Search This Blog

Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Saturday, March 31, 2012

Malware, Phishing Gather in North America

In its annual review of global security threats, Websense says a major trend it observed last year is that more malware connections, hosting and phishing appear to be occurring in the United States and Canada.

"50 percent of malware connections lead to the U.S.," says Charles Renert, vice president of Websense Security Labs. According to the 2012 Websense Threat Report, Canada's malware ranking has also zoomed upward in the past year, so the country now clocks in at No. 2 at 13.2 percent. The countries in the top five ranking include Germany at 5.4 percent, the Netherlands at 4.9 percent and China at 4.1 percent.
China and Russia used to be much bigger in the rankings, according to Websense, but since organizations have been more often blocking IP ranges for these countries, cybercriminals have turned to getting malware closer to their victims by exploiting trusted networks, such as social-networking sites. (See also "Best Security Suites: PC Bodyguards.")

For more, click the link below:


http://www.pcworld.com/article/252909/malware_phishing_gather_in_north_america.html#tk.nl_bdx_h_crawl

Thursday, March 22, 2012

IBM X-Force Report: 2011 Shows Progress Against Security Threats But Attackers Adapt

IBM X-Force Report: 2011 Shows Progress Against Security Threats But Attackers Adapt

Emerging Attack Trends include Mobile Exploits, Automated Password Guessing, a Surge in Phishing and Shell Command Injection Attacks


