According to APWG, phishers had already built out the eCrime infrastructure for the holidays with the number of dedicated phishing sites jumping from 4630 to 7197. Meanwhile, the new WMF image-rendering vulnerability related to Windows Meta Files was being exploited by phishers to spread crimeware code that would install keyloggers and IRC-based administration tools on vulnerable Windows PCs.
APWG Chairman David Jevans said: "The speed, precision and massive scale by which the phishers were able to identify and exploit this vulnerability for criminal enterprise highlights the fact that the eCrime industry has reached a level of efficiency that has the potential to threaten the larger online economy."
APWG Secretary General Peter Cassidy added: "It's apparent while we reveled in holiday celebrations, we silently passed a grim new milestone."
The report also noted that December 2005 showed a "disturbing" trend of far more brands being spoofed than in any month on record. Over 120 brands were used in phishing attacks during the month. A large number of banks, credit unions and credit card associations were attacked. A larger number of European financial institution attacks were reported than in previous months.
APWG also reported receiving complaints of attacks against numerous ISPs, webmail providers and even P2P networks. It also noted numerous reports in December of a U.S. Internal Revenue Service phishing attack.
The December APWG report is informed by research contributed from analysts at Websense Security Labs, MarkMonitor and Panda Software.
APWG members include national law enforcement agencies, global banks and financial institutions, national ISPs, ISVs, hardware vendors and e-commerce companies. The group, formed in 2003, has more than 2200 members worldwide from 1500 companies, government regulatory ministries and law enforcement agencies.
Copyright © SC Magazine, US edition
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED GOES EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @itnews.com.au to your white-listed senders.