I'm sure we've all noticed spam levels are slightly down, or that our spam filters seem to be working a little better. Nevertheless, spam continues to get through filters and for the next few weeks, a lot of it will have a holiday theme. Due to the sour economic situation, it's also likely going to take advantage of financial fears or the promise of a rescue from an already bad situation.
Since most unfortunate situations involving fraud, phishing, and financial misdeeds on the Internet start with a spam e-mail, it pays to use a little common sense and caution before falling for a too good to be true, or sometimes scary e-mail from an unknown source.
Last week, Symantec issued its December 2008 State of Spam Report. It predicts that although spam volumes are down after a lot of providers blocked access to sites hosted by McColo.com, we will likely see them rise again. Spam levels dropped a reported 65 percent after this happened. "McColo.com was allegedly hosting a significant number of botnet command-and-control systems'" according to the report. The bad news is that the report indicates the bad guys are moving elsewhere and that a number of them are hosting their efforts from IP addresses in (where else) China.
Getting back to the holiday season, the report notes that spammers are mimicking marketing come-ons from legitimate retailers offering holiday shopping deals. This makes it hard to distinguish exactly who is behind the e-mail. Sometimes the line between legitimate and illegitimate becomes a little blurry, which is something spammers have always taken advantage of.
The report also reveals a lot of links leading to malware infected sites in spam e-mails are using political themes to draw in their victims. Items related to Barack Obama are especially popular with spammers and scammers. In another twist to using Obama's good name, one spam campaign offered a Barack Obama coin, "a piece of history for only $9.95 plus shipping." This was an attempt to steal debit and credit card information.
Hot news stories were also used as lures to download malicious software. In particular, the recent Mumbai terrorist attacks pointed to links designed to infect machines. Ironically, a lot of this malware is designed to turn a computer into what is referred to as a "zombie," which when used in a botnet is used to send out even more spam.
While we haven't seen the holiday season pass, spammers of the scammer type are already using the IRS name to steal personal and financial information. The pre-tax season phishing scheme mentioned in the Symantec Report involved a come-on designed to snare people by telling them they had a tax refund or economic stimulus payment due to them. The link in these e-mails went to fake IRS site(s) — complete with offical logos — designed to steal personal and financial information.
The IRS isn't alone when it comes to having their good name spoofed. Just this week the FBI reported that their name was being used (yet again) in a campaign involving a typical Nigerian 419 scam. If an intended victim got leery after initially responding — they were threatened with "official consequences" should they fail to turn over the required personal and financial information.
Fear or scaring a victim into submitting to a scam is nothing new. In fact, some of it is now being referred to as Scareware. Scareware most frequently surfaces as a fake message claiming your computer is infected. In then offers to fix the problem for a nominal amount of money. My guess is that malware might actually be downloaded on a system by clicking on one of these come-ons.
Since it's hard to pay in cash over the Internet, anyone who pays on this form of extortion might have their method of payment stolen, also. Symantec recently released another report showing how many personal and financial details are for sale (super-cheap) on the Internet.
Alex Eckelberry of Sunbelt Software and the popular Sunbelt Blog just posted a visual presentation of scareware examples on his Flickr account.
There is little doubt that spam and its intended purposes have made the electronic world somewhat of a "virtual minefield" at times. It pays to make your computer bullet-proof by using good state of the art software from a legitimate vendor, but even if you are protected in this manner, you also need to protect yourself from social engineering schemes designed to lure a person into doing something they are going to regret later.
The Anti Phishing Working Group offers sage advice (from a variety of reputable sources) to the average person on how to avoid becoming a victim. Interestingly enough, they also recently released a report that is rather ominous stating the the number of crimeware spreading URLs are at an all-time high. Crimeware is another name for malware when it has a pure criminal intent.
To close this post, I'll point to a amusing video Symantec did on the 12 Days of Christmas Spam. It's probably best to end on a lighter note on what has become a serious problem.
Showing posts with label blog. Show all posts
Showing posts with label blog. Show all posts
Sunday, December 14, 2008
Friday, May 25, 2007
Google launches security awareness effort using the blogosphere
There is another effort to curb fraud, phishing and financial misdeeds in the blogosphere. This week, Google launched a blog called the "Google Online Security Blog," which is designed to protect their users from the sometimes dangerous (murky) waters on the Internet.
In their own words (from their first post):
They have also included a link to a paper, which studies this issue.
Since Google (as far as I know) isn't selling security software, the paper is well worth a read. This isn't to say that a lot of the papers published by security companies aren't relevant, it just means that Google's effort isn't designed to sell security software.
They also point out that most of the sites they investigated that download malware a.k.a. crimeware belong to webmasters, who don't know they've been hacked and are being used to compromise systems.
This post was written by Panayiotis Mavrommatis and Niels Provos of Google's Anti Malware team and includes a link to StopBadware.org. StopBadware.org has a lot of great tips on how to protect and avoid the growing phenomenon of malware (crimeware).
Google's Online Security Blog can be seen, here.
I look forward to seeing what else they come out with!
In their own words (from their first post):
Online security is an important topic for Google, our users, and anyone who uses the Internet. The related issues are complex and dynamic and we've been looking for a way to foster discussion on the topic and keep users informed. Thus, we've started this blog where we hope to periodically provide updates on recent trends, interesting findings, and efforts related to online security. Among the issues we'll tackle is malware, which is the subject of our inaugural post.In this post they discuss "drive by downloads," which install what I call "cybernasties" on systems, often designed to steal personal, or financial details. They point out that Google already warns users of malicious sites in their search results and that users can prevent these sites from loading using Google Desktop Search.
They have also included a link to a paper, which studies this issue.
Since Google (as far as I know) isn't selling security software, the paper is well worth a read. This isn't to say that a lot of the papers published by security companies aren't relevant, it just means that Google's effort isn't designed to sell security software.
They also point out that most of the sites they investigated that download malware a.k.a. crimeware belong to webmasters, who don't know they've been hacked and are being used to compromise systems.
This post was written by Panayiotis Mavrommatis and Niels Provos of Google's Anti Malware team and includes a link to StopBadware.org. StopBadware.org has a lot of great tips on how to protect and avoid the growing phenomenon of malware (crimeware).
Google's Online Security Blog can be seen, here.
I look forward to seeing what else they come out with!
Labels:
badware,
blog,
computer security,
crimeware,
cybernasties,
google,
malware,
stopbadware.org
Sunday, February 25, 2007
MyTruston, a privacy friendly identity theft prevention/recovery service based on trust

Tom Fragala, CEO of MyTruston (Identity Theft Prevention and Recovery Services) has created a service for identity theft victims, where they don't have to put all their personal information (which was used to steal money) on another database.
There must be a lot of people not buying some of the current services on the market. Out of 205 million active credit customers, less than 5 percent subscribe to a service. This tells me that a lot of people aren't buying some of the services out there, but still might benefit from one.
This makes a lot of sense, when databases seem to be compromised, weekly. The Privacy Rights Clearinghouse has ample evidence supporting this in their chronology of data breaches, here.
The concept behind MyTruston is that preventing identity theft should be free. People only have to pay (if and when) they become a victim, and only do so, while in the recovery process.
In a recent conversation with Tom, I asked him what would happen if someone suspended the service, and changed their mind, later. He told me that the system would retain all their information, and they could start all over (as if they never left). Since identity theft can (raise it's ugly head over and over again) when new fraudulent accounts are opened, this is a pretty customer friendly feature.
Most of the current identity theft services count on a person paying for them over a long period of time, whether they use it, or not. In fact, these services are probably betting on making a lot of money from people, who never use them.
Additionally, with most of these services, you aren't covered unless you've paid the up-front premiums.
With MyTruston, the prevention part is free, and if you need to recover; you'll spend a lot less money and do it the right way (the first time). For $19.99 a month, that's a pretty fair deal.
There must be a lot of people not buying some of the current services on the market. Out of 205 million active credit customers, less than 5 percent subscribe to a service. This tells me that a lot of people aren't buying some of the services out there, but still might benefit from one.
Studies indicate that 1 in 5 of us has been a victim of identity theft in the past five years. People need to be able to go somewhere, they can both trust and takes care of the problem at a reasonable price.
MyTruston delivers this, and the service was designed by someone (Tom Fragala), who had a personal experience with identity theft. Many of the key principles behind the service, were based on his experience (as well as) more than a 1000 hours helping other victims.
The service is easy to use (I tested it myself) and it walked me through each recovery step. A person can stop in the process anywhere, and it automatically reminds you where you left off.
Tom is currently working on developing protection for more sophisticated forms of identity theft, and plans to roll them out in the near future. These forms of identity theft, which sometimes aren't very apparent, have been the subject of a lot of speculation, recently.
Identity theft is a problem that isn't going to disappear very soon.
Given current trends, Thomas Harkin (former director of Mastercards fraud division) recently predicted the problem could grow as much as 20 times in a USA Today article. One of the reasons for this is only an estimated 6 out of a 100 criminals stealing people's identities ever get convicted.
You can take a look at MyTruston, here.
Tom is also a fellow blogger, and covers this subject (identity theft) on his blog. I read and link to what he says, frequently.
Sunday, February 18, 2007
Buying drugs on the Internet could be hazardous to your health
I normally write about Internet fraud, which is enabled (a lot) by spam e-mails attacking our in-boxes on a daily basis.
A lot of these spam e-mails are trying to sell drugs.
The FDA is now warning all of us that buying these drugs from questionable sources could be hazardous to your health.
This makes this issue more serious than losing a little money!
From their press release on the matter:
My advice is to anyone, who cares to listen, is get your prescriptions from your own doctor and fill them at your local pharmacy.
The FDA has a lot more material on how to avoid problems, such as this one, on their main website, here.
A lot of these spam e-mails are trying to sell drugs.
The FDA is now warning all of us that buying these drugs from questionable sources could be hazardous to your health.
This makes this issue more serious than losing a little money!
From their press release on the matter:
The Food and Drug Administration (FDA) has become aware that a number of Americans who placed orders for specific drug products over the Internet (Ambien, Xanax, Lexapro, and Ativan), instead received a product that, according to preliminary analysis, contains haloperidol, a powerful anti-psychotic drug.FDA press release, here.
Reports show several consumers in the United States have sought emergency medical treatment for symptoms such as difficulty in breathing, muscle spasms and muscle stiffness after ingesting the suspect product. Haloperidol can cause muscle stiffness and spasms, agitation, and sedation.
Therefore, the agency is reissuing its warning to consumers about the possible dangers of buying prescription drugs online. FDA urges consumers to review the FDA Web site for information before buying medication over the Internet.
My advice is to anyone, who cares to listen, is get your prescriptions from your own doctor and fill them at your local pharmacy.
The FDA has a lot more material on how to avoid problems, such as this one, on their main website, here.
Subscribe to:
Posts (Atom)
