Phishers stir up ‘perfect crimeware storm’

Powered by SC Magazine

The Anti-Phishing Working Group (APWG) reported today that December last year provided conditions for “a near perfect crimeware storm”. The group’s latest research reveals that crimeware-distributing sites nearly doubled in number in the month of December 2005, hurtling from 1044 in November to 1912.

According to APWG, phishers had already built out the eCrime infrastructure for the holidays with the number of dedicated phishing sites jumping from 4630 to 7197. Meanwhile, the new WMF image-rendering vulnerability related to Windows Meta Files was being exploited by phishers to spread crimeware code that would install keyloggers and IRC-based administration tools on vulnerable Windows PCs.

APWG Chairman David Jevans said: "The speed, precision and massive scale by which the phishers were able to identify and exploit this vulnerability for criminal enterprise highlights the fact that the eCrime industry has reached a level of efficiency that has the potential to threaten the larger online economy."

APWG Secretary General Peter Cassidy added: "It's apparent while we reveled in holiday celebrations, we silently passed a grim new milestone."

The report also noted that December 2005 showed a "disturbing" trend of far more brands being spoofed than in any month on record. Over 120 brands were used in phishing attacks during the month. A large number of banks, credit unions and credit card associations were attacked. A larger number of European financial institution attacks were reported than in previous months.

APWG also reported receiving complaints of attacks against numerous ISPs, webmail providers and even P2P networks. It also noted numerous reports in December of a U.S. Internal Revenue Service phishing attack.

The December APWG report is informed by research contributed from analysts at Websense Security Labs, MarkMonitor and Panda Software. APWG members include national law enforcement agencies, global banks and financial institutions, national ISPs, ISVs, hardware vendors and e-commerce companies. The group, formed in 2003, has more than 2200 members worldwide from 1500 companies, government regulatory ministries and law enforcement agencies.

Copyright © SC Magazine, US edition

Top Stories
Westpac interim CIO resigns
Group CIO yet to be appointed.
Earning the right to innovate
Breaking down the barriers to innovation is a long, but rewarding process, says Bank of Queensland Group CIO, Julie Bale.
A call for timely reporting
[Blog post] Businesses need incentives to keep customer data secure.
Sign up to receive iTnews email bulletins
Latest Comments
What is delaying adoption of public cloud in your organisation?

   |   View results
Lock-in concerns
Application integration concerns
Security and compliance concerns
Unreliable network infrastructure
Data sovereignty concerns
Lack of stakeholder support
Protecting on-premise IT jobs
Difficulty transitioning CapEx budget into OpEx