Saturday, May 19

Rise in Malware Threats

Malware danger and profitability rising

FBI reports show general increases in money-driven threats.

Two major new reports on computer security issues have shown a steady rise in just about every aspect of security risk, with increased danger from each vector in some way linked to financial motives.

According to Symantec's report on the threat landscape in the second half or last year, released last week, viruses, worms and trojans, exploitation of vulnerabilities, spam and phishing, spyware and data theft were all up on previous figures.

The report shows a decrease in volume of network worms, with a matching increase in the numbers of trojans seen, and also reckons that while half of the top ten malcode families are viruses and worms and half are trojans, the trojans have the edge in terms of potential to infect.

The US was again the major source of malware and spam, and although China has the lead in terms of machines infected with bots, most are controlled from the US, and the States is also home to most spam-sending bots.

Read more here

ID Data Theft by Trojan

Huge haul of ID data stolen by trojan

Smart Russian spyware gathered info 'unnoticed' for 54 days.

According to researchers at SecureWorks, a sophisticated trojan which spread through browser exploits, harvested sensitive data both from storage and by monitoring online activity, and uploaded this data to a server in St. Petersburg, went undetected by many AV products for over 50 days.

The trojan, dubbed 'Gozi' by researchers at SecureWorks, was first spotted by them in early January, and was apparently infecting users from early December 2006. A single seeding of one variant is thought to have infected over 5,000 individual machines and stolen data concerning over 10,000 accounts, netting credentials worth up to $2 million on the black market.

When first tested against 30 AV products, no specific identification was available, although several picked up on suspicious behaviour or the use of packers. By early February, several products were detecting the trojan under various names, while many more still had no detection at all.

Following up initial investigation into the behaviour of the trojan, SecureWorks researchers looked into the site storing the stolen data, and found the harvested information stored in a searchable format, which was then used to inform affected financial institutions, while attempts were made to have the server tracked and shut down.

Full analysis of the trojan, along with details of subsequent investigations into online data trading, can be found here.