Home > Security News > Research shows smarter phishing
Security News:
EMAIL THIS

Research shows smarter phishing

By Bill Brenner, Senior News Writer
20 Apr 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Data from a series of recent reports suggest that phishing attacks have steadily grown more aggressive and sophisticated since the start of the year.

The volume of phishing e-mails hasn't grown significantly in recent months, said Paul Wood, senior analyst for New York-based MessageLabs Ltd. But he said the bad guys are findings ways to hit their targets more effectively.

In its March threat roundup, MessageLabs said phishing attacks accounted for 14.5% of all malicious e-mails it intercepted for the month. The company said one in 309 e-mails was a phishing attack. That may not seem like a lot, Wood said, but beyond the raw numbers are other indicators of a threat that's worsening.

As U.S. banks respond more aggressively to phishing threats with tighter security measures, Wood said attackers are simply going after more international banks that may not be as prepared for the threat. Though individuals are becoming more adept at identifying standard phishing e-mails that may appear to come from a bank or auction site they don't use, attackers are finding other ways to fool them. One way is to spoof sites that aren't necessarily tied to the financial sector.

"Phishing is up in South America because they have a lot of online banking down there," Wood said, "but there also tends to be a lot of e-cards that people send back and forth. It's big in the South American culture."

More on phishing

End of spam, phishing threats not far off

Hooked: Phishing is luring more and more of your customers

Keep attackers from phishing in your waters

SearchSecurity.com's e-mail security all-in-one guide

Users may not fall for a spoofed e-mail from a bank, he said, but if they fall for a spoofed e-card and are directed to a malicious site that way, attackers download malware that monitors the user's online activity. When the user visits a banking Web site, the malware strikes.

"The numbers haven't changed a lot at all," Wood said. "We see an upward trend in phishing attacks not in terms of volume and how many phishing e-mails are out there, but we see an increase in how sophisticated and how targeted the attacks are, with more sophisticated use of malware. The trend is that attackers will continue to devise phishing tricks that are a lot more difficult for banks and users to recognize."

Another report from RSA Cyota, a division of Bedford, Mass.-based RSA Security Inc., backed MessageLab's findings that an increasing number of phishing attacks are targeting banks outside the U.S.

The number of attacks on banks outside the U.S. climbed from 29% in February to 49% in March, RSA Cyota found. Most of the banks attacked for the first time were in Germany while Spanish and Italian banks were also targeted.

But while attacks in other countries are on the rise, RSA Cyota found that the U.S. still hosts almost 60% of all phishing attacks.

While companies like MessageLabs haven't seen a huge spike in the volume of phishing e-mails, other organizations have. The Anti-Phishing Working Group (APWG) -- an industry association that includes such members as San Francisco-based MarkMonitor Inc., Bilbao, Spain's Panda Software and San Diego-based Websense Inc. -- outlined a significant spike in phishing attacks in its most recent report (.pdf), which covered January.

According to the organization, January saw:

  • 17,877 unique phishing attacks;
  • 9,715 unique phishing Web sites; and
  • 101 brands hijacked by phishing campaigns.

    Of the phishing e-mails identified in January, 45% contained some form of target name in the URL; 30% included an IP address but no host name; the average time online for a phishing site was five days and the longest time online for a phishing site was 31 days.

    Financial services continued to be the most targeted industry, suffering 92% of all phishing attacks in January.

    Russian AV firm Kaspersky Lab, one of the organization's sponsors, tried putting the report in perspective on its Web site, noting that the 17,877 phishing attacks monitored in January was a new high. The previous record, the firm said, was 16,882 attacks in November 2005.

    "Another huge jump took place in the number of new unique phishing sites opened in January," Kaspersky said. "This time 9,715 sites were detected, representing a massive increase on the 7,197 sites found in December, and the previous record of 5,295 unique phishing sites reported in August 2005."

    Kaspersky attributed the continued increase in phishing attacks to the ability of attackers to launch malicious Web sites in a hurry. "Phishers … have mastered a quick rollout technology with pre-fabricated sites going up in extremely quick time," the company said.

    Tags: Email and Messaging Threats (spam, phishing, instant messaging)Security Awareness Training and Internal ThreatsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Email and Messaging Threats (spam, phishing, instant messaging)
    The world's top 5 riskiest domains
    How to secure a .pdf file
    Top spammer gets four years in jail for stock fraud scheme
    New Zeus spam poses as Social Security statements
    Messaging security risks have upper hand on solutions
    Web-based attacks skyrocket, pirating sites surge, security firms say
    Pushdo botnet uses Facebook to spread malicious email attachment
    Scareware report highlights successful business model
    How to prevent phishing attacks with social engineering tests
    Phishing protection begins with training, antiphishing evangelist
    Email and Messaging Threats (spam, phishing, instant messaging) Research

    Security Awareness Training and Internal Threats
    Health Net breach failure of security policy, technology
    Health Net healthcare data breach affects1.5 million
    Massive T-Mobile UK security breach involves insiders
    Secure your remote users in 2010
    Layoffs prompt insider threat fears, cybersecurity survey finds
    How to use Internet security threat reports
    Creating a HIPAA employee training program
    Successful rogue antivirus hinges on social engineering
    External attacks start with unintentional mistakes, survey finds
    Security technologies fail to address insider threat management

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    CAPTCHA  (SearchSecurity.com)
    crimeware  (SearchSecurity.com)
    Operation Phish Phry  (SearchSecurity.com)
    pharming  (SearchSecurity.com)
    phishing  (SearchSecurity.com)
    Register of Known Spam Operations  (SearchSecurity.com)
    Rock Phish  (SearchSecurity.com)
    Sender Policy Framework  (SearchSecurity.com)
    spam cocktail  (SearchSecurity.com)
    spear phishing  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts