Feeds

Phishers and security firms in malware 'arms race'

Def Con

Providing a secure and efficient Helpdesk

Conventional phishing attacks launched via spam messages are becoming eclipsed by sophisticated malware designed to steal identities, according to a study by Anti-Phishing Working Group (APWG). APWG's July 2005 phishing reports adds that fraudsters are developing approaches specially designed to neutralise counter-phishing technologies.

APWG researchers reported a "marked increase" in screenscraper technology by phishers, an approach designed to counter graphical keyboard systems sometimes used by banks to thwart conventional key-logging Trojans. When a consumer selects a character on the graphical keyboard using mouse clicks, the screenscraper takes a snapshot of the screen and sends it to the phishers' server, in one example intercepted by the researchers. Despite the emergence of this more sophisticated technique keylogging Trojans remain a popular option. There were some 174 phishing-based Trojans detected in July, up from 154 in June. The majority of these Trojans lay in wait on sites hosted in either Brazil or the US.

"The technological contest between phisher and counter-phisher is well and truly underway," said APWG Chairman David Jevans. "It is a contest of escalation."

Around 14,135 unique phishing reports were recorded by APWG in July, down from 15,050 in June. In July 2005, 71 brands were reported as being phished, down from a high of 107 different brands being phished in May 2005. Financial institutions made up 86 per cent of all phishing targets, down slightly from a recent high of 91 per cent. And it's not just the big names that are targeted any more. Phishers are beginning to hit smaller financial institutions and ISPs.

APWG Secretary General Peter Cassidy, obviously a bit of a film buff, finds analogies in the contrasting roles of Jimmy Stewart in It's a Wonderful Life and Hitchcock's Rear Window to explain changes in phishing tactics. "Our hope was that as the large financial institutions gained expertise in thwarting and deflecting phishing attacks, phishers and their spam-based schemes would become ineffective as probabilities of landing phishing mails into inboxes of small institutions' customers decreased their intake of user credentials," he said.

"Instead, phishers have employed Internet marketing practices of list creation and affinity marketing to target and leverage the trust of small institutions. That is a significant part of the new play in the American context. The community thrift enjoys a special place in the American psyche and pantheon. Few other institutions have movies dedicated to them played every Christmas, starring a pre-Hitchcock Jimmy Stewart. Phishers are trying to use that trust now against them."

The Anti-Phishing Working Group (APWG) report on the latest trends in phishing fraud can be found here (PDF). ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Hackers thrash Bash Shellshock bug: World races to cover hole
Update your gear now to avoid early attacks hitting the web
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.