Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk //

Compliance

6/29/2009
12:13 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Report: Data-Stealing Malware Leads To Rise In Cybercrime, Cyberterrorism

In its first Focus Report, Trend Micro examines the growth of data-stealing malware, its characteristics, and its roots in the underground cyber crime economy

Cupertino, Calif. " June 29, 2009 " While the term "data-stealing malware" is a relatively new one, its sole purpose for existence is a familiar story: To steal proprietary information such as online banking credentials, credit card numbers, social security numbers, passwords, and more from compromised networks and PCs in order to fuel an underground cyber crime economy driven by profit-seeking criminal networks that cross geopolitical boundaries.

Trojans: The Rising Star in Data-Stealing Trojans are the fastest growing category of data-stealing malware, according to data from TrendLabs(SM), Trend Micro's global network of research, service, and support centers committed to constant threat surveillance and attack prevention. Trojan attacks pose a serious threat to computer security. True to their name, they typically arrive disguised as something benign such as a screen saver, game, or joke. Based on TrendLabs research:

  • In 2007, 52 percent of data-stealing malware were Trojans; in 2008, that number increased to 87 percent; as of Q1 2009, 93 percent of data-stealing malware were Trojans.
  • Trojans and Trojan spyware are the predominant type of data-stealing malware in all regions monitored by TrendLabs, including Australia, Asia, Africa, South America, North America and Europe.

    "As a threat category, data-stealing malware is experiencing tremendous growth because it serves the needs of financially motivated criminals who leverage the Internet for what it does best—provides valuable information," said Jamz Yaneza, threat research manager for Trend Micro.

    The Politics of Transnational Cyber Crime Politics and cyber crime have finally intersected in news headlines; understandably so: In the U.S. alone, the number of known breaches of government computers with malware more than doubled between 2006 and 2008, according to the Department of Homeland Security.[i]

    And, says Trend Micro advanced threat researcher Paul Ferguson, it is even possible that cyber terrorists may have already planted malware within the U.S. electrical grid that would allow them to remotely disrupt service.

    Cyber crime has gained significant international mobility. In 2007, Estonian computer networks were crippled when serious distributed denial of service (DDoS) attacks against government and civilian sites were reputedly linked back to Russian operatives. At the time, Russia and Estonia were involved in a dispute over the Estonians' removal of a Soviet war memorial. The French Embassy's web site in Beijing was inaccessible for several days after a full-scale cyber attack following President Nicolas Sarkozy's meeting with Tibetan spiritual leader, the Dalai Lama. Experts now widely believe instead that a Chinese hacking group staged the attack for nationalistic purposes.

    "Virtually anyone with a computer and Internet access can wreak havoc. In the U.S., hacker attacks have been documented on county or state government sites," said Ferguson. "Smaller organizations have a limited IT budget and few IT staff so they hire a third party to build a web site. Over time, the site fails to be maintained or upgraded, exposing vulnerabilities that hacktivists then leverage to express political views."

    Cyber espionage is also grabbing headlines. Every year, corporations suffer billions of dollars in intellectual property losses when trade secrets are illegally copied and sold to competitors on the black market for profit, or used for extortion. Business networks all over the world provide the perfect medium for cybercriminals capable of breaching their defenses.

    "Cybercriminals are using malware for financial gain and for geopolitical purposes," said Ferguson. "We have even seen data-stealing malware attacks against U.S. defense contractors—believed to be Chinese—launched to steal confidential trade secrets. However, it's hard to connect the dots back to the people really pulling the strings because of the anonymous nature of the Internet."

    Traditional Security is no Longer a Match for Cyber Criminals For years, security protections have been focused on protecting the endpoints—where most people access data. In today's multi-threat environment, a new strategy is needed. The Trend Micro Smart Protection Network enables a multilayered threat prevention approach that is built upon the concept of proactively blocking data-stealing malware in the Internet cloud before they can infiltrate a network.

    A correlated approach is used to address the tendency for cybercriminals today to launch multi-pronged, combined attacks composed of a number of different Web threats. Using correlation technology and behavioral analysis, the Smart Protection Network correlates combinations of threat activities to evaluate their potential for danger. It analyzes email, embedded links, file attachments, and hosted web files to identify new IPs, domains, URLs, and files that can be instantly added to reputation databases to quickly block new threats.

    By examining the relationships between and across different components, the Smart Protection Network provides a realistic view of potential threats to deliver a holistic, comprehensive view of the threat landscape.

    Data Protection Pack for "Insider" Threats A company's greatest asset " their employees " can also be their greatest security liability, especially by those who have access to data within a corporate network. Trend Micro offers solutions not just for external threats, but internal threats as well. The Data Protection Pack, which bundles together Trend Micro LeakProof Standard, Trend Micro Email Encryption Gateway and Trend Micro Message Archiver. The Data Protection Pack secures email and prevents the loss of sensitive data in use, in motion and at rest; it is available for Trend Micro NeatSuite Advanced and Client Server Messaging customers.

    For more information on the Trend Micro Smart Protection Network and the product and solutions it powers, visit: http://www.smartprotectionnetwork.com

    To read the full Data-Stealing Malware Focus Report, visit: http://us.trendmicro.com/imperia/md/content/us/pdf/threats/securitylibrary/data_stealing_malware_focus_report_-_june_2009.pdf

    Trend Micro continues to invest heavily in threat research and analysis. For a complete library of past threat reports, visit: http://us.trendmicro.com/us/threats/enterprise/security-library/white-paper-listing/index.html

    About Trend Micro: Trend Micro Incorporated, a global leader in Internet content security, focuses on securing the exchange of digital information for businesses and consumers. A pioneer and industry vanguard, Trend Micro is advancing integrated threat management technology to protect operational continuity, personal information, and property from malware, spam, data leaks and the newest Web threats. Visit TrendWatch at www.trendmicro.com/go/trendwatch to learn more about the latest threats. Trend Micro's flexible solutions, available in multiple form factors, are supported 24/7 by threat intelligence experts around the globe. Many of these solutions are powered by the Trend Micro Smart Protection Network, a next generation cloud-client content security infrastructure designed to protect customers from Web threats. A transnational company, with headquarters in Tokyo, Trend Micro's trusted security solutions are sold through its business partners worldwide. Please visit www.trendmicro.com.

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Why Cyber-Risk Is a C-Suite Issue
    Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
    Unreasonable Security Best Practices vs. Good Risk Management
    Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
    Breaches Are Inevitable, So Embrace the Chaos
    Ariel Zeitlin, Chief Technology Officer & Co-Founder, Guardicore,  11/13/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Current Issue
    Navigating the Deluge of Security Data
    In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
    Flash Poll
    New Best Practices for Secure App Development
    New Best Practices for Secure App Development
    The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-19010
    PUBLISHED: 2019-11-16
    Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
    CVE-2019-16761
    PUBLISHED: 2019-11-15
    A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the [email protected] npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0...
    CVE-2019-16762
    PUBLISHED: 2019-11-15
    A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. Affected users can upgrade to any...
    CVE-2019-13581
    PUBLISHED: 2019-11-15
    An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service or execute arbitrary ...
    CVE-2019-13582
    PUBLISHED: 2019-11-15
    An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitrary code execution.