ARMONK, N.Y. - 22 Mar 2012: IBM [NYSE:IBM] today released the results of its X-Force 2011 Trend and Risk Report, which shows surprising improvements in several areas of Internet security such as a reduction in application security vulnerabilities, exploit code and spam. As a result, the report suggests attackers today are being forced to rethink their tactics by targeting more niche IT loopholes and emerging technologies such as social networks and mobile devices.
The X-Force 2011 Trend and Risk Report revealed a 50 percent decline in spam email compared to 2010; more diligent patching of security vulnerabilities by software vendors, with only 36 percent of software vulnerabilities remaining unpatched in 2011 compared to 43 percent in 2010; and higher quality of software application code, as seen in web-application vulnerabilities called cross site scripting half as likely to exist in clients’ software as they were four years ago.  
In light of these improvements, it seems attackers are adapting their techniques. The report uncovers a rise in emerging attack trends including mobile exploits, automated password guessing, and a surge in phishing attacks. An increase in automated shell command injection attacks against web servers may be a response to successful efforts to close off other kinds of web application vulnerabilities.  
The IBM X-Force 2011 Trend and Risk Report is based on intelligence gathered by one of the industry’s leading security research teams through its research of public vulnerability disclosures findings from more than 4,000 clients, and the monitoring and analysis of an average of 13 billion events daily in 2011. 
“In 2011, we’ve seen surprisingly good progress in the fight against attacks through the IT industry’s efforts to improve the quality of software,” said Tom Cross, manager of Threat Intelligence and Strategy for IBM X-Force. "In response, attackers continue to evolve their techniques to find new avenues into an organization. As long as attackers profit from cyber crime, organizations should remain diligent in prioritizing and addressing their vulnerabilities." 
According to the report, there are positive trends as it appears companies implemented better security practices in 2011:  
·         Thirty percent decline in the availability of exploit code – When security vulnerabilities are disclosed, exploit code is sometimes released that attackers can download and use to break into computers. Approximately 30 percent fewer exploits were released in 2011 than were seen on average over the past four years. This improvement can be attributed to architectural and procedural changes made by software developers that help make it more difficult for attackers to successfully exploit vulnerabilities.  
·         Decrease in unpatched security vulnerabilities – When security vulnerabilities are publicly disclosed, it is important that the responsible software vendor provide a patch or fix in a timely fashion. Some security vulnerabilities are never patched, but the percentage of unpatched vulnerabilities has been decreasing steadily over the past few years. In 2011 this number was down to 36 percent from 43 percent in 2010. 
·         Fifty percent reduction in cross site scripting (XSS) vulnerabilities due to improvements in software quality - The IBM X-Force team is seeing significant improvement in the quality of software produced by organizations that use tools like IBM AppScan OnDemand service to analyze, find, and fix vulnerabilities in their code.  IBM found XSS vulnerabilities are half as likely to exist in customers' software as they were four years ago. However, XSS vulnerabilities still appear in about 40 percent of the applications IBM scans. This is still high for something well understood and able to be addressed. 
·         Decline in spam – IBM’s global spam email monitoring network has seen about half the volume of spam email in 2011 that was seen in 2010. Some of this decline can be attributed to the take-down of several large spam botnets, which likely hindered spammers’ ability to send emails. The IBM X-Force team witnessed spam evolve through several generations over the past seven years as spam filtering technology has improved and spammers have adapted their techniques in order to successfully reach readers.  
Attackers Adapt Their Techniques in 2011
Even with these improvements, there has been a rise in new attack trends and an array of significant, widely reported external network and security breaches.  As malicious attackers become increasingly savvy, the IBM X-Force documented increases in three key areas of attack activity: 
·         Attacks targeting shell command injection vulnerabilities more than double - For years, SQL injection attacks against web applications have been a popular vector for attackers of all types. SQL injection vulnerabilities allow an attacker to manipulate the database behind a website. As progress has been made to close those vulnerabilities – the number of SQL injection vulnerabilities in publicly maintained web applications dropped by 46 percent in 2011– some attackers have now started to target shell command injection vulnerabilities instead. These vulnerabilities allow the attacker to execute commands directly on a web server. Shell command injection attacks rose by two to three times over the course of 2011. Web application developers should pay close attention to this increasingly popular attack vector.  
·         Spike in automated password guessing – Poor passwords and password policies have played a role in a number of high-profile breaches during 2011. There is also a lot of automated attack activity on the Internet in which attacks scan the net for systems with weak login passwords. IBM observed a large spike in this sort of password guessing activity directed at secure shell servers (SSH) in the later half of 2011.  
·         Increase in phishing attacks that impersonate social networking sites and mail parcel services – The volume of email attributed to phishing was relatively small over the course of 2010 and the first half of 2011, but phishing came back with a vengeance in the second half, reaching volumes that haven’t been seen since 2008. Many of these emails impersonate popular social networking sites and mail parcel services, and entice victims to click on links to web pages that may try to infect their PCs with malware. Some of this activity can also be attributed to advertising click fraud, where spammers use misleading emails to drive traffic to retail websites.  
Emerging Technologies Create New Avenues for Attacks
New technologies such as mobile and cloud computing continue to create challenges for enterprise security.  
·         Publicly released mobile exploits rise 19 percent in 2011 – This year’s IBM X-Force report focused on a number of emerging trends and best practices to manage the growing trend of “Bring your Own Device,” or BYOD, in the enterprise. IBM X-Force reported a 19 percent increase over the prior year in the number of exploits publicly released that can be used to target mobile devices. There are many mobile devices in consumers' hands that have unpatched vulnerabilities to publicly released exploits, creating an opportunity for attackers. IT managers should be prepared to address this growing risk. 
·         Attacks increasingly relate to social media - With the widespread adoption of social media platforms and social technologies, this area has become a target of attacker activity. IBM X-Force observed a surge in phishing emails impersonating social media sites. More sophisticated attackers have also taken notice. The amount of information people are offering in social networks about their personal and professional lives has begun to play a role in pre-attack intelligence gathering for the infiltration of public and private sector computing networks.  
·         Cloud computing presents new challenges - Cloud computing is moving rapidly from emerging to mainstream technology, and rapid growth is anticipated through the end of 2013. In 2011, there were many high profile cloud breaches affecting well-known organizations and large populations of their customers. IT security staff should carefully consider which workloads are sent to third-party cloud providers and what should be kept in-house due to the sensitivity of data. Cloud security requires foresight on the part of the customer as well as flexibility and skills on the part of the cloud provider. The IBM X-Force report notes that the most effective means for managing security in the cloud may be through Service Level Agreements (SLAs) because of the limited impact that an organization can realistically exercise over the cloud computing service. Therefore, careful consideration should be given to ownership, access management, governance and termination when crafting SLAs. The IBM X-Force report encourages cloud customers to take a lifecycle view of the cloud deployment and fully consider the impact to their overall information security posture.  
"Many cloud customers using a service worry about the security of the technology. Depending upon the type of cloud deployment, most, if not all, of the technology is outside of the customer's control,” said Ryan Berg, IBM Security Cloud Strategist. “They should focus on information security requirements of the data destined for the cloud, and through due diligence, make certain their cloud provider has the capability to adequately secure the workload."  
IBM continues to work with its clients to step up security to address these new areas. Recommendations for helping clients improve the security of their IT department in light of these new threats include: performing regular security assessments; segmenting sensitive systems and information; training end users about phishing and spear phishing and secure computing principals in general, as well as examining the policies of business partners.  
To view the full X-Force 2011 Trend and Risk Report and watch a highlight video please visitwww.ibm.com/security/xforce.     
About the IBM X-Force Trend and Risk Report
The IBM X-Force Trend and Risk Report is an annual assessment of the security landscape, designed to help clients better understand the latest security risks, and stay ahead of these threats. The report gathers facts from numerous intelligence sources, including its database of more than 50,000 computer security vulnerabilities, its global Web crawler and its international spam collectors, and the real-time monitoring of 13 billion events every day for nearly 4,000 clients in more than 130 countries. These 13-billion events monitored each day – more than 150,000 per second – are a result of the work done in IBM's nine global Security Operations Centers, which is provided as a managed security service to clients. 
About IBM Security
With more than 40 years of security development and innovation, IBM has breadth and depth in security research, products, services and consulting. IBM has nine worldwide research labs innovating security technology and nine security operations centers around the world to help global clients maintain an appropriate security posture. IBM Managed Security Services delivers the expertise, tools and infrastructure clients need to secure their information assets from constant Internet attacks, often at a fraction of the cost of in-house security resources. The Institute for Advanced Security is IBM’s global initiative the help organizations better understand and respond to the security threats to their business. Visit the Institute community atwww.instituteforadvancedsecurity.com 
For more information on IBM Security Solutions, please visit: www.ibm.com/security.

Tuesday, February 21, 2012

News Release from Panda Security

  1

One Bot To Rule Them All

  • The Ainslot.L bot scans computers and removes any other bots it finds
  • It spreads in a fake email purporting to come from UK clothing company CULT
  • The message is very well crafted to avoid raising suspicion
PandaLabs, the anti-malware laboratory of Panda Security –The Cloud Security Company– has reported on a new bot called Ainslot.L. This malware is designed to log user activities, download additional malware and take control of the system. Additionally, it acts as a banker Trojan, stealing log-in information related to banks. It also scans the computer looking for and removing other bots so that it becomes the only bot on the system.
“The fact that Ainslot.L removes other bots from infected systems definitely caught our attention”, explained Luis Corrons, technical director of PandaLabs. “It eliminates all competition, leaving the computer at its mercy. It reminds us of the popular ‘Highlander’ movies, – There can be only one –.”
It spreads in a fake email purporting to come from UK clothing company CULT. The message, which is very well crafted, informs users that they have placed a £200 order on CULT’s online store and the invoice amount will be charged to their credit card. The text includes a link to view the order which actually downloads the bot onto the computer.
According to Corrons, “Phishing emails are not usually so well done. There is no doubt that this time fraudsters have been very careful to try to make these messages look as real as possible to get as many bites as they can”.
More information is available in the PandaLabs Blog.

Thursday, January 26, 2012

Report Finds Spammers Abusing Holidays and Major Events

News release from Symantec:


Symantec Report Finds Spammers are Taking Advantage of New Year Holidays and Major Events

MOUNTAIN VIEW, Calif. – January 26, 2012 – January 26, 2012– Symantec Corp. (Nasdaq: SYMC) today announced the findings of its January Symantec Intelligence Report, which shows that spammers are using holidays and major events to make their mail more appealing.

Symantec Intelligence has seen more than 10,000 unique domain names compromised with a redirect script written in PHP that contains a reference to the New Year in the file name. These redirect scripts were hosted on compromised Web sites and links to these were included in spam emails, which were subsequently blocked by Symantec.cloud.

Click-to-Tweet: Symantec report finds spammers are taking advantage of New Year, holidays and major events: http://bit.ly/xzxecU

To further entice recipients to open their messages, spammers used additional social engineering techniques by including parameters in the URL to suggest that the destination is a social networking site.

Symantec Intelligence expects to see spammers taking advantage of other upcoming “calendar events” with one of the most important traditional Chinese New Year celebrations starting this week and continuing for several days, as well as the fast-approaching Valentine's Day.

“We also expect to see plenty of spam and malware taking advantage of some of the major upcoming sporting events this year. We are already seeing references to the Summer Olympics in London as part of 419 or advance fee fraud messages,” said Paul Wood, senior intelligence analyst, Symantec.

“By relating their mails to widely-celebrated holidays and current events with global interest, spammers and malware authors can (at first glance at least) make their messages more interesting, and increase the chance of recipients visiting spam Web sites or becoming infected,” Wood said.

During December, global spam levels dropped, but in January gradually returned to similar levels as in November 2011, which is still lower than the 2011 average.

Other Report Highlights:
Spam: In January 2012, the global ratio of spam in email traffic rose by 1.3 percentage points since December 2011, to 69.0 percent (1 in 1.45 emails). This follows a more noticeable drop in December when spam fell by 2.8 percentage points to 67.7 percent. The recent increase means that spam has almost returned to the same level as in November 2011.

Phishing: In January, the global phishing rate increased by 0.06 percentage points, taking the average to one in 370.0 emails (0.27 percent) that comprised some form of phishing attack.

Email-borne Threats: The global ratio of email-borne viruses in email traffic was one in 295.0 emails (0.33 percent) in January, a decrease of 0.02 percentage points since December 2011. In January, 29.0 percent of email-borne malware contained links to malicious Web sites, unchanged since December 2011.

Web-based Malware Threats: January saw an average of 2,102 Web sites each day harboring malware and other potentially unwanted programs including spyware and adware; a decrease of 77.4 percent since December 2011.

Endpoint Threats: The most frequently blocked malware for the last month was WS.Trojan.H. WS.Trojan.H is generic cloud-based heuristic detection for files that posses characteristics of an as yet unclassified threat. Files detected by this heuristic are deemed by Symantec to pose a risk to users and are therefore blocked from accessing the computer.

Geographical Trends:
Spam
  • Saudi Arabia became the most spammed geography in January; with a spam rate of 75.5 percent.
  • China was the second most-spammed with 75.0 percent of email traffic blocked as spam.
  • In the US, 69.0 percent of email was spam and 68.7 percent in Canada.
  • The spam level in the UK was 69.3 percent.
  • In The Netherlands, spam accounted for 70.7 percent of email traffic, 68.2 percent in Germany, 69.1 percent in Denmark and 68.6 percent in Australia.
  • In Hong Kong, 67.5 percent of email was blocked as spam and 66.7 percent in Singapore, compared with 65.6 percent in Japan.
  • Spam accounted for 69.5 percent of email traffic in South Africa and 73.1 percent in Brazil.
Phishing
  • The Netherlands became the country most targeted for phishing attacks in January, with one in 62.6 emails identified as phishing.
  • The UK was the second most targeted country, with one in 179.4 emails identified as phishing attacks.
  • Phishing levels for the US were one in 1,145 and one in 379.9 for Canada.
  • In Germany phishing levels were one in 797.6, one in 330.9 in Denmark.
  • In Australia, phishing activity accounted for one in 542.2 emails and one in 942.9 in Hong Kong; for Japan it was one in 5,692 and one in 1,156 for Singapore.
  • In Brazil one in 1,007 emails was blocked as phishing.
E-mail-borne Threats
  • The Netherlands had the highest ratio of malicious emails in January, with one in 61.4 emails identified as malicious.
  • The UK had the second highest rate, with one in 169.1 emails identified as malicious.
  • In South Africa, one in 305.9 emails was blocked as malicious.
  • The virus rate for email-borne malware in the US was one in 592.5 and one in 285.4 in Canada.
  • In Germany virus activity reached one in 471.7 and one in 318.1 in Denmark.
  • In Australia, one in 327.9 emails was malicious.
  • For Japan the rate was one in 1,573, compared with one in 482.9 in Singapore.
  • In Brazil, one in 681.7 emails in contained malicious content.
Vertical Trends:
  • The Education sector became the most spammed industry sector in January, with a spam rate of 71.0 percent.
  • The spam rate for the Chemical & Pharmaceutical sector was 69.0 percent, compared with 68.7 percent for IT Services, 68.4 percent for Retail, 68.9 percent for Public Sector and 68.2 percent for Finance.
  • The Public Sector remained the most targeted by phishing activity in January, with one in 99.1 emails comprising a phishing attack.
  • Phishing levels for the Chemical & Pharmaceutical sector reached one in 838.0 and one in 647.8 for the IT Services sector, one in 529.4 for Retail, one in 169.4 for Education and one in 253.7 for Finance.
  • With one in 90.2 emails being blocked as malicious, the Public Sector remained the most targeted industry in January.
  • The virus rate for the Chemical & Pharmaceutical sector reached one in 381.3 and one in 399.4 for the IT Services sector; one in 407.1 for Retail, one in 138.3for Education and one in 236.7 for Finance.
Market Trends:
  • The spam rate for small to medium-sized businesses (1-250) was 68.9%, compared with 69.1% for large enterprises (2500+).
  • Phishing attacks targeting small to medium-sized businesses (1-250) accounted for one in 225.2 emails, compared with one in 410.9 for large enterprises (2500+).
  • Malicious email-borne attacks destined for small to medium-sized businesses (1-250) accounted for one in 277.3 emails, compared with one in 281.5 for large enterprises (2500+).
The January Symantec Intelligence Report provides greater detail on all of the trends and figures noted above, as well as more detailed geographical and vertical trends.

Related
Connect with Symantec
About Symantec Intelligence Report
The Symantec Intelligence report combines the best research and analysis from the Symantec.cloud MessageLabs Intelligence Report and the Symantec State of Spam & Phishing Report. The new integrated report, the Symantec Intelligence Report, provides the latest analysis of cyber security threats, trends and insights from the Symantec Intelligence team concerning malware, spam, and other potentially harmful business risks. The data used to compile the analysis for this combined report includes data from December 2011 and January 2012.

About Symantec
Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.

Note to Editors: If you would like additional information on Symantec Corporation and its products, please visit the Symantec News Room at http://www.symantec.com/news. All prices noted are in U.S. dollars and are valid only in the United States.

Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners.