spread via email by employing a number of lures, one of them exploiting Valentine’s Day. If the targeted user clicked the link in the email, a Web page was displayed while the worm was downloaded in the background.
Web page displayed by Storm Worm
PandaLabs offers users a series of tips to avoid falling victim to computer threats:
- Do not open emails or messages received on social networks from unknown senders.
- Do not click any links included in email messages, even though they may come from reliable sources. It is better to type the URL directly in the browser. This rule applies to messages received through any mail client, as well as those in Facebook, Twitter, or other social networks or messaging applications, etc. If you do click on any such links, take a close look at the page you arrive at. If you don’t recognize it, close your browser.
- Do not run attached files that come from unknown sources. Especially these days, stay on the alert for files that claim to be Valentine Day’s greeting cards, romantic videos, etc.
- Even if the page seems legitimate, but asks you to download something, you should be suspicious and don’t accept the download. If, in any event, you download and install any type of executable file and you begin to see unusual messages on your computer, you have probably been infected with malware.
- If you are making any purchases online, type the address of the store in the browser, rather than going through any links that have been sent to you. Only buy online from sites that have a solid reputation and offer secure transactions, encrypting all information that is entered in the page.
- Do not use shared or public computers, or an unsecured WiFi connection, for making transactions or operations that require you to enter passwords or other personal details.
- Have an effective security solution installed, capable of detecting both known and new malware strains.
Panda Security offers you several free tools for scanning computers for malware, like Panda Cloud Antivirus:www.cloudantivirus.com
Thursday, February 2, 2012
Malware Creation Hit Record High in 2011
News release from Panda Security:
January 31, 2012
Malware Creation hit a New Record High in 2011 with 26 million samples
- Trojans continue to be the most pervasive malware threat
- China, Thailand and Taiwan are the world’s most infected countries
- Data theft, social media and cyber-war take the spotlight
- The full report is available at http://press.pandasecurity.com/press-room/reports/
PandaLabs, the antimalware laboratory of Panda Security, has released its 2011 Annual Security Report, which details an extremely interesting year of data theft, social networking attacks and cyber-warfare. According to the report, malware creation hit a new record high in 2011 with 26 million new strains in circulation, nearly one-third of all malware that has ever existed and been classified by the company (88 million).
These figures show cyber-criminals’ sheer capacity to automate the creation of new malware variants, further evidenced by the average number of new threats created and released every day increasing from 63,000 to 73,000 since last year. Panda Security leverages Collective Intelligence, a cloud-based proprietary system that automatically detects, analyzes and classifies 99.4 percent of all malware received, leaving just 0.6 percent to be dealt with manually. In November 2011, PandaLabs announced that Collective Intelligence had reached a historic milestone by processing 200 million files, and this number has already reached 210 million.
Malware
In 2011, Trojans dominated the threat landscape more than ever before. Whereas in 2009 Trojans made up 60 percent of all malware, the percentage dropped to 56 percent in 2010. Last year, however, the percentage jumped up to 73 percent, so that three out of every four new malware strains created were Trojans, followed by viruses (14.24 percent) and worms (8.13 percent).
The countries leading the list of most infections are once again Thailand, China and Taiwan, with 60, 56 and 52 percent of infected computers respectively. These are actually the only countries that exceed the worldwide average of 38.49 percent.
2011: The year of cyber-attacks, social media and cyber-war
The report offers a general view of the most important events regarding computer security in 2011. Sony suffered a massive breach that led to the theft of data belonging to 100 million user accounts in what is probably the largest-ever Internet security break-in, whereas the Steam video game service, used by 35 million people, was also compromised by hackers.
Social networking sites, mainly Facebook and Twitter, play a vital role in the life of Internet users and are extensively covered in the report. 2011 witnessed the launch of a new social media service in a bid to rival Facebook: Google+. Despite its rapid growth, with more than 25 million users registered in just few weeks, Google+ is still far away from its direct competitor, Facebook, which makes it less of a target for cyber-crooks.
Cyber-war also grabbed headlines in 2011. The number of cyber-attacks multiplied all over the world, affecting governments and government contractors -like weapons manufacturers- alike. Besides offering an overview of the most significant events in the computer security field, the 2011 Annual Security Report also forecasts future trends for 2012.
The full report is available at: http://press.pandasecurity.com/press-room/reports/. Visit the PandaLabs blog for more information about these and other threats: http://pandalabs.pandasecurity.com/
Thursday, January 26, 2012
Report Finds Spammers Abusing Holidays and Major Events
News release from Symantec:
Symantec Report Finds Spammers are Taking Advantage of New Year Holidays and Major Events
MOUNTAIN VIEW, Calif. – January 26, 2012 – January 26, 2012– Symantec Corp. (Nasdaq: SYMC) today announced the findings of its January Symantec Intelligence Report, which shows that spammers are using holidays and major events to make their mail more appealing.
Symantec Intelligence has seen more than 10,000 unique domain names compromised with a redirect script written in PHP that contains a reference to the New Year in the file name. These redirect scripts were hosted on compromised Web sites and links to these were included in spam emails, which were subsequently blocked by Symantec.cloud.
Click-to-Tweet: Symantec report finds spammers are taking advantage of New Year, holidays and major events: http://bit.ly/xzxecU
To further entice recipients to open their messages, spammers used additional social engineering techniques by including parameters in the URL to suggest that the destination is a social networking site.
Symantec Intelligence expects to see spammers taking advantage of other upcoming “calendar events” with one of the most important traditional Chinese New Year celebrations starting this week and continuing for several days, as well as the fast-approaching Valentine's Day.
“We also expect to see plenty of spam and malware taking advantage of some of the major upcoming sporting events this year. We are already seeing references to the Summer Olympics in London as part of 419 or advance fee fraud messages,” said Paul Wood, senior intelligence analyst, Symantec.
“By relating their mails to widely-celebrated holidays and current events with global interest, spammers and malware authors can (at first glance at least) make their messages more interesting, and increase the chance of recipients visiting spam Web sites or becoming infected,” Wood said.
During December, global spam levels dropped, but in January gradually returned to similar levels as in November 2011, which is still lower than the 2011 average.
Other Report Highlights:
Spam: In January 2012, the global ratio of spam in email traffic rose by 1.3 percentage points since December 2011, to 69.0 percent (1 in 1.45 emails). This follows a more noticeable drop in December when spam fell by 2.8 percentage points to 67.7 percent. The recent increase means that spam has almost returned to the same level as in November 2011.
Phishing: In January, the global phishing rate increased by 0.06 percentage points, taking the average to one in 370.0 emails (0.27 percent) that comprised some form of phishing attack.
Email-borne Threats: The global ratio of email-borne viruses in email traffic was one in 295.0 emails (0.33 percent) in January, a decrease of 0.02 percentage points since December 2011. In January, 29.0 percent of email-borne malware contained links to malicious Web sites, unchanged since December 2011.
Web-based Malware Threats: January saw an average of 2,102 Web sites each day harboring malware and other potentially unwanted programs including spyware and adware; a decrease of 77.4 percent since December 2011.
Endpoint Threats: The most frequently blocked malware for the last month was WS.Trojan.H. WS.Trojan.H is generic cloud-based heuristic detection for files that posses characteristics of an as yet unclassified threat. Files detected by this heuristic are deemed by Symantec to pose a risk to users and are therefore blocked from accessing the computer.
Geographical Trends:
Spam
Related
The Symantec Intelligence report combines the best research and analysis from the Symantec.cloud MessageLabs Intelligence Report and the Symantec State of Spam & Phishing Report. The new integrated report, the Symantec Intelligence Report, provides the latest analysis of cyber security threats, trends and insights from the Symantec Intelligence team concerning malware, spam, and other potentially harmful business risks. The data used to compile the analysis for this combined report includes data from December 2011 and January 2012.
About Symantec
Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.
Note to Editors: If you would like additional information on Symantec Corporation and its products, please visit the Symantec News Room at http://www.symantec.com/news. All prices noted are in U.S. dollars and are valid only in the United States.
Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners.
Symantec Intelligence has seen more than 10,000 unique domain names compromised with a redirect script written in PHP that contains a reference to the New Year in the file name. These redirect scripts were hosted on compromised Web sites and links to these were included in spam emails, which were subsequently blocked by Symantec.cloud.
Click-to-Tweet: Symantec report finds spammers are taking advantage of New Year, holidays and major events: http://bit.ly/xzxecU
To further entice recipients to open their messages, spammers used additional social engineering techniques by including parameters in the URL to suggest that the destination is a social networking site.
Symantec Intelligence expects to see spammers taking advantage of other upcoming “calendar events” with one of the most important traditional Chinese New Year celebrations starting this week and continuing for several days, as well as the fast-approaching Valentine's Day.
“We also expect to see plenty of spam and malware taking advantage of some of the major upcoming sporting events this year. We are already seeing references to the Summer Olympics in London as part of 419 or advance fee fraud messages,” said Paul Wood, senior intelligence analyst, Symantec.
“By relating their mails to widely-celebrated holidays and current events with global interest, spammers and malware authors can (at first glance at least) make their messages more interesting, and increase the chance of recipients visiting spam Web sites or becoming infected,” Wood said.
During December, global spam levels dropped, but in January gradually returned to similar levels as in November 2011, which is still lower than the 2011 average.
Other Report Highlights:
Spam: In January 2012, the global ratio of spam in email traffic rose by 1.3 percentage points since December 2011, to 69.0 percent (1 in 1.45 emails). This follows a more noticeable drop in December when spam fell by 2.8 percentage points to 67.7 percent. The recent increase means that spam has almost returned to the same level as in November 2011.
Phishing: In January, the global phishing rate increased by 0.06 percentage points, taking the average to one in 370.0 emails (0.27 percent) that comprised some form of phishing attack.
Email-borne Threats: The global ratio of email-borne viruses in email traffic was one in 295.0 emails (0.33 percent) in January, a decrease of 0.02 percentage points since December 2011. In January, 29.0 percent of email-borne malware contained links to malicious Web sites, unchanged since December 2011.
Web-based Malware Threats: January saw an average of 2,102 Web sites each day harboring malware and other potentially unwanted programs including spyware and adware; a decrease of 77.4 percent since December 2011.
Endpoint Threats: The most frequently blocked malware for the last month was WS.Trojan.H. WS.Trojan.H is generic cloud-based heuristic detection for files that posses characteristics of an as yet unclassified threat. Files detected by this heuristic are deemed by Symantec to pose a risk to users and are therefore blocked from accessing the computer.
Geographical Trends:
Spam
Phishing
- Saudi Arabia became the most spammed geography in January; with a spam rate of 75.5 percent.
- China was the second most-spammed with 75.0 percent of email traffic blocked as spam.
- In the US, 69.0 percent of email was spam and 68.7 percent in Canada.
- The spam level in the UK was 69.3 percent.
- In The Netherlands, spam accounted for 70.7 percent of email traffic, 68.2 percent in Germany, 69.1 percent in Denmark and 68.6 percent in Australia.
- In Hong Kong, 67.5 percent of email was blocked as spam and 66.7 percent in Singapore, compared with 65.6 percent in Japan.
- Spam accounted for 69.5 percent of email traffic in South Africa and 73.1 percent in Brazil.
E-mail-borne Threats
- The Netherlands became the country most targeted for phishing attacks in January, with one in 62.6 emails identified as phishing.
- The UK was the second most targeted country, with one in 179.4 emails identified as phishing attacks.
- Phishing levels for the US were one in 1,145 and one in 379.9 for Canada.
- In Germany phishing levels were one in 797.6, one in 330.9 in Denmark.
- In Australia, phishing activity accounted for one in 542.2 emails and one in 942.9 in Hong Kong; for Japan it was one in 5,692 and one in 1,156 for Singapore.
- In Brazil one in 1,007 emails was blocked as phishing.
Vertical Trends:
- The Netherlands had the highest ratio of malicious emails in January, with one in 61.4 emails identified as malicious.
- The UK had the second highest rate, with one in 169.1 emails identified as malicious.
- In South Africa, one in 305.9 emails was blocked as malicious.
- The virus rate for email-borne malware in the US was one in 592.5 and one in 285.4 in Canada.
- In Germany virus activity reached one in 471.7 and one in 318.1 in Denmark.
- In Australia, one in 327.9 emails was malicious.
- For Japan the rate was one in 1,573, compared with one in 482.9 in Singapore.
- In Brazil, one in 681.7 emails in contained malicious content.
Market Trends:
- The Education sector became the most spammed industry sector in January, with a spam rate of 71.0 percent.
- The spam rate for the Chemical & Pharmaceutical sector was 69.0 percent, compared with 68.7 percent for IT Services, 68.4 percent for Retail, 68.9 percent for Public Sector and 68.2 percent for Finance.
- The Public Sector remained the most targeted by phishing activity in January, with one in 99.1 emails comprising a phishing attack.
- Phishing levels for the Chemical & Pharmaceutical sector reached one in 838.0 and one in 647.8 for the IT Services sector, one in 529.4 for Retail, one in 169.4 for Education and one in 253.7 for Finance.
- With one in 90.2 emails being blocked as malicious, the Public Sector remained the most targeted industry in January.
- The virus rate for the Chemical & Pharmaceutical sector reached one in 381.3 and one in 399.4 for the IT Services sector; one in 407.1 for Retail, one in 138.3for Education and one in 236.7 for Finance.
The January Symantec Intelligence Report provides greater detail on all of the trends and figures noted above, as well as more detailed geographical and vertical trends.
- The spam rate for small to medium-sized businesses (1-250) was 68.9%, compared with 69.1% for large enterprises (2500+).
- Phishing attacks targeting small to medium-sized businesses (1-250) accounted for one in 225.2 emails, compared with one in 410.9 for large enterprises (2500+).
- Malicious email-borne attacks destined for small to medium-sized businesses (1-250) accounted for one in 277.3 emails, compared with one in 281.5 for large enterprises (2500+).
Related
Connect with Symantec
About Symantec Intelligence Report
The Symantec Intelligence report combines the best research and analysis from the Symantec.cloud MessageLabs Intelligence Report and the Symantec State of Spam & Phishing Report. The new integrated report, the Symantec Intelligence Report, provides the latest analysis of cyber security threats, trends and insights from the Symantec Intelligence team concerning malware, spam, and other potentially harmful business risks. The data used to compile the analysis for this combined report includes data from December 2011 and January 2012.
About Symantec
Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.
Note to Editors: If you would like additional information on Symantec Corporation and its products, please visit the Symantec News Room at http://www.symantec.com/news. All prices noted are in U.S. dollars and are valid only in the United States.
Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners.
Sunday, November 20, 2011
E-mail Scammers Target Businesses
From the FBI's website:
E-Mails Containing Malware Sent to Businesses Concerning Their Online Job Postings
01/19/2011—Recent FBI analysis reveals that cyber criminals engaging in ACH/wire transfer fraud have targeted businesses by responding via e-mail to employment opportunities posted online.
Recently, more than $150,000 was stolen from a U.S. business via unauthorized wire transfer as a result of an e-mail the business received that contained malware. The malware was embedded in an e-mail response to a job posting the business placed on an employment website and allowed the attacker to obtain the online banking credentials of the person who was authorized to conduct financial transactions within the company. The malicious actor changed the account settings to allow the sending of wire transfers, one to the Ukraine and two to domestic accounts. The malware was identified as a Bredolab variant, svrwsc.exe. This malware was connected to the ZeuS/Zbot Trojan, which is commonly used by cyber criminals to defraud U.S. businesses.
The FBI recommends that potential employers remain vigilant in opening the e-mails of prospective employees. Running a virus scan prior to opening any e-mail attachments may provide an added layer of security against this type of attack. The FBI also recommends that businesses use separate computer systems to conduct financial transactions.
For more information on this type of fraud and prevention tips, please refer to previous public service announcements at the links below:
- http://www.ic3.gov/media/2010/CorporateAccountTakeOver.pdf
- http://www.ic3.gov/media/2010/WorkAtHome.pdf
- http://www.ic3.gov/media/2009/091103.aspx
Subscribe to:
Posts (Atom)