Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Networking

    Microsoft Finds Phishing on Social Networks, Malware Attacks Increased

    Written by

    Fahmida Y. Rashid
    Published May 12, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Botnets continue to be the backbone of cyber-crime, with four of the top 10 threats in 2010 getting regular instructions from malicious command-and-control-servers, Microsoft said in a recent report. Phishing on social networks also became more prevalent in 2010.

      While the Taterf, Rimecud, Conficker and Renos worms continued to wreak havoc on user systems, attacks based on rogue security software, phishing scams on social networking sites and adware increased significantly, according to Microsoft’s latest version of the Security Intelligence Report released May 12. In SIR volume 10, Microsoft researchers examined security trends based on data collected from more than 600 million systems worldwide between July and December of 2010.

      There is a “polarization” of criminal behavior, the report found. There are two types of cyber-criminals, with one group going after large targets with sophisticated tools and the other camp relying on more “accessible” methods such as social engineering and other “marketing like” tricks or launching attacks based on toolkits and other exploits. The more skilled group looks for large payoffs while the less sophisticated attacks were interested in stealing small amounts from a large number of people, the report found.

      One of the reasons Microsoft puts out this report is to provide “actionable guidance” along with an overview of malware trends, Jeff Williams, principal group program manager with the Microsoft Malware Protection Center, told eWEEK.

      Phishing attacks on social networking platforms that trick users into giving up sensitive information or clicking on malicious links have sky-rocketed 1,200 percent. Phishing on social networking sites accounted for 84.5 percent of all phishing attacks in December, compared with a mere 8.3 percent at the beginning of 2010.

      Phishing attacks take advantage of the user’s tendency to trust content they think is from their friends. The criminals also get a higher return on investment targeting social networks because a handful of sites represent the majority of the users, Williams said. Phishing attempts are still concentrated on financial targets, which see between 78 and 91 percent of all phishing attacks each month.

      Adware surprisingly increased 70 percent globally during the second half of 2010, according to the report. In previous versions of the report, adware had been declining, according to Williams. The increase was caused by two new adware “families,” including ClickPotato, which displays pop-up and notification-style advertisements based on the user’s browsing habits, and Pornpop, with adult content pop-under ads.

      Pornpop appeared for the first time in the fourth quarter of 2010 and is one of the fastest spreading, according to Williams. Although ClickPotato had been around for awhile, it hadn’t been much of a threat. But in the second half of 2010, these two families were the two biggest sources of malware and accounted for nearly 25 percent of all the infections, Williams said.

      Rogue scareware, such as fake antivirus and other security software, has emerged as one of the most common methods to swindle money out of victims. The five largest software families accounted for 70 percent of the detections, according to Williams. FakeSpypro was the most commonly detected fake software up until third quarter 2010, when it practically disappeared. Then FakePAV emerged around the same time and became the most commonly detected scareware in the fourth quarter.

      It was possible the FakeSpypro gang had decided to switch tactics to work on FakePAV, Williams said.

      Java exploits broke into the list of top 10 threat families for the first time, with two different JRE exploits accounting for 9 percent of infections.

      The report highlighted some positive trends, including the continued decline in vulnerability disclosures, which dropped 16.5 percent from 2009 to 2010. The drop was probably the result of “better development practices and quality control” throughout the industry as well as better technology advancements in Windows 7, Williams said.

      In the previous report, four of the top 10 threats used the AutoRun worm, but the technological improvements in Windows 7 had pushed down Autorun malware as a threat, Williams said.

      Spam dropped from more than 90 billion unwanted messages blocked per month at the beginning of the reporting period to below 60 billion in December, according to the report.

      Organizations should protect its systems by actively updating its network and implementing strong information security policies to ensure all systems are properly patched and updated before getting on the network, Williams said.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.