Web attacks are financial boon for crooks, Cisco finds
From SC Magazine | 2009-12-09 11:05:10
<div id="subtitle">Spam and spyware still are profitable for cybercriminals, but the big money is in banking trojans and other web exploits, Cisco's annual security report has found.</div><div><p>Cybercriminals still are making large sums of money by pushing spyware and pharmaceutical spam, but internet fraudsters will leverage banking trojans and other web exploits, particularly on social networking sites, for far greater returns in the future, according to a new report from Cisco. Cisco's 2009 Annual Security Report, released Tuesday, details the top cybersecurity trends of 2009 and examines what is expected for 2010. Spyware, scareware and pharmaceutical spam have been the biggest moneymakers of the year for cybercriminals, the report finds. These tried-and-true methods will continue to remain prevalent because they are inexpensive for criminals to produce and yield a positive return on investment, Scott Olechowski, threat research manager, Cisco told SCMagazineUS.com on Tuesday.Cisco's report also identified baking trojans, such as the notorious Zeus trojan, along with web exploits, as the top “rising stars” in the cybercriminal arsenal. “Banking trojans, we know for a fact, are already producing incredible returns for criminals today,” Olechowski said. As a result, the best black-hat engineers are focusing their efforts on banking trojans, he said. This is evident in the sophistication of such threats, and the fact that the trojan's code is written to evade anti-virus protections. Banking sites, meanwhile, are being forced to respond with defenses of their own, Olechowski said. Some have implemented multifactor authentication, only accept transactions from known IP addresses and use machine fingerprinting technologies, which confirm the right machine and user are performing the intended action. “We have seen Zeus blow by all three of those things and a whole bunch of others,” Olechowski said. “The trojan can bypass all this stuff through some pretty clever engineering.” In addition, sophisticated scripting tools have allowed the cybercriminals behind Zeus to readily adapt it to new banking sites, Olechowski said.Also on the rise are web exploits. “We are seeing a lot of prepackaged kits that you can buy for a couple hundred to a thousand dollars that include a whole bunch of different techniques designed to compromise machines that are not patched,” Olechowski said. The pricier kits include exploits for zero-day vulnerabilities, he addedSome cybercriminals make money by selling the kits themselves, while others use the kits to infect PCs with malware and to establish a botnet, which they can rent out to other cybercriminals.“The answer to this threat is fairly straightforward: Users need to be vigilant about installing the latest versions of application software, such as Adobe Reader, since new versions will contain the latest security patches,” the report states. “In addition, updated anti-virus and firewall programs will provide protection against malware attached to these applications.”Threats on social networking sites, such as the Koobface worm, provide another huge potential for cybercriminals in the coming year, according to the report. “We are starting to see this real transformation from old IM [instant messaging] and phishing scams to leveraging trust and social networks to get people to perform actions that individuals would not perform otherwise and endanger themselves and their machines,” Olechowski said.</p><img src="http://admatch-syndication.mochila.com/images/ad.gif?aid=65085785&bid=informcom" /></div><div id="copyright"><div>
Copyright 2009 <a href="http://content.mochila.com/api/content/asset?assetID=2009-12-09:HaymarketMediaGroup/SCMagazines/Web_attacks_are_financial_boon_f-27496/&uname=mochila_api&cert=d1ff44fd2ac969664ae05bf7687cc5d1&bpid=informcom">SC Magazine</a></div></div>
Related Video by 5min
Related Articles
- Suncreen nanoparticles 'might be toxic' Marlborough Express, New Zealand | 2010-03-11 16:29:07
- Quantum Dots Spotlight DNA-Repair Proteins in Motion Science Daily | 2010-03-11 13:33:27
- Edmonton’s NAIT to offer nanotechnology Edmonton Journal, Canada | 2010-03-11 12:58:51
- Scavenging Energy Waste to Turn Water Into Hydrogen Fuel Science Daily | 2010-03-11 14:22:52
- Alberta companies delivering new products to the Conventional Energy marketplace Canadian Business Online | 2010-03-11 12:15:24
- GE, RPI, UAlbany land state energy grants Washington Business Journal | 2010-03-11 12:02:30
Related Blogs
- Quantum dots spotlight DNA-repair proteins in motion, says Pitt expert EurekAlert! | 2010-03-11 12:54:01
- Carbon Nanotube Speakers Could Be Powered by Lasers, Transform Noisy Spaces into Peaceful Sanctums PhysOrg.com | 2010-03-11 12:24:21
- U of Minnesota researcher discovers how electricity moves through cells EurekAlert! | 2010-03-11 16:51:48
- Quantum Computing Thrives on Chaos Wired: Wired Science | 2010-03-11 16:16:24