Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

10/8/2012
05:20 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Solutionary Research Reveals Cybercriminals Frequently Use UPS, Better Business Bureau Names To Disguise Phishing Emails Used For Malware Attacks

New report provides insights into current malware trends

OMAHA, NE – October 4, 2012 – Solutionary, the leading pure-play managed security services provider (MSSP), announced today the release of the Q3 2012 SERT Quarterly Research Report, the first quarterly research report released by Solutionary's Security Engineering Research Team (SERT). The report provides insights into current malware trends and key tactics used by cybercriminals to execute malware distribution attacks. Research revealed that the UPS and Better Business Bureau (BBB) brands were among the most commonly used by cybercriminals to disguise malware-attack phishing emails, that 92% of all malware was mass distributed, and that anti-virus solutions were unable to detect 60% of malware in the wild.

"Cybercriminals constantly evolve malware and attack techniques to evade security and gain the most profit from their targets. Sixty percent of the mass-distributed malware we examined can easily slip past anti-virus software, and when that doesn't work, cybercriminals fool email recipients with phishing emails that inject malware into networks and computers at unprecedented rates," said Rob Kraus, director of SERT. "Most organizations simply don't have the internal resources needed to keep pace with modern malware attacks. To stay ahead of the threats, protect their brands and defend against breaches they need products, solutions and services that are focused purely on reducing security risks."

SERT research revealed that the majority of mass-distributed malware samples were banking Trojans, malware that uses man-in-the-browser keystroke logging to steal victim's bank account information so that it can later be used to make fraudulent charges. The most common method of delivery used for the banking Trojans was phishing emails claiming to be legitimate - such as UPS delivery confirmations, BBB complaints, flight ticket confirmations and scanned documents - that lured victims to compromised websites. Once infected, the victims' browsers were redirected, unbeknownst to them, to a Blackhole Exploit Kit landing page, which then installed additional malware, such as Zeus or Cridex.

"The malware types identified in our report impact enterprises, SMBs, government agencies and consumers," added Kraus. "They leave businesses exposed to data breaches, banks liable for millions in fraudulent charges, and consumers reeling from the impact of identity theft."

The last quarter also produced evidence of a new era in cyber espionage with the rise of advanced, modular toolkits. Flame, first discovered in May 2012, appears to have been written for espionage and has become the model for sophisticated attack toolkits. Gauss, the next toolkit to be identified, targets financial and social-media information for a specific area in the Middle East.

Late in the quarter two other trends were identified by SERT: new Zero-day exploits and increased attacks on the financial sector. The end of August brought the discovery of a Java Zero-day (CVE-2012-4681) in the wild. The exploit downloads a payload executable that resembles a Poison Ivy variant and acts as a remote access tool (RAT), allowing a remote "operator" to control a system. In September two more notably significant Zero-day vulnerabilities were observed, including one that affected Microsoft's Internet Explorer and another that had to do with Java's sandboxing mechanisms. There were also significant issues observed during the month of September regarding attacks against the financial sector. The first was financial transaction fraud conducted using malware, which in some cases was preempted or followed up by Distributed Denial of Service (DDoS) attacks. The other issue observed was DDoS attacks against a significant volume of banking websites, although these highly disruptive attacks appear to be driven by a hacktivist agenda rather than financial theft.

Key findings

· Ninety-two percent of malware analyzed during the quarter was mass distributed

· Nearly 60% of all malware goes undetected by common anti-virus software

· The majority of malware samples analyzed in Q3 were banking Trojans, with Cridex taking the lead at 91%

· Only 54% of the Cridex banking Trojan samples were detected by common anti-virus software at the time of analysis

· The Blackhole Exploit Kit continued to be the most popular exploit kit used by cybercriminals

To access a copy of the complete report, please visit http://www.solutionary.com/index/SERT/Quarterly-Threat-Report.php.

Visit our blog at http://blog.solutionary.com/.

Follow us on Twitter.

About Solutionary

Solutionary is the leading pure-play managed security services provider. Solutionary reduces the information security and compliance burden, delivering flexible managed security services that align with client goals, enhancing organizations' existing security program, infrastructure and personnel. The company's services are based on experienced security professionals, global threat intelligence from the Solutionary Security Engineering Research Team (SERT) and the patented, cloud-based ActiveGuard® service platform. Solutionary works as an extension of clients' internal teams, providing industry-leading customer service, patented technology, thought leadership, years of innovation and proprietary certifications that exceed industry standards. This client focus and dedication to customer service enables Solutionary to boast a client retention rate of over 98%. Solutionary provides 24/7 services to mid-market and global, enterprise clients through multiple security operations centers (SOCs) in North America. For more information, visit www.solutionary.com.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/22/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
Is Zero Trust the Best Answer to the COVID-19 Lockdown?
Dan Blum, Cybersecurity & Risk Management Strategist,  5/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13616
PUBLISHED: 2020-05-26
The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
CVE-2020-13614
PUBLISHED: 2020-05-26
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
CVE-2020-13615
PUBLISHED: 2020-05-26
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
CVE-2020-9046
PUBLISHED: 2020-05-26
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
CVE-2020-12388
PUBLISHED: 2020-05-26
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.