Home > Security News > Phishing websites, rogue antivirus skyrocket in 2009
Security News:
EMAIL THIS

Phishing websites, rogue antivirus skyrocket in 2009

By Robert Westervelt, News Editor
01 Oct 2009 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Phishing websites and rogue antivirus programs increased precipitously in the first half of 2009, according to a new report issued by the Antiphishing Working Group.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

The number of unique phishing websites reached a high of nearly 50,000 in June, the second highest on record since more than 55,000 phishing websites were recorded in April, 2007. Meanwhile, the number of people downloading and installing rogue antivirus programs is also on the rise, providing a cash cow to cybercriminal gangs. In the first quarter of 2009 alone, more new strains of rouge antivirus were created than in all of 2008, according to the APWG Phishing Trends Report.

The organization, an industry association of security vendors, individual businesses and business trade associations, started in 2003 and has monitored phishing and email spoofing with the goal of finding ways to reduce and ultimately eliminate the problem. The report includes data collected by security vendors Websense Inc. and Panda Security, as well as brand jacking information from Mark Monitor Inc.
Rogueware, phishing:
Panda reports fast-spreading rogueware antivirus fraud rakes in millions: Rogueware fake antivirus strains are increasing at a stunning rate. Panda Security reports that this cyber crime bilks users out of about $34 million every month.

Can mutual authentication beat phishing or man-in-the-middle attacks? What's the best way to prevent phishing and man-in-the-middle attacks? IAM expert David Griffeth explains the benefits of mutual authentication over one-way SSL.

Phishing, identity theft keeps law enforcement, researchers occupied: An expert on cybercrime and online scams, Derek Manky, is one of the members of the Fortiguard research team

Rogue antivirus displays fake pop-up warnings and launches messages in the task bar warning of a possible infection. Once downloaded, the program typically conducts a fake scan of a victim's system and then provides results showing fake infections.

In June, the number variants of rogue antivirus programs increased above 152,000, according to the APWG. The number of rogue antivirus variants detected was four times as many samples as in all of 2008.

Luis Corrons, technical director of PandaLabs, the research arm of Panda Security, said the lucrative business model has attracted new cybercriminal gangs that are helping fuel the increase in rogue antivirus. Panda estimates that victims are shelling out $34 million per month worldwide for rogue antivirus programs. There are currently more than 200 different gangs being tracked by researchers. Ten gangs are responsible for more than 77% of the rogue antivirus samples, he said.

"Unlike with banking Trojans, where you have to infect the user, steal the data, then hire some money mule with rogueware they only have to wait for users to pay," Corrons said. "The user is the one willing to pay in order to disinfect their computer."
SearchSecurity radio:

According to security experts, the rogueware is not very sophisticated. Cybercriminals rely on website visitors to download and install the phony programs. Despite lacking sophistication it has been coded to successfully avoid detection by legitimate antivirus programs, according to the APWG report. Each downloaded rogue antivirus program contains a slightly different binary file, which tricks signature-based antivirus. In addition, Corrons said the programs themselves don't act maliciously on computers, other than displaying false information, which helps them evade detection from antivirus engines.

The number of rogue antivirus downloads increased more than 217% from Q1 to Q2 of 2009, from more than 133,000 detected infections to more than 423,000 detected infections. The increase could be attributed to the Zlob Trojan, which downloads and installs rogue antivirus software, Corrons said.

In addition, the APWG said the payment-services industry represented the favorite target of phishers, rising over the financial-services industry, which has been the coveted choice for most phishing attacks. Phishing campaigns directed at the payment-services industry rose 16% from the first quarter to the second quarter of 2009. Meanwhile, phishing campaigns directed at the financial-services industry dropped more than 10% during the same period, according to the report.

Tags: Email and Messaging Threats (spam, phishing, instant messaging)Web Application and Web 2.0 ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Email and Messaging Threats (spam, phishing, instant messaging)
Chinese hacker attacks target Google Gmail accounts, top tech firms
PDF attack code complicates security analysis, skirts detection
Panda warns of American Express phishing scam
Active PDF attacks target Reader, Acrobat zero-day vulnerability
Yahoo login credentials at risk to hijacking attack
The world's top 5 riskiest domains
How to secure a .pdf file
Top spammer gets four years in jail for stock fraud scheme
New Zeus spam poses as Social Security statements
Messaging security risks have upper hand on solutions
Email and Messaging Threats (spam, phishing, instant messaging) Research

Web Application and Web 2.0 Threats
Torrent phishing scheme trips up Twitter users
Browser exploit kit probe highlights need for patching, vigilance
Attackers continue barrage of SEO attacks
Self-defending Web applications thwart attacks
Facebook, McAfee partner to fix social network security issues
Facebook attacks prompt investments in social networking security
PDF attack code complicates security analysis, skirts detection
Adobe warns of critical Flash Media Server vulnerability
Firefox, Opera, Safari browsers top list of high risk software
FBI estimates rogue antivirus losses exceeding $150 million

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CAPTCHA  (SearchSecurity.com)
crimeware  (SearchSecurity.com)
Operation Phish Phry  (SearchSecurity.com)
pharming  (SearchSecurity.com)
phishing  (SearchSecurity.com)
Register of Known Spam Operations  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)
Sender Policy Framework  (SearchSecurity.com)
spam cocktail  (SearchSecurity.com)
spear phishing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts