Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

1/20/2011
05:02 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Crimeware Toolkits Driving Most Online Malware

Symantec report connects the dots in rise in malware and easy-to-use crimeware kits

DIY crimeware kits are all the rage -- more than 60 percent of malicious websites use these toolkits to do their dirty work, while the other 40 percent are suspected of doing so, according to a new report from Symantec.

And while the kits aren't exactly point-and-click, they do lower the bar for less technical bad guys to get into cybercrime. "In the past, there were guys who were really good with computers that would engage in cybercrime. With these [crimeware] kits, we are seeing the reverse. You've now got guys who are criminals being able to move into the cybercrime field," says Marc Fossi, manager of development for security technology and response at Symantec, and author of the new "Symantec Report on Attack Kits and Malicious Websites," which analyzed a snapshot of attack data collected by Symantec tools between July 1, 2009, and June 30, 2010, to quantify the crimeware activity.

The kits historically helped computer-savvy bad guys become criminals, and now they are helping more seasoned criminals become cybercriminals, he says. "These kits are now far more accessible ... and are pretty easy to use," he says.

Symantec is seeing these kits more in use now than ever before. "Almost two-thirds of the activity on malicious websites could be [definitely] attributed to these kits," he says.

These easy-to-use and access crimeware kits are part of the reason cybercrime is on the rise: According to the report, the Zeus crimeware kit had 90,000 unique variants as of August 2009, and is suspected to be responsible for infecting millions of machines.

But the turning point for these kits was MPack, which was the first crimeware kit that was sold for profit, according to Fossi. "But one of the problems with it was it was done as a script. It's easy for people to copy scripts, change them a bit, and resell them as their own kit. So you saw a lot of kit piracy," he says.

New crimeware kits often come with anti-piracy features much like commercial software. "You can only install them on a limited number of domains," he says.

High-end kits are priced in the thousands of dollars, and often come with icon-driven interfaces, support contracts that include email support, bug fixes, and other services. "It's a very professional model," Fossi says. Just one Zeus ring in the U.S. made $70 million during an 18-month period, he says.

Symantec says most exploits incorporated into crimeware kits are not using zero-day bugs. "Exploits being included in these kits are tied to publicly available exploits," Fossi says.

The full report is available here for download.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27132
PUBLISHED: 2021-02-27
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
CVE-2021-25284
PUBLISHED: 2021-02-27
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
CVE-2021-3144
PUBLISHED: 2021-02-27
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
CVE-2021-3148
PUBLISHED: 2021-02-27
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
CVE-2021-3151
PUBLISHED: 2021-02-27
i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web script or HTML via C__MONITORING__CONFIG__TITLE, SM2__C__MONITORING__CONFIG__TITLE, C__MONITORING__CONFIG__PATH, SM2__C__MONITORING__CONFIG__PATH, C__M...