Welcome | Sign In
LinuxInsider.com
Security

Report Shows Uptick in Automated Phishing

Print Version
E-Mail Article
Reprints
Report Shows Uptick in Automated Phishing

The APWG report indicated that the number of brands used for bogus phishing efforts -- eBay, PayPal, Microsoft and others -- is increasing. The report gave greater focus to the server side of phishing attacks, but indicated more company trademarks are likely to be used as the basis of fraud.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

Security experts are warning that automated software and compromised computers used to pass on malicious e-mail or host rogue, information-stealing Web sites are feeding fraud on the Internet.

The Anti-Phishing Working Group (APWG), a consortium of security experts looking to analyze the online fraud known as phishing -- whereby users are directed via e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse to malicious sites that steal personal and financial information -- highlighted the issue in a report this week.

The group reported "massive increases" in the number of sites used for phishing scams, adding that automation and an increasing number of compromised, broadband Internet connections are the likely cause of the rise.

Getting Smarter

While the group said "a new and powerful set of tools" recently deployed by attackers could explain the phishing increase, iDefense director of malicious code intelligence Ken Dunham told TechNewsWorld the problem is only now being fully recognized.

"Phishing is really a small component of a much bigger fraud picture," Dunham said. "(Internet) fraud has been on the increase for the last 18-24 months and the reason is that money is the motive. There's money to be made and the criminals have known about it for a long time."

Echoing the findings of the APWG -- which said attackers are using new software tools and so-called "Bot nets" of compromised computers to reach victims -- Dunham said the convergence of viruses and spamming was a troubling trend.

Year of Convergence

"2004 should be called the year of convergence, because we see technologies and techniques coming together for more successful attacks and fraud," he said.

Dunham added with the sophistication and stealth of backdoor Trojans and other malicious software, it is hard for PC users to know if they are being compromised or used in some kind of attack or fraud.

Message Labs senior antivirus technologist Alex Shipp -- whose company warned earlier this month of an automated phishing attack designed to capture online banking details when users opened an e-mail without requiring a link -- agreed that the attacks are simultaneously becoming more dangerous and inconspicuous.

While the automated phishing attack had limited reach and was generally seen as a "proof-of-concept" effort, it also laid the groundwork for attackers to improve the approach.

"This latest technique demonstrates how phishing attacks could become increasingly difficult for end users and online organizations alike to protect against," Shipp said. "By reducing the need for user intervention, the perpetrators are making it easier to dupe users into handing over the contents of their bank accounts."

Big Brands and Beyond

The APWG report, authored by Websense and Tumbleweed Communications (Nasdaq: TMWD), indicated that the number of brands used for bogus phishing efforts -- eBay (Nasdaq: EBAY), PayPal, Microsoft (Nasdaq: MSFT), and others for example -- is also increasing. The group said it gave greater focus to the server side of phishing attacks, but indicated more and more company trademarks are likely to be used as the basis of fraud.

Dunham agreed, telling TechNewsWorld that while the bigger-name companies are more likely to be used in phishing attacks, any company providing online services should expect a phishing attack with its brand in 2005.

"If there is money to be made there, other companies will be hit," Dunham said.

Trying to Net Phishing

Dunham, who indicated fraudsters are using "multi-staged, sequential attacks" and setting up larger numbers of phishing sites, said there is still a need to respond faster.

"We've got to figure out a way to shut down a hostile Web site faster and a way to identify them," he said.


Print Version E-Mail Article Reprints More by Jay Lyman


More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network