Printer Friendly
The Free Library
19,585,946 articles and books
Member login
User name  
Password 
 
Join us Forgot password?

Beware of Geeks Bearing Spam and the Expanding Phishing Net.


MessageLabs Intelligence Report Reveals Cyber-Criminals Speak a New Language and Phishing Pronounced "fishing," it is a scam to steal valuable information such as credit card and social security numbers, user IDs and passwords. Also known as "brand spoofing," an official-looking e-mail is sent to potential victims pretending to be from their ISP, bank or retail establishment.  Attacks Now Account For More than Half of All Malicious Emails

NEW YORK New York, state, United States
New York, Middle Atlantic state of the United States. It is bordered by Vermont, Massachusetts, Connecticut, and the Atlantic Ocean (E), New Jersey and Pennsylvania (S), Lakes Erie and Ontario and the Canadian province of
 -- MessageLabs, a leading provider of integrated messaging and web security services Security services are state institutions for the provision of intelligence, primarily of a strategic nature, but also including protective security intelligence. Examples include the Security Service (MI5) and the Secret Intelligence Service (MI6) in the United Kingdom, and the  to businesses worldwide, today announced the results of its MessageLabs Intelligence Report for September and the third quarter of 2006. In this expanded report, MessageLabs observed the adoption of new spam techniques to circumvent cir·cum·vent  
tr.v. cir·cum·vent·ed, cir·cum·vent·ing, cir·cum·vents
1. To surround (an enemy, for example); enclose or entrap.

2. To go around; bypass: circumvented the city.
 traditional IT security and the sharp increase in phishing attacks which accounted for more than half of all the malicious emails intercepted by MessageLabs in September.

In recent weeks MessageLabs has noticed an increase in the number of spam emails that are specifically targeting individuals within the technology sector by using social engineering techniques. Called "geek A technically oriented person. It has typically implied a "nerdy" or "weird" personality, someone with limited social skills who likes to tinker with scientific or high-tech projects. The origin of the term dates back to the late 1800s.  spam," this type of spam includes technology-related keywords within the email to dupe recipients into believing that the spam is actually something more relevant, such as a bug report. This targeted approach using hidden keywords can help to pollute pol·lute
v.
1. To make unfit for or harmful to living things, especially by the addition of waste matter; contaminate.

2. To make less suitable for an activity, especially by the introduction of unwanted factors.
 the Bayesian filters often used by technology professionals. The use of technology buzzwords Below is a list of common buzzwords which form part of the business jargon of Corporate work environments. General Conversation
  • Alignment []
  • At the end of the day [0]
  • Break through the clutter[1]
, such as .NET, cpan, xss and Java, hidden inside the body of the spam can ensure that the mail looks convincing enough for limited anti-spam software to allow it through.

"Cyber-criminals continue to seek new and more subversive means to launch their attacks. Geek spam is yet another way that the bad guys are evolving their methods and we expect to see an increase in other similarly targeted spam, such as accountants and by using financial terminology," said Mark Sunner, chief technology officer, MessageLabs. "When you couple this with the continuing escalation in phishing attacks and an augmented focus on banks who have not adopted new security technology, the end user is increasingly more exposed to complex and well engineered attacks."

MessageLabs research has also shown that phishing attacks continue to become more targeted as more criminal groups shift their attention from creating malware to conducting such attacks. The focus of these attacks has changed in recent months to banking organisations that have not deployed any two-factor authentication The use of two independent mechanisms for authentication; for example, requiring a smart card and a password. The combination is less likely to allow abuse than either component alone. See authentication.  security measures Noun 1. security measures - measures taken as a precaution against theft or espionage or sabotage etc.; "military security has been stepped up since the recent uprising"
security
. The unilateral approach undertaken by some banks has indirectly resulted in a huge increase in phishing attacks directed against those banks still investigating such technology. Banking organisations with this technology are still being attacked but on a much lesser scale. These increased attacks are perhaps a prelude to the imminent release of Microsoft Internet Explorer See Internet Explorer.  7.0, which will include additional anti-phishing countermeasures That form of military science that, by the employment of devices and/or techniques, has as its objective the impairment of the operational effectiveness of enemy activity. See also electronic warfare.  

Other report highlights:

Spam: the global ration ration

a fixed allowance of total feed for an animal for one day. Usually specifies the individual ingredients and their amounts and the amounts of the specific nutriments such as carbohydrate, fiber, individual minerals and vitamins.
 of spam this month is 64.4 percent, a diminutive di·min·u·tive  
adj.
1. Extremely small in size; tiny. See Synonyms at small.

2. Grammar Of or being a suffix that indicates smallness or, by semantic extension, qualities such as youth, familiarity, affection, or
 decrease of 0.1 percent from August. This is indicative that spam is not going away, and that concentrations are expected to increase again in coming months as spammers continue to adopt new techniques.

Viruses: virus and trojan traffic has been steadily declining since the beginning of the year and in Q3 2006 is much lower than for the same period in 2005. In September, the global ratio of email-borne viruses in email traffic from new and previously unknown bad sources destined des·tine  
tr.v. des·tined, des·tin·ing, des·tines
1. To determine beforehand; preordain: a foolish scheme destined to fail; a film destined to become a classic.

2.
 for valid recipients was 1 in 89.6 emails (1.12 percent), an increase of 0.1 percent since last month - still a large volume.

Bots: MessageLabs research indicates that bots are increasing in number and distribution, particularly in South American countries List of American countries

Nations:
  •  Antigua and Barbuda
  •  Bahamas
, where the use of bots to distribute bank trojans and phishing scams has now escalated to such a degree as to make them the new "419-scam" of the region.

Phishing: September showed a large increase of 0.27 percent in the proportion of phishing attacks compared with the previous month. One in 170 (0.59 percent) emails was some form of phishing attack. When judged as a proportion of all email-borne threats such as viruses and trojans, the number of phishing emails has risen by 21.7 percent, now accounting for 52.4 percent of all the malicious emails intercepted by MessageLabs in September.

Geographic Trends:

* Although levels dropped by 4.4 percent in September, Israel continues to be the world's top spam target with spam representing 73.6 percent of all email traffic.

* Of the top five spammed countries, Ireland suffered the largest increase with a jump of 1.7 percent to 64.2 percent. This trend was mirrored in the virus figures where, with a 1.2 percent increase, it received the largest increase in virus attacks with 1 in 26.2 being compromised.

* India continues to be the least spammed country with spam only representing 25 percent, a far cry from its position in Q3 2005 when it was the most violated country with a 81.69 percent spam rate.

* Australia was the least affected virus country in September with a drop of nearly one percent.

* Belgium was the second least affected virus country with 1 in 101.7 viruses during September.

Vertical Trends:

* The Education sector remained dominant at the top of the spam chart for the second month in a row with a spam rate of 62.9 percent. An increase of 11.1 percent represented the greatest increase within the top five sectors. It also received the highest increase in virus levels.

* The largest rise in spam was seen in the General Services sector (ranked 15th), which rose by 13.5 percent to 53.5 percent in September.

* The greatest decline in the top five sectors came in Recreation, where spam levels fell by 5.9 percent.

* For viruses, Business Support Services support services Psychology Non-health care-related ancillary services–eg, transportation, financial aid, support groups, homemaker services, respite services, and other services  remains the dominant focus of activity, with a higher ratio of viruses than other sectors, with traffic rising by 0.1 percent since August.

* Overall, the largest drop in virus rates came in the Building & Construction sector (ranked 16th), where levels fell by 5.9 percent to 1 in 101.5 in September.

The September/Q3 2006 MessageLabs Intelligence Report provides greater detail on all of the trends and figures noted above, as well as more detailed geographical and vertical trends. The full report is available at http://www.messagelabs.com/Threat_Watch/Intelligence_Reports.

MessageLabs Intelligence is a respected source of data and analysis for messaging security issues, trends and statistics. MessageLabs provides a range of information on global security threats based on live data feeds from our control towers around the world.

About MessageLabs

MessageLabs is a leading provider of integrated messaging and web security services, with over 14,000 clients ranging from small business to the Fortune 500 located in more than 80 countries. MessageLabs provides a range of managed security services to protect, control, encrypt and archive communications across Email, Web and Instant Messaging Exchanging text messages in real time between two or more people logged into a particular instant messaging (IM) service. Instant messaging is more interactive than e-mail because messages are sent immediately, whereas e-mail messages can be queued up in a mail server for seconds or .

These services are delivered by MessageLabs globally distributed infrastructure and supported 24/7 by security experts. This provides a convenient and cost-effective solution for managing and reducing risk and providing certainty in the exchange of business information. For more information, please visit www.messagelabs.com.
COPYRIGHT 2006 Business Wire
No portion of this article can be reproduced without the express written permission from the copyright holder.
Copyright 2006, Gale Group. All rights reserved. Gale Group is a Thomson Corporation Company.

 Reader Opinion

Title:

Comment:



 

Article Details
Printer friendly Cite/link Email Feedback
Publication:Business Wire
Date:Oct 2, 2006
Words:1142
Previous Article:Image Entertainment Sends New Letter to Stockholders Urging Re-Election of Current Board.
Next Article:Lakes Entertainment, Inc. Announces Shingle Springs Agreement with El Dorado County.
Topics:



Related Articles
Do-it-yourself phishing kits found on the internet.
Taking the bait.
2004: the security year reviewed, Sophos.
New holiday phishing seam.
Fighting e-mail fraud.
Hook, line and sinker: life insurers and their policyholders could be the next targets of online phishing scams.
EEMA to tackle cyber crime at UK Regional Interest group workshop.
Avoiding the 'phishing' hook: new online scares and virus attacks undermine your business.
Security news and products; Webwasher6.0 proactive anti-malware protection.
Security news and products; on the menu today is Phish and Spam.

Terms of use | Copyright © 2012 Farlex, Inc. | Feedback | For webmasters | Submit articles