Global web threats go local

By

The increasing sophistication of malware writers has been highlighted once again in a new report by web security firm McAfee.

Global web threats go local
The annual Global Threat Report found that internet criminals are now concentrating on configuring their attacks to specific geographic locations and languages to achieve greater success rates.

Spam and phishing emails for example are increasingly being written so that they appear in the native language of the recipient, while malicious web sites serve up malware in a language determined by the country the target is located in.

Criminals are also looking to exploit popular local applications such as banking web sites, crafting software which can determine specifically which user details need to be intercepted to ensure a successful attack, according to Toralv Dirro, McAfee Avert Labs Security strategist.

The report also drew attention to the exploitation of the user-generated content on many so-called web 2.0 sites such as Wikipedia and MySpace, to embed malicious code in these web pages.

"For the operators of these sites it would be a good idea to automatically convert pictures from one format to another to remove some of the exploits," he explained. "And for enterprises, if you allow your users to visit these sites you should make sure you filter not just email but http traffic."
Got a news tip for our journalists? Share it with us anonymously here.
itweek.co.uk @ 2010 Incisive Media
Tags:

Most Read Articles

Qantas facing 'significant' data theft after cyber attack

Qantas facing 'significant' data theft after cyber attack

Ex-student charged over Western Sydney University cyberattacks

Ex-student charged over Western Sydney University cyberattacks

Home Affairs officer accessed data on "friends and associates"

Home Affairs officer accessed data on "friends and associates"

SA Water plans 'once-in-a-generation' core technology uplift

SA Water plans 'once-in-a-generation' core technology uplift

Log In

  |  Forgot your password?