Advertisement
Promo

Security threats Toolkit

Criminals send malware levels soaring

Alice Lander and Graeme Wearden ZDNet.co.uk

Published: 04 Jul 2005 17:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security firm Sophos has seen a dramatic rise in the number of viruses, worms and Trojan horses this year as more organised criminals turn to cybercrime.

The firm reported last week that it had detected 7,944 new pieces of such malware in the first six months of this year — almost 60 percent more than the same time last year.

The biggest growth was in Trojan horses — programs that can damage a user's files, steal information, or even create a backdoor that can be used to compromise that PC.

Trojans cannot self-propagate in the same way as viruses, so they have typically been less prevalent. According to Sophos, their increased popularity shows the extent to which the creation of malware is increasingly becoming the preserve of professional criminals.

"There's been a shift towards Trojans to make money," said Graham Cluley, senior technology consultant at Sophos.

The IT security landscape has changed over recent months, with credit card fraud gangs, virus writing gangs, spammers and malicious hackers becoming more closely entwined, added Cluley.

One factor may be the anti-spam legislation that has been passed in many countries. Although these laws have been condemned as toothless in some quarters, Cluley claimed the legislation has helped to educate users to avoid unsolicited mail. As such, spammers have been forced to widen their activities.

2005 has seen several high-profile instances of businesses being hit by cybercrime. Back in March, it emerged that police had foiled an attempt to steal £220m from Sumitomo Mitsui Bank using keystroke loggers.

The top 10 viruses detected by Sophos so far this year all took advantage of flaws in Microsoft products, as virus writers target what Sophos calls "the great unwashed public".

But attacks directed at specific organisations could also take advantage of problems in other software, warned Cluley.

"We're also seeing vulnerabilities in Linux, Unix and Mac software too. No-one's perfect," he said.

Today's cybercrime gangs
Who are these mysterious organised criminals who have taken to writing viruses and launching cyberattacks? Cluley cited three gangs who he said epitomised the threat.

Superzonda
Superzonda have been known to be a threat for at least the last two years.

The BBC reported in July 2003 that Superzonda operated 24 hours a day, seven days a week, all over the world. Cluley said of them: "Until recently they were sending 50 million spams a day, but recent anti-spam legislation has reined them in."

The BBC also reported that Superzonda used British Airways without its knowledge to host a Web site advertising Russian mail order brides.

HangUp
HangUp, based in Russia, is suspected of writing viruses that steal financial information.

Reports claim that they plant software bugs to steal passwords, and rent out huge networks to send out viruses and spam. HangUp allegedly has 4,000 members operating worldwide, including Americans, Brazilians, Britons, Russians, and Spaniards.

ShadowCrew:
ShadowCrew were a massive underground network of criminals who bought and sold credit-card details, social security numbers and identification documents. They sold credit-card numbers, email accounts, passports, driver's licenses and student IDs, and were estimated to have caused over $4m (£2m) in losses for card issuers and banks.

However, the US Secret Service broke up the gang in 2004. Cluley said it was "great" that they had been smashed, but warned that "they are now fractured" so it could be hard to keep track of individual offenders.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
132 out of 289 people found this useful



Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters