Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Monday, December 10, 2007

Malware incidents double in 2007

EUROPEAN tech security specialist F-Secure has reported it has detected as many malware signatures during 2007 as it had in the entire preceding 20 years.

And the company is predicting a miserable 2008, with malware volumes continuing to increase as criminals successfully create a network-based underground ecosystem, trading malware development tools, skills, capabilities and resources.

F-Secure says in its 2007 Data Security Wrap-Up that it has identified a total about 500,000 malware signatures in its cumulative database – compared to 250,000 a year ago. The number of examples of malware had doubled in just one year.

“We've never seen as many samples arrive to our labs,” F-Secure Corporation Chief Research Officer Mikko Hypponen said.

“We would be unable to handle such huge samples loads if we would not have built a high degree of automation into our malware analysis systems over the past years,” he said.

The company said that while no truly new malware technologies were seen the existing ones were refined and adapted for much greater effectiveness.

Financial transactions remain a favorite target for network crime. The amount of phishing sites continues to increase, but as bank customers have become more aware of this threat the criminals have started employing more sophisticated techniques.

For more IT Security news, click here.

Monday, November 26, 2007

Symantec launches SmartPhone protection

US-based tech security specialist has rolled out a suite of consumer mobile security products that provides anti-virus, firewall and anti-spam protection for Windows Mobile and Symbian OS phone operating systems.

Symantec’s Norton Smartphone Security aims to give mobile device users the same level of security that has become standard for laptops and other computing devices.

“Smartphones are expanding consumer freedom to communicate and access important information anytime, anywhere,” said Symantec Consumer Business Unit senior vice-president Rowan Trollope said.

“However, unsecure public WiFi or network connections can put users at risk. In addition, web and e-mail viruses can directly infect smartphones, enabling hackers to remotely control the device, access sensitive information or disable applications,” he said.

“Norton Smartphone Security runs discreetly in the background, providing the confidence and peace of mind to engage in everyday activities like e-mailing, Web browsing or banking online from these handheld devices.”

As more users transact using their mobile devices, the financial incentives for virus writers and mobile hackers increase, Symantec says.

In a U.S. survey of smartphone users conducted by Applied Research, 34 per cent of respondents said they access their bank accounts via their mobile device and 54 per cent of respondents said they access web sites that require a password.

For more IT Security news, click here.

Monday, August 27, 2007

Sharp rise in global malware threat: Sophos

NEW figures compiled by security vendor Sophos’ global network of monitoring stations has found a further sharp rise in web-based virus threats – with 80 per cent of the threats located on hacked legitimate sites.

Sophos uncovered an average of 29,700 new infected web pages every day.

The research for June puts the Iframe malware as by far the most prevalent web-based threat, making up 64 per cent of all threats during the month.

Earlier this month, an Iframe attack on multiple Italian web sites occurred, making headlines around the world. More than 10,000 web pages were infected, most of which were on legitimate but compromised web sites hosted in Italy.

Victim web sites included Italian city councils, employment services and tourism sites. Most of the affected pages appear to be hosted by one of the largest ISPs in Italy.

“The Italian Iframe attack should certainly act as a wake-up call to ISPs across the globe,” said Sophos senior security consultant Carole Theriault.

“Malicious code dumped on these web sites is just waiting to pounce on innocent surfers. Web sites should be as secure as Fort Knox, but at the moment, too many web pages are easy pickings for cybercriminals,” Ms Theriault said.

Nearly 60 per cent of malware-infected web pages in June were hosted in China, while 24 per cent were hosted in the US.

For more Business Software news, click here.

Thursday, April 5, 2007

Patch offered for Windows cursor bug

MICROSOFT is expected to issue a patch outside of its routine monthly security update following the hacker activity focused on an exploit that targets the cursor animation files used in Windows.

The company issued a statement saying its monitoring of attacks found that customer impact had been “limited”, but said it would make a patch available outside of its usual security routines.

Microsoft said it had completed testing on the patch earlier than expected.

The Windows Animated Cursor Handling vulnerability – also known as the ANI exploit – was identified late last week.

“In order for the attack to be carried out, the user must either visit a Web site that contains a web page that is used to exploit the vulnerability, or view a specially-craft email message or email attachment sent to them by the attacker,” Microsoft said in a statement.

Tech security specialist F-Secure said the majority of the attacks could be traced back to different Chinese hacker groups.

“We’ve seen a lot of activity relating to the ANI exploit during the weekend,” F-Secure’s chief research officer Mikko Hypponen said.

“This vulnerability is really tempting for the bad guys. It's easy to modify the exploit, and it can be launched via web or email fairly easily. We hope to see Microsoft release a patch for this exploit very soon.”

Most of the activity around the ANI exploit has been via dozens of malicious websites that attack the user if they visit the page with the most common versions of Internet Explorer. However, on Sunday the first worm using the ANI exploit to spread was found.

For more IT Security news, click here.

Spam virus activity spikes in first quarter

DESPITE slowing marginally furing March, Spam levels increased more than 75 per cent during the first quarter to the highest levels in two years, according to managed security service provider MessageLabs.

MessageLabs Intelligence Report for March also found that it is small and medium sized businesses that are copping the worst of the spam problem, with SMBs receiving more than double the volume of spam compared to enterprise organisations.

Quarter on quarter, virus and botnet activity also increased, also with SMB wearing more than larger, better resourced organisations.

MessageLabs said SMBs were not targeted by spammers any more than large organisations, but were less likely to have defences in place to deal with the problem.

For small businesses, spam can very quickly become a silent killer, overwhelming the resources of the mail system before any effective countermeasures can be enforced, the report said.

“Today, spam is considered a side effect of email,” MessageLabs chief security analyst Mark Sunner said.

“The majority of small businesses view spam as an ongoing irritation rather than a real threat and have given up on dealing with the issue only to find that bad guys target them even more aggressively.

“If the first quarter data tells us anything, it’s that malicious activity in the form of spam will only continue on an upward trend,” Mr Sunner said.

Also in Q1 2007, MessageLabs saw virus and trojan traffic levels steadily decline from last year with rates of 1 in 126.1 emails. While the overall levels decreased, MessageLabs believes that virus and Trojan activity is actually on the rise with spammers delivering them disguised as spam.

Phishing activity accounted for 70.8 per cent of the malware threats this quarter, an increase of 8.6 per cent on the previous quarter.

For more Managed Service news, click here.

Friday, March 30, 2007

Warezov now targets Skype users

ROGUE net users have created a new variation of Warezov/Stration malicious code that is currently spreading through the Skype network, attacking Skype users’ machines, security specialists have warned.

WebSense Security Labs issued a warning that Skype users receive a message that says “Check this up”, with a URL containing a hyperlink.

Although the code itself is not self-propagating, when it runs, a URL is sent to all users within the user's contacts list.

When users click on the link, they are redirected to a site that is hosting an .exe file that users are prompted to click. WebSense notes that there is no vulnerability within Skype itself, but if the users runs the .exe file, several other files are automatically downloaded and run.

Once the computer is infected it can be accessed by the attacker and the Trojan will start propagating by sending the rogue message to everyone in the users contact list.

Skype has warned users against opening the malicious .exe file. The company said users should be careful before opening any attachment in general.

For more Net Working, VOIP Expo and IT Security news, click below.





Monday, February 26, 2007

Bogus email declares PM dead, infects computer

AN email widely circulating in Australia that links to a bogus news report claiming Prime Minister John Howard had suffered a heart attack is being used to spread a malicious computer virus, experts have warned.

Global security firm Sophos has issued a global warning to users to be wary of unsolicited emails posing as breaking news reports.

The comes after the widespread distribution of a message which claims Mr Howard was in Sydney’s Royal North Shore Hospital fighting for his life after a heart attack suffered at Kirribilli House.

The emails pretend to link to a story from The Australian newspaper. The bogus news story points to a web site containing malicious code.

Clicking on the link takes users to a web page which downloads malicious code into their PC, and then displays the real ‘404 page not found’ error page used by The Australian on the news.com.au site.

The Prime Minister is the latest in a long line of public figures to be used by malware authors and hackers. Politicians like George W Bush, Arnold Schwarenegger, Ronald Reagan and Bill Clinton have been used in the past.

“It seems the hackers are back to their old tricks of spamming out sensational headlines in the hope that computer users will forget to think before they click, and visit the website hosting the malignant code,” said Sophos senior technology consultant Graham Cluley.

For more IT Security news click here.