Showing posts with label symantec. Show all posts
Showing posts with label symantec. Show all posts

Friday, April 17, 2009

Twin Reports Suggest We are Losing the Cybercrime War

According to Symantec, malicious activity in 2008 amounted to 60 percent of all the activity they have recorded since they started keeping records. Last year, they recorded 1.6 million new malicious code signatures and blocked 245 million malware attacks from their users every month.

Many of these attacks – when the words malware or malicious code are used – are designed to steal information (preferably financial) or take command and control of a computer. Once command and control of a computer is accomplished – it’s called a zombie and networked into a botnet. A botnet works as a super computer and is used to spam the electronic universe. Some of these spam e-mails contain even more malware, which infects more unprotected systems.

In 2008, Symantec saw a 31 percent increase in the number of zombie computers. In 2008, Symantec observed an average of more than 75,000 active bot-infected computers each day, a 31 percent increase from 2007. Symantec's latest report, which covers January to December of 2008, suggests that 90 percent of these attacks are designed to steal information. Attacks using key loggers – which log a computer's keystrokes and send them to the criminals who installed the malicious code – grew from 72 to 76 percent of the activity observed by Symantec's security lab.

Many of these attacks use a technique known as phishing, which is normally delivered in a spam e-mail. Phishing either tricks people into giving up their information (social engineering) or gets them to download malicious code, which makes the process automatic. Last year, Symantec detected 55,389 phishing website hosts, which is where you are sent if you click on a link in a phish-mail. Spoofed financial services companies accounted for 76 percent of these lures compared to 52 percent in 2007.

Spam, which delivers most of this activity, continued to grow, too. This equated to 349.6 billion spam messages in 2008 compared to 119.6 billion spam messages in 2007, which is a 192 percent increase. According to the monthly spam report from Symantec, last month's spam social engineering themes included mortgage rescue, tax season, terror and scareware (fake antivirus solutions) for the much anticipated Conficker worm that was designed to hit on April Fool's Day. Please note that Conficker a.k.a. Downdaup is still a problem, but it didn't spread it's gloom and doom on April 1st to the degree it was expected to.

Cybercriminals have always been quick to exploit the headlines and with the sour economy in the news have been targeting the financial industry. Here also, Symantec saw an increase of personal and financial information being stolen by using financial institutions as bait. In 2008, this amounted to 29 percent of the activity compared to 10 percent in 2007.

In their latest report, Symantec leveraged information from their recent Report on the Underground Economy which points to an organized criminal community that specializes in the sale of stolen personal and financial information. They noted that the economic principle of supply and demand has come into play with this underground economy due to a glut of stolen data – causing prices to go down.

Most of this stolen information is sold in electronic forums, such as websites and Internet Relay Chat (IRC) channels. These forums enable information to be sold worldwide and make the activity anonymous. Because the activity is anonymous, it is very difficult to investigate or shut-down. Credit cards go anywhere from less than a dollar to about $30 and bank account credentials sell for anywhere from $10 to $100. Much of the cost depends on the perceived value of information and the amount of it, which is purchased.



Symantec isn't the only one releasing a report showing an alarming increase information theft. Verizon just released a report showing that 285 million information records were compromised in 2008, alone. While the Symantec report focuses more on individual attacks, the Verizon report studies the impact large scale attacks on businesses and organizations. When combined, the information in these reports is pretty revealing.

According to the Verizon report, the 285 million records stolen are greater than what was known to be stolen in 2004 to 2007. I say "greater" because I've often speculated that the most valuable information stolen is the data no one knows has been stolen. After information is known to have been stolen, measures are taken to protect it. This makes it useless or at least a lot harder to use.

Recently, underground services have also popped up in these underground forums, which allow information thieves to see if the information they are buying hasn't been compromised (pun intended).

Verizon, who investigated 90 data breaches last year, noted that malware is now being designed to steal debit card and PIN information. The report also breaks down the point of compromise by industry and how the data was breached. For instance, in the past year 93 percent of the activity compromised was at financial institutions. Also cited was that most attacks were accomplished by external entities (73 percent) taking advantage of procedural flaws, but that when the breach was assisted by an insider (20 percent) more data was stolen.

The trend towards compromising debit cards and PINS is likely because these instruments are the quickest route to obtaining cash. Obtaining cash is normally the ultimate goal of an information thief and stolen debit card information accomplishes this with a minimum of effort.

Also covered are breaches caused by partners (32 percent), which are external entities providing services to a business. Please note these percentages add up to more than 100 percent, which means that multiple points of compromise can be attributed to any one incident in some cases.

Both reports are an excellent read and point to the fact that there is a glut of stolen information for sale on the black market, which isn't good news. The fact that more information is being stolen than ever before – even when security procedures are ramped up on a regular basis – is not good news, either.

Perhaps both of these reports suggest the obvious, which is we are not winning the war against cybercrime and the problem is getting worse. Historically, these losses have been written off and the cost is passed to the consumer. With the sour economy and the fact that a lot of the financial industry is already on the brink of bankruptcy, writing off these losses might no longer be a realistic solution.

The reason criminals can easily exploit this information is that we are storing it in too many places that are too easy to access. The reason this has happened is because a lot of people are making a lot of money by using and selling this information. Making the information easy to access makes it easier to make money from it. I'm all for making money, but at what point does it prove to be irresponsible?

No security fix is going to solve this problem without a healthy dose of common sense being infused into the scheme of things!

After all, the economy is already in a lot of trouble because of some of same people making a lot of money, irresponsibly. My guess is we are getting to the point, where we will no longer be able to write-off the cost of being irresponsible to the consumer, as well as, the taxpaying public.

Sunday, March 22, 2009

Symantec Indian Call Center Employee Selling Credit Card Details (Shocking)!

A story of an undercover investigation by the BBC shows how dishonest employees at call centers — who collect plastic payment card details on clients — might be making a little extra pocket change by selling them.

The focus of the BBC story is centered on an Indian call center employee for Symantec Security Corporation stealing payment card information. It is also centered on UK customers, which is understandable given it is the BBC, but the reality is that information is stolen then sold from countries all over the world.

Payment card details are handled by telephone at call centers in a lot of places and the calls come from all over, too. A lot of companies have different tiers (levels of personnel) handling calls, depending on the difficulty or nature of the call. At a lot of major companies, these tiers are located in different centers, which are in different countries. Any call might start in one country and, given the nature of the call, it could be transferred to another center located in another country. Given this, payment card information can be sent and then illicitly recorded over a fairly wide geographical area.

Besides that, dishonest employees are caught on a regular basis in a lot of different places. They don't all necessarily reside in India and call centers there are not the only place payment card information can be compromised. In fact, payment card information can be compromised anywhere (not just call centers) where they are used at a point of sale.

Information crooks are recruited and some think even planted anywhere financial information can be stolen. Even if they are not, payment card details are being bartered in forums on the Internet. It probably wouldn't be very hard to find a place to sell credit/debit card information when all it takes to do it is a click of a mouse.

The BBC story, which aired on video, chronicles an investigative effort by their reporters on the streets of Delhi. In the segment, it shows reporters making contact with the underground broker, who offers them payment card details from "all over the world" for $10-$12, each. It then shows a buy being made and money changing hands.

When the information was checked, it revealed that only one in seven card numbers were actually usable. They were able to trace some of the good numbers to a call center handling Symantec (Norton) products. The story stated that there has only been one successful prosecution in India for this type of crime and that it netted a non-custodial sentence. It also stated that the laws regarding the protection of data are not as stringent as they are in some places. The story mentions that Symantec's official comment was that it was an isolated incident and that the employee was removed.

Since one to seven card details turned out to be real, I guess we can assume the underground broker wasn't being completely honest. I've also seen reports of credit card details being sold for a lot less and you don't have to travel to India to find them.

In November, Symantec — the point of compromise in the story — issued a report on the underground economy, which focused on this very subject. "Credit cards are also typically sold in bulk, with lot sizes from as few as 50 credit cards to as many as 2,000. Common bulk amounts and rates observed by Symantec during this reporting period were 50 credit cards for $40 ($0.80 each), 200 credit cards for $150 ($0.75 each), and 2,000 credit cards for $200 ($0.10 each)," according to the report.

If this report is anywhere near accurate and the BBC was buying card details at $10-$12 each — if only one to seven was good in the Delhi exchange — the BBC was getting ripped off!

According to the 68-page report by Symantec, these details can be bought anywhere that has an Internet connection. Counterfeit instruments (ready to use) are often sent through the mail, too. The information is sold via IRC (Internet relay chat) channels in forums designed to market stolen financial information. Although credit/debit card details seem to dominate the scene, a lot of other information is sold that can be used to commit financial crimes and identity theft in these forums, too.

If you don't want to believe the Symantec report, the FBI took down one of these forums not very long ago. This forum known as Dark Market was responsible for about $70 million in fraud, worldwide. My best guess is that the information in the report is pretty accurate.

Although dishonest insiders are the cause of a portion of it, we should remember that hackers breaking into business systems, phishing, malicious software and even the trash can be sources of stolen information. The places targeted for information can be merchants, restaurants, goverment organizations, charity organizations, universities, medical facilities or anywhere payment card information is used at a point of sale.

Keeping up with all the points of compromise is difficult, but one place that attempts to is the DataLossDB site. Please note that the unknown data breaches are the most lucrative for the criminals behind this activity. Once a breach is discovered, measures are enacted to disable the stolen data.

It can be extremely difficult, if not impossible, to identify the point of compromise in most individual cases. The reason for this is there are too many different places where information might have been stolen from.

Maybe that's the problem, or we are storing and transmitting too much information all over the place? Since everyone is making money by transmitting information, I doubt this practice is going to stop anytime soon. So far as outsourcing, I doubt this is going to stop in the near term, either. Companies save a lot of payroll by outsourcing jobs. Payroll is a big expense for corporations and cutting payroll seems to be in vogue these days.

Nothing is going to change until laws are passed that force everyone making money from this information start doing the right things. This includes laws that prohibit people from being irresponsible (my opinion) to laws that punch the criminals stealing the information where it hurts.

Until then, the rest of us will have to batten down the hatches and weather the storm. I highly recommend making sure your information is protected as well as it can be (there are no guarantees) by protecting your own electronic transmissions. Monitoring financial activity — from your financial statements to information on your credit report and the Internet — is a good idea, too. Of course, while doing this, you need to ensure your electronic transmissions are protected by a reliable vendor and that you aren't paying for protection that you could get for free. Sadly enough, everyone claiming they can protect you isn't necessarily being completely honest, either.

Saturday, March 14, 2009

Downadup/Conficker Worm Disables Computer Security

If you were a hacker or a e-scam artist with malicious intent, would it be valuable to disable a machine's security system? Most of them find it relatively easy to take command and control of unprotected machines, but fully patched and protected machines pose more of a challenge.

Since late last year, hackers have developed a new tool that attacks protected machines, known as the Downadup/Conficker worm. This worm is being called a complex piece of malicious code that is able jump network hurdles, hide in the shadows and even defend itself against security measures, according to a recent report by Symantec.

Symantec has documented its blog posts on this subject in this report, which are available on their site. They also have a blog post by Ben Nahorney that attempts to put this complex threat into terms that can be understood by the general public.

Just this month, Symantec identified the third version of Downadup/Conficker, which has an even more powerful punch designed to take down computer security systems. This version has been dubbed the W32.Downadup.C variant and is still under analysis. The payload from W32.Downadup.C is set is to be triggered on April 1st, and if it is, the damage from it could be huge. SC Magazine aptly summed this up in an article called, "No Joke — Conficker Worm set to explode on April Fool's Day."

Since Downadup/Conficker has the ability to replicate itself — even on USB drives and network shares — by cracking passwords, it can spread like wildfire and wreak havoc on systems.
The report concludes that this is only the beginning of the Downadup/Conficker threat. If you take the time to read through the report, it shows how this malware is evolving and changing to avoid attempts to stop the spread of it.

It is being reported that Downadup Conficker has enabled one of the largest botnets to be formed on the Internet because of the number of systems that aren't protected from it. Of course, it appears that once infected, the worm itself might prevent the patches from be downloaded on a machine.

Botnets generate all the spam we see in our in boxes and are the vehicle of most fraud, phishing and financial misdeeds seen on the Internet. They consist of infected computers that have been taken over and form a super computer capable of spreading a lot of garbage. Of course, becoming infected can also mean that all your personal and financial information will be data-mined and used by less than honest people to steal money or commit other types of crimes.

Information can be stolen to commit espionage or even provide a fake identities, which are then used to support other more serious criminal activity. Although a lot of espionage is industrial, it is on record already that Downadup/Conficker infected computers at the U.K. Ministry of Defence and the Houston Municipal Courts which suggest a more sinister intent than merely committing financial crimes.

Since the beginning of the year, there are different estimates of how many computers are infected, but all them seem to agree it's somewhere around nine million.

Microsoft has announced a $250,000 reward for information leading to the arrest of the authors of this code. It has also announced an industry-wide coalition to fix the threat that Downadup/Conficker poses. Included in this coalition are ICANN, NeuStar, Symantec, CNNIC, Afilias, Public Internet Registry, Global Domains International Inc., M1D Global, AOL, Verisign, F-Secure, ISC, researchers from Georgia Tech, the Shadowserver Foundation, Arbor Networks and Support Intelligence.

Microsoft also provides information on patches and the latest developments on Conficker/Downadup on its site. It also has another page where you can learn more about these types of threats and how to stay safe online.

Monday, January 19, 2009

Fake Obama Site is a Malware Booby-Trap

Over the weekend, I got an e-mail from my Mom warning me not to open any e-mail with the title "Obama Acceptance Speech" because it contained a trojan. It even cited Snopes as stating that the threat wasn't a hoax. I sent her a reply referencing the last post on spam I did, which had a paragraph about Obama spam on it. My point was anyone who thinks there is only one e-mail of this type is out there is probably sadly mistaken.

On Sunday, with the inauguration less than 24 hours away, I got a hot tip that the Symantec Lab had detected another round of Obama spam with malicious intent being sent across the electronic universe. Zuftikar Ramzan announced on the Symantec Security Blog that this latest round of Obama spam uses lures with titles like "Our new president has gone," "Obama refused to be the president of the United States of America," and "There is no president in the USA anymore and Obama has gone."

Zuftikar also mentioned a link in these e-mails (removed for safety reasons) leading to a faux website that looks amazingly similar to the official Obama-Biden site. The fake site can be seen below:



This fake site attempts to exploit weaknesses in a Web browser to install malicious software without the owner's knowledge. According to Zuftikar, the page and its links all have malicious software on them. In other words, the entire site is literally a virtual booby trap.

The files are titled usa.exe, obamanew.exe, pdf.exe, statement.exe, barackblog.exe and barackspeech.exe. While the titles might be different, they lead to the same variety of malware known as the W32.Waledac. This malicious software is capable of stealing sensitive information, turning your machine into a spam-spewing zombie and leaving a back door for a hacker to gain access to it.

Political themes have been used a lot in recent times to lure people into clicking on links in spam e-mails they shouldn't have. Other common lures include the old fashioned too-good-to-be-true, security and badge-of-authority types (IRS, FBI, CIA, etc.).

With tax season upon us, expect the IRS to be a common one used in the near future.Symantec does provide removal instructions for this malware on their site, but most of us are far better off by not clicking on this type of stuff in the first place. These e-mails are sent out by the millions and the best thing to do is hit delete before opening them up.

Monday, January 05, 2009

Twitter Users (Including Barack and Britney) Hacked and Phished

The Phishermen (and probably a few women) are always looking for fresh waters to hook some unsuspecting phish — so it should be no surprise that Twitter is their latest target. After all, e-mail, cell phones, and Facebook have already been phished, along with countless desktops and laptops.

According to a Symantec blog post, Twitter users are receiving warning messages from Twitter command and control about this matter. The blog post by Marian Meritt, the Internet Safety Guru at Symantec, gives blogger Chris Pirillo credit for breaking the story on Saturday. According to the blog post at Symantec, the messages appear to come from someone you know at Twitter with a link to a malicious website designed to steal information.

Twitter also put up a warning on their blog. It starts with a Wikipedia definition of phishing and then details how the phishing attack will come in the form of an e-mail message notifying a person they have a Twitter Direct Message. Thus far, the social engineering lures being used in the e-mail go something like this: "Hey! check out this funny blog about you..." and direct the user to click on a link to a fake website.

They also point out that if you look at the URL you'll see that it is not the same as the URL for the normal landing page for Twitter. A trick to do this (without clicking on the link) is to hover your mouse pointer over the link. If you look at the bottom left portion of your page it will display the URL the link goes to. With all the malware people can get nowadays by just visiting (driving-by) a malicious page — this is a much safer way to go about it rather instead of actually clicking on the link to find it.



Twitter blog picture showing where to look for a suspicious URL

Authentic looking phishing sites aren't hard to create. Often the hacker merely copies the pictures of a legitimate site and puts them on a compromised (hacked) site so the activity can't be traced back to them. Hackers frequently seek out sites with poor security to compromise and put up their own (malicious) site.

Also contained in the blog entry are instructions on what to do if you've been phished. Basically, they direct you to their password reset tool and a legitimate e-mail will be sent to you so you can change your password.

Interestingly enough, Twitter also reported this morning that 33 prominent Twitter-ers were hacked over the weekend. Apparently, the notables included President-elect Obama, Rick Sanchez, and Britney Spears. According to Twitter, this attack has nothing to do with the phishing expedition into their waters. Apparently, someone hacked into some of the tools their support team uses to help people with their e-mail.

They also pointed out that Mr. Obama hasn't been twittering lately due to issues with the transition.

Sunday, December 14, 2008

Most Internet Scams Start with Spam

I'm sure we've all noticed spam levels are slightly down, or that our spam filters seem to be working a little better. Nevertheless, spam continues to get through filters and for the next few weeks, a lot of it will have a holiday theme. Due to the sour economic situation, it's also likely going to take advantage of financial fears or the promise of a rescue from an already bad situation.

Since most unfortunate situations involving fraud, phishing, and financial misdeeds on the Internet start with a spam e-mail, it pays to use a little common sense and caution before falling for a too good to be true, or sometimes scary e-mail from an unknown source.

Last week, Symantec issued its December 2008 State of Spam Report. It predicts that although spam volumes are down after a lot of providers blocked access to sites hosted by McColo.com, we will likely see them rise again. Spam levels dropped a reported 65 percent after this happened. "McColo.com was allegedly hosting a significant number of botnet command-and-control systems'" according to the report. The bad news is that the report indicates the bad guys are moving elsewhere and that a number of them are hosting their efforts from IP addresses in (where else) China.

Getting back to the holiday season, the report notes that spammers are mimicking marketing come-ons from legitimate retailers offering holiday shopping deals. This makes it hard to distinguish exactly who is behind the e-mail. Sometimes the line between legitimate and illegitimate becomes a little blurry, which is something spammers have always taken advantage of.

The report also reveals a lot of links leading to malware infected sites in spam e-mails are using political themes to draw in their victims. Items related to Barack Obama are especially popular with spammers and scammers. In another twist to using Obama's good name, one spam campaign offered a Barack Obama coin, "a piece of history for only $9.95 plus shipping." This was an attempt to steal debit and credit card information.

Hot news stories were also used as lures to download malicious software. In particular, the recent Mumbai terrorist attacks pointed to links designed to infect machines. Ironically, a lot of this malware is designed to turn a computer into what is referred to as a "zombie," which when used in a botnet is used to send out even more spam.

While we haven't seen the holiday season pass, spammers of the scammer type are already using the IRS name to steal personal and financial information. The pre-tax season phishing scheme mentioned in the Symantec Report involved a come-on designed to snare people by telling them they had a tax refund or economic stimulus payment due to them. The link in these e-mails went to fake IRS site(s) — complete with offical logos — designed to steal personal and financial information.

The IRS isn't alone when it comes to having their good name spoofed. Just this week the FBI reported that their name was being used (yet again) in a campaign involving a typical Nigerian 419 scam. If an intended victim got leery after initially responding — they were threatened with "official consequences" should they fail to turn over the required personal and financial information.

Fear or scaring a victim into submitting to a scam is nothing new. In fact, some of it is now being referred to as Scareware. Scareware most frequently surfaces as a fake message claiming your computer is infected. In then offers to fix the problem for a nominal amount of money. My guess is that malware might actually be downloaded on a system by clicking on one of these come-ons.

Since it's hard to pay in cash over the Internet, anyone who pays on this form of extortion might have their method of payment stolen, also. Symantec recently released another report showing how many personal and financial details are for sale (super-cheap) on the Internet.

Alex Eckelberry of Sunbelt Software and the popular Sunbelt Blog just posted a visual presentation of scareware examples on his Flickr account.

There is little doubt that spam and its intended purposes have made the electronic world somewhat of a "virtual minefield" at times. It pays to make your computer bullet-proof by using good state of the art software from a legitimate vendor, but even if you are protected in this manner, you also need to protect yourself from social engineering schemes designed to lure a person into doing something they are going to regret later.

The Anti Phishing Working Group offers sage advice (from a variety of reputable sources) to the average person on how to avoid becoming a victim. Interestingly enough, they also recently released a report that is rather ominous stating the the number of crimeware spreading URLs are at an all-time high. Crimeware is another name for malware when it has a pure criminal intent.

To close this post, I'll point to a amusing video Symantec did on the 12 Days of Christmas Spam. It's probably best to end on a lighter note on what has become a serious problem.

Wednesday, August 13, 2008

BlackHat Experts Predict the Hot Computer Security Topics for 2009

On the opening day of the BlackHat 2008 conference, Symantec did an anonymous survey of the attendees to discover exactly what they thought would be the hot security topics in the upcoming year.

While no one can predict the future, I found some of this fairly interesting.

The sample group consisted of IT managers, security researchers, and executives from several different industries,and of course, the government. The group surveyed could be considered International in nature, also. Experts from North America, Latin America and the Asia Pacific all voiced their opinions regarding what will become the hot security topics in the upcoming year.

Most surveyed seemed to believe that Web 2.0 and vitualization will be exploited frequently in the next year. In the post, I read about this by Zulfikar Ramzan, he mentions that Symantec has invested considerable resources in developing technology to prevent exploits in both these areas. He also mentions that Symantec is developing solutions to the increased dangers of what is known as drive-by pharming. In drive-by attacks, all a user has to do is visit a malicious site to be be infected.

Earlier this year, Zuftikar reported on one of the first sightings of drive-by pharming in the wild.

Another ongoing concern, especially with crimeservers being found in the wild with gigabytes of personal and financial information is the ongoing issue of data theft. Data theft is and will probably be the primary motive for most of the exploits out there. On a personal level, what scares me, is the increasing sophisitication of the attacks and the ever increasing amount of information compromised.

The respondents in the survey believe that most data will be stolen via insufficient access controls, laptops gone missing, data sent to third parties, and data being wrongfully posted to the Internet, intranet, and extranet.

Another new solution mentioned by the respondents is whitelisting. In simple terms, whitelisting is where a system is protected by only allowing approved sources to integrate with it. If a file or application isn't approved by the whitelist, it simply will not run.

Also mentioned in the Symantec post are what motivates researchers to examine and sometimes even develop malicious technology for research purposes. Some mentioned they need to do it to accomplish their jobs -- while others mentioned personal profit and even fame as their primary motivation. So far as developing malicious technology for research purposes, the post points out the danger that some of this research might accidentially be leaked into the wild.

A recent example of this occurred with DNS Cache Poisioning, which was covered in more detail at the conference by the person who discovered it, Dan Kaminsky. DNS Cache Poisoning allows an Internet bad guy (or gal) to redirect a user to a malicious site without their knowledge. Within days of the information being leaked, instructions (computer code) was put into a hacker tool called Metasploit. Metasploit is a controversial tool used both by researchers to work on exploits and by hackers to launch attacks.

The DNS Cache Poisoning exploit was made public prematurely. Kaminsky and a whole crew of experts had secretly been working on solutions to protect systems from the exploit before it was leaked. On Monday, the Register reported that large areas of the Internet remain at risk.

So far as platforms that are of the most concern, the respondents listed XP over Vista, which is a turn around from last year where the concerns were exactly the opposite. A speculation for this was cited as the industry being slow to adopt to the Vista platform.

With DNS Cache Poisoning and Gigabytes of personal information being found floating around the Internet, there is little doubt 2009 is going to be an interesting and challenging year for the BlackHat attendees. In my humble opinion, it all boils down to the fact that information is worth a lot of money that criminals and businesses alike see as a cash cow.

Maybe in 2009, we will take a look at what enables the problem in the first place? Until we do, I fear the problem will only continue to grow.

Sunday, May 11, 2008

Symantec May Spam Report reveals IRS e-mail leads to vampire game?

Symantec just released it's monthly spam report. I always find these reports a valuable tool to see exactly what trends the cybercriminal and less than ethical e-commerce communities have been up to in the past month.

Although most of us view spam as a major nuisance, the fact remains that spam is the preferred vehicle of marketing garbage and ripping off human beings on the Internet.

This month continues a nasty trend where spammers and phishermen (identity and information thieves) continue to manipulate Google's search engine:

For some time, spammers have used reputable brands to try and deliver spam and phishing messages to end-users. In the last year, Google has become a favorite target for some spammers. In November 2007, Symantec reported the emergence of a technique where spammers manipulated Google’s advanced search query and the “I’m feeling lucky” option to direct users to a spam site. In February 2008, Symantec reported that spammers had manipulated parameters in Google URLs used for AdSense and redirected unsuspecting end-users to a spam website. In April 2008 phishing emails purporting to come from the Google AdWords service have emerged. Google AdWords is a service that allows advertisers to intelligibly connect with individuals who search using Google. In the Google AdWords phishing samples that have emerged, the end-user is encouraged to click on a link to update their billing information and/or renew their account. The link in these phishing emails leads to a fraudulent website where personal information is requested and harvested.
Spear phishing, where specific people are targeted arrived in inboxes in the form of fake government subpoenas addressed to corporate executives. Also seen were come-ons to become a movie star, spam being sent in the form of instant messages and the 419 (Advance Fee) boys inserting calendar reminders in their spam to remind people send them their money.

While closely related to the long known use of job sites to gather information to commit identity theft, a new twist has been noted where professional networking sites are used for this purpose, also.

From the May report:

One of the side effects stemming from the growth of personal and professional networking sites is the increase in unsolicited emails that operate under the guise of connecting business professionals with their peers. The recipient is asked to join the “inner circle” and is encouraged to supply the network with their professional history by clicking on a URL which brings the user to a registration page. The page requests personal information that could be used for identity theft and could fuel future spam attacks.

In these monthly reports, Symantec normally has one twist with a particularly ghoulish or amusing angle. This month is no exception and they are reporting an IRS spam campaign that leads to a site where you can raise a vampire from the dead:

This time, instead of the refund link taking you to a site to steal your credentials, the link takes you to a popular web-based game in which you incarnate a vampire. The vampire gains more power every time end-users click on his link. It’s a rough, dark world out there… be warned.
I found this especially ironic because scammers and spammers are often referred to as ghouls or vampires when being described in literary terms. So far as the connection to all of this with the IRS, I'll leave that to the reader's imagination.

The IRS having their name spammed is nothing new. As predicted, there is an IRS spam (phishing) campaign going on right now using the tax stimulus program as a come-on to steal personal and financial information, which will probably be used to commit financial crimes. I'm predicting this might be a topic of interest on the June Spam Report.

The full report on the State of Spam for the month of May may be seen courtesy of Symantec, here.

Thursday, April 17, 2008

Symantec releases Internet Threat Security Report

Symantec recently issued it's Internet Security Report, which covers the second half of 2007. The key findings in the report are that malicious activity has become web based, attackers are going after end users rather than computers, the underground community is maturing and consolidating and the bad guys are getting better at improvising and adapting.

The report confirms that hacker tool kits are increasingly making it easier for less sophisticated types to effective commit technical crimes. Symantec also believes that these tool kits are being professionally developed, which supports the deduction that the underground community is maturing and consolidating.

Perhaps the availability of tool kits is the reason that a 559 percent increase in phishing websites has been noted?

The report also shows that the bad guys are going after "trusted" sites, such as social networking sites.

The underground economy in stolen financial details is also on the increase. These details, which are sold in Internet forums are getting cheaper. With all the phishing going on coupled with a record amount of data breaches an over abundant supply of stolen information is likely the reason for this. The report found a wide variety of pricing on payment card numbers, ranging from .40 cents to $20 per card.

The easy availability of encoders and other portable payment card technology makes it "too easy" to counterfeit the numbers into realistic looking plastic. In addition to this, there is a thriving market in counterfeit documents, which provides a wide-array of realistic counterfeit identification to vet the counterfeit financial instruments.

Besides identities and payment card details, stolen bank accounts are becoming increasingly available. Symantec attributes the increase in bank account information to a mirror increase in banking trojans over the second half of 2007.

Besides being used to clean out an account, bank account details are useful to criminals when they commit check fraud. Anyone, who follows scams on the Internet, knows that counterfeit checks are being delivered to unsuspecting mules to cash in a variety of advance fee (419) type scams. Please note there are organized gangs, who move from area to area committing check fraud using mules, who know exactly what they are doing, also.

Recently, an International task force monitored the mail and discovered large amounts of counterfeit checks being shipped throughout North America and the European Union.

All in all this report is a very interesting read. If you are a more visual type, Symantec also did a very nice flash presentation on this, which can be seen on the page linked to in the previous sentence.

Sunday, February 17, 2008

Hillary Clinton used as a spam lure to download malicious software

On Thursday, Kelly Conley reported a predicted spam lure (seen in the wild) using the 2008 elections on the Symantec blog:

It’s election year in the United States, everyone must be aware of that by now. We've just observed a Trojan being spammed out utilizing a candidate's name, Hillary Clinton, as bait. The email asks you to click a link to download an interview with her.

"If anyone clicked on the link they were actually downloading "a suspect file, "mpg.exe," which is a Trojan downloader. This downloader downloads a file, inst241.exe, which is detected as Trojan.Srizbi," according to Kelly.

This Trojan normally ends up turning your system into a spam spewing zombie, or part of a botnet.

Shortly thereafter, McAfee reported seeing the same thing. One of the spam e-mails circulating stated that Hillary had been shot right before the Virginia primary.

Fear is a common social engineering technique to lure someone into clicking on to something that they shouldn't. Sadaam Hussein's hanging and Benazir Bhutto's assasination were the two most recent examples of a lure like this being used in spam e-mails.

Gregg Keizer at Computer World did an interesting article on this, where he interviewed Oliver Friedrichs, director of Symantec's security response team. Oliver noted that the spammers might be a little wary of attracting too much attention from law enforcement with this type of activity. He did, however, note that it is still early in the game and attacks using the hurricane disasters a few years ago sparked a lot of activity.

Brian Krebs at Security Fix (Washington Post) also did a nice write-up on this story, where he interviewed Zulfikar Ramzam (Symantec), who gave a lot of insight into the technical aspects of this particular attack. Also noted in the Security Fix article was that the Trojan.Srizbi was used to spread malware using Ron Paul as the lure in October.

In the Computer World article, Oliver Friedrichs speculated:

A lot of money will be at stake. The campaign of Sen. Barack Obama (D-Ill.) raised $28 million online in January alone, according to news reports. That's a substantial amount of money. And clearly any sense of conscience or caution [on the part of hackers] might just go out the window.
Brian Krebbs ended his post with a thought in the same vein:

Coincidence? You decide. But at least the bad guys aren't singling out one particular political party over another. So far, we haven't seen malware attacks apparently designed to disrupt a U.S. election, but the potential for such activity certainly exists (political phishing, anyone?), particularly if candidates aren't taking precautions to ensure that their online fundraising systems can't easily be abused by credit card thieves.
Besides money, another thought to consider might be someone trying to do this to disrupt the election in general, or attack a particular candidate? Politics and or religious beliefs can cause the wrong person to do some pretty nasty things despite a strong possibility of getting caught (my humble opinion).

After all, both of these attacks seem to have originated outside the borders of the United States and it isn't unknown for foreign hackers to attack government systems.

Attacking a political campaign isn't too far a stretch from that type of activity.

Tuesday, February 05, 2008

Has the European Union become the primary point of origin for spam and scams?

Today, Kelley Conley (manager, Symantec Security Response) announced on their blog that the February State of Spam Report had been posted.

An interesting trend showing that the European Union was now the number one origin point for spam was noted:

The February State of Spam Report highlights an interesting trend in the shift of spam moving from North America to EMEA. The percentage of spam originating from EMEA has surpassed that of North America, which represents a significant shift in where the bulk of the world’s spam is “supposedly” sent from.
Well "supposedly," most of the spam is coming from the European Union. Here is the reason why:

Although it appears that way the very nature of spam distribution makes it difficult to accurately pinpoint the true geographic origin the sender. Spammers often take advantage of tricks that allow them to mask their real location and bypass DNS block lists.

Spam doesn't seem to be decreasing, either. January analysis by Symantec revealed that 78.5 percent of all e-mail sent is spam.

Other notable results from the report are that spammers a.k.a. scammers are busy taking advantage of a rumored tax rebate to steal people's identities and using Valentine's day deals to lure men to a dating site.

My guess is that we will see Valentine's day e-cards bearing malicious software pop up in the near future, also. Clicking on one of these normally turns your system into what I refer as a "spam spewing zombie." It's also a good way to have a keylogger implanted (dropped) on your system, which is capable of stealing all your personal and financial information.

Another persistent trend is spam offering too good to be true job offers, which entail tricking someone into laundering the proceeds of Internet crime. If anyone is considering getting involved in this activity, please be aware that I hear people are getting arrested after getting involved in one of these schemes.

Even when people don't get arrested, they end up being responsible for a LOT of money. Their identities are often used to commit more crimes without their permission, or immediate knowledge, also.

In case anyone wants more information on this, I've written a few "tidbits" about this type of scam (spam), which can linked to, here.

Spammers are also exploiting the global immigration issue by offering "too good to be true" offers of visa help in Europe. So far the targets are Russians and Ukrainians, but if this spam (scam) proves profitable, I'm sure it will be marketed (spammed), elsewhere.

Other notable trends noted in the report are new variations of porn scams, weight loss scams involving a promise to alter your genes and offers to turn a "ton of manure" into biofuel.

I found this especially ironic since it describes a great way to describe most spam, "manure." And if 78.5 percent of all e-mail being generated is spam, we are facing tons of "manure" on the Internet on a daily basis!

I guess that means that most spammers are full of "manure."

The full report, which I highly recommend reading can be seen, here.


(Picture courtesy of Josh Bancroft at Flickr)

Tuesday, January 22, 2008

Symantec reports sighting drive-by pharming in the wild



We hear a lot about phishing, but we don't see a whole lot written about pharming. According to a blog post on Symantec's blog by Zulfikar Ramzan, we might start seeing pharming mentioned a lot more than it has been in the past.

According to Zuftikar, the first instances of drive by pharming are being seen in the wild (on the Internet). This means a computer can be infected by merely viewing a e-mail, or website without clicking on a attachment, or link.

"Pharming (pronounced farming) is a Hacker's attack aiming to redirect a website's traffic to another, bogus website. Pharming can be conducted either by changing the hosts file on a victim’s computer or by exploitation of a vulnerability in DNS server software," according to Wikipedia.

In Zuftikar's own words:

In a previous blog entry posted almost a year ago, I talked about the concept of a drive-by pharming attack. With this sort of attack, all a victim would have to do to be susceptible is simply view the attacker’s malicious HTML or JavaScript code, which could be placed on a Web page or embedded in an email. The attacker’s malicious code could change the DNS server settings on the victim’s home broadband router (whether or not it’s a wireless router). From then on, all future DNS requests would be resolved by the attacker’s DNS server, which meant that the attacker effectively could control the victim’s Internet connection.

Here is a further description of the activity seen in the wild, which reveals how deceptive (not to mention deadly) this type of pharming attack could be:

In one real-life variant that we observed, the attackers embedded the malicious code inside an email that claimed it had an e-card waiting for you at the Web site gusanito.com. Unfortunately the email also contained an HTML IMG tag that resulted in an HTTP GET request being made to a router (the make of which is a popular router model in Mexico). The GET request modified the router’s DNS settings so that the URL for a popular Mexico-based banking site (as well as other related domains) would be mapped to an attacker’s Web site.

Now, anyone who subsequently tried to go to this particular banking Web site (one of the largest banks in Mexico) using the same computer would be directed to the attacker’s site instead. Anyone who transacted with this rogue site would have their credentials stolen.
Please note that many users fail to change preset (factory) passwords, which leaves hardware vulnerable to being compromised. These preset passwords aren't very difficult for those with malicious intent to get their greedy paws on. I've even run into preset passwords on technical manuals posted on the Internet.

What is SCARY in this instance is that the specific router targeted in this attack didn't need a password to compromise the system.

Quite simply, the router didn't authenticate the request.

The malicious code which makes this attack possible can be inserted on the inside of a e-mail message, or directly off a web page. It isn't necessary to click on something to start the execution (pardon the pun) process.

Once this occurs, the hacker controls your router and can send you anywhere they want to.

Zuftikar offers a lot of sound recommendations on how to protect yourself from pharming attacks.

Note that he still recommends changing the factory preset passwords on any router you might own. The problem in the instance observed occurred with a particular type (brand) of router.

To view these recommendations, I recommend you read his interesting post, which can be seen, here.

Saturday, January 19, 2008

January Symantec Report reveals questionable blogs, polls and Nigerian Scam restitution schemes

If you ever want to know what criminals and other misfits are up to on the Internet, watching spam traffic can reveal a few clues.

After all, spam is the vehicle most cybercriminals use to pass along whatever scheme they are behind designed to part people with their hard-earned money.

Symantec noted in December that close to 75 percent of all e-mail being sent is spam.

A little over a week ago, they issued their January report, which showed spam levels peaking towards the end of December to 83 percent.

Highlights noted in the January report are:

Holiday Spam Spikes: Spam levels reached new levels as spammers inserted holiday-oriented keywords into everything from subject lines to images.

Spammers Get Honest? Not So Fast: Spammers tried a new twist on an old scam, falsely promising past spam victims restitution of $100,000.

As Oil Prices Hike, Spammers Strike: This new spam claims to identify gas stations that fraudulently tamper with pump prices.

Not-So-Happy New Year: Recipients were invited to download a fun New Year’s song and dance, but instead found themselves downloading something far more malicious.

Presidential Polling Scam: Promising gift cards in exchange for opinions, spammers leverage the US presidential primaries to collect personal information.

Beware of Blogs: The use of blogs within spams appears to be on the rise, particularly in China where simplified character sets are common.
I found the 419 restitution activity interesting. In case you've never heard the term "419," it is the penal code in Nigeria for the infamous Advance Fee scam.

Here is what the report said:

419 spammers who have traditionally used stories about African dictators to defraud individuals have recently changed their approach to these types of emails. Certain 419 scams observed by Symantec this month claim to offer compensation to victims of 419 scams. The scam states that payments will be supervised by UN officials and about 150 scam victims will be paid compensation of $100,000 each. It provides some URL links as a reference to money that was successfully recovered by 419 scam victims. At the bottom of the email, it explains how the money may be recovered and the fraudulent background of such emails may be observed.

Interestingly enough, the Economic and Financial Crimes Commission (EFCC)of Nigeria has made real victims whole with funds seized from 419 scammers. You can see some real examples of this on their site.

The most recent time, I've mentioned the EFCC on this blog is when they were part of an International task force that intercepted large quantities of counterfeit checks at post offices in several countries. These counterfeit checks are normally used in advance fee scams, where people are tricked into cashing them and wiring the proceeds back to the criminal(s) sending them.

This led to a major press campaign and new website dedicated to educating the public about these checks called FakeChecks.org. The United States Postal Inspection Service, who worked with the EFCC on the task force, is one of the major sponsors of this site.

Most advance fee scams can be traced to a spam e-mail.

So far as the other trends noted, spammers and scammers are very adept of using what is popular or newsworthy to spread their deceit on the Internet.

It's probably not a surprise that they are taking advantage of the rise in oil prices, or political polls to lure people into their web.

If you would like to read more about this, the January report from Symantec can be read in full, here.

Thursday, December 27, 2007

Symantec awarded $21 million award against Chinese Software Pirates

On Christmas Eve, Symantec announced a legal victory against Chinese pirates selling their cloned software at super cheap prices.

Please note, I stole the super cheap description from Symantec's video called, The 12 days of Christmas Spam." The super cheap tag can either refer to price, or the quality of counterfeit software (personal thought).

From the press release:

Symantec Corp. (NASDAQ: SYMC) today announced that it was awarded $21 million in damages against a large network of distributors selling counterfeit Symantec software.

The judgments were handed down by the United States District Court for the Central District of California in Los Angeles, CA in favor of Symantec against ANYI, SILI Inc., Mark Ma, Mike Lee, John Zhang, Yee Sha, and related defendants.

"Our customers are the real winners as a result of this case," said Scott Minden, director, Symantec Legal department. "A judgment like this is a crippling blow against these particular syndicates and will drive them even further underground, making it more difficult for them to sell directly to unsuspecting users. It complicates their ability to operate behind the guise as legitimate businesses."
The investigation conducted by Symantec in collusion with the FBI and Chinese authorities also led to some criminal charges being filed in China.

It appears that this particular case involved pirated software being made to appear as if it was the real deal. According to industry experts, the counterfeiting problem has increased 10,000 percent in recent history.

The software industry alone estimates it loses $40 billion a year because of pirated software. I wonder how many jobs this equates to?

Pirated (super cheap software) is also hawked via the millions (billions?) of spam e-mails attacking our in boxes in record amounts. Recently, Symantec issued a report based on the spam data they monitor revealing that over the current holiday season 71percent of all e-mail sent is spam.

Counterfeit software also can contain malware (malicious software), which can lead to your system becoming a zombie (part of a botnet to facilitate more spam) and even steal your personal and financial details. These details are then used to steal money either from you directly, or to steal money from financial institutions.

I'm sometimes amazed how a lot of current criminal activity ties in together via the digital world. All the average person needs to do is to watch all the spam messages they get and consider all the different schemes that are behind them. The schemes are nothing new, but the digital age has enabled criminals to reach out to more people than ever before.

Either this is occurring naturally, or someone pretty organized people are running operations along the lines of major corporations?

Besides the more personal dangers of buying pirated software, there is a lot of evidence the activity is making a lot of money for organized crime, rogue governments and terrorist groups, alike.

Press release from Symantec, here.

Friday, December 14, 2007

Symantec reveals how the spammers are trying to steal Christmas

Kelly Conley announced the Christmas edition of Symantec's spam report on the company blog:

Here we are the end of another year. As 2007 rolls to a close the December State of Spam Report reviews this past month’s key trends and reflects on some of the year’s most notable spam events and trends.
The report notes that Bill Gates' prediction in 2004 that spam would be eradicated has proven not only to be wrong, but that the amount of spam circulating on the Internet has exceeded everyone's expectations (nightmares?).

This month, three out of every four e-mails sent is spam!

Spammers are even using MP3s, videos, and Google's alerts/searches to spread their seedy marketing ventures to Internet users.

Here are some of the highlights of the end-of-year report:

• Penny stocks use Thanksgiving holiday captions in subject line – spammers using common personal Thanksgiving-related words in the subject of emails

• Replica products a favorite for spammers this holiday season – replica gear has always been a spammer favorite. Spammers are marketing their wares using seasonal words in the subject lines of their mailings

• Spam begins to snowball – spammers collecting email addresses by using a funny .gif that shows a snowball hurtling at you through your computer

• Christmas freebie anyone? – spammers taking advantage of the season to market "free" gift cards for well known companies

• Seasonal lotto scams - in a scam targeted at UK end users, spammers have updated a lottery spam email for a Christmas Bonanza special

The current interest in celebrities like Britney Spears, Lindsay Lohan and the Osmonds were used as lures to get people to open spam e-mails hawking "questionably safe" drugs.

Spammers use whatever is trendy, popular or in the news to trick people into clicking on them. Here is one of the sicker examples of this seen recently:

An attack this month preyed on the public interest in the story of the missing British child, Madeleine McCann. The email contained a link to http://madeleine2007.notlong.com/, which redirected to http://internetwonderful.com/madeleine. The second site is designed to look similar to the official McCann family site, www.findmadeleine.com, however, it actually is set up to distribute a virus. The site also contains an unauthorized use of the Symantec logo and a number of Google ads for anti-virus products.

It should be noted that although the spam email also contains a link to the legitimate findmadeliene.com site, there is no connection between the spammers and the genuine site.

The report concludes it's findings with recognition of anti-spam efforts during the year, such as the FBI's Operation Bot Roast, the SEC's Operation Spamalot, ISP's sharing more information and security vendors employing new spam filter technologies.

We need to remember that spam is the vehicle used to spread 99.9 percent of the questionable marketing and scams on the Internet. Clicking on a spam e-mail can cause a person to become victim of anything from a financial scam to using a unsafe product that is a threat to their personal safety.

These reports serve a purpose, which is to educate the average person on what to watch out for and not click on a spam e-mail in the first place. Since it's Christmas and a lot of us are thinking about the young people in our lives, perhaps this is a good time to educate them on the growing problem of spam on the Internet!

I meet a few older people from time to time that might benefit from the education process, also.

Kelley Conley's blog post announcing the December report, here.

Symantec's December (year end) report on the state of spam, here.

On a lighter note, here is the YouTube video on the 12 days of Christmas Spam:

Thursday, November 08, 2007

Symantec reports on spam trends for 2007

Photo courtesy of slumberparty_uk at Flickr

According to Symantec's November report about 70.5 percent of the e-mail sent to your inbox is spam. This is pretty frustrating for a lot of us, who have to rely on spam filters that don't seem to work very well.

If you are like me, I get spam in my inbox and have legitimate e-mail mistaken as spam and sent to my bulk folder.

I've also heard of a lot of spam being able to bypass corporate spam filters recently. This can be particularly dangerous if an employee clicks on something that is malicious in nature.

Some experts have tested employees with phishy (spam) e-mails to see if they would fall for the bait. A large percentage of them did.

I mentioned corporations in the paragraph above, but this can happen at any organization.

In keeping with tradition, the spam kings stay on top of current events and ensure their social engineering lures are what would be considered newsworthy and even trendy.

From the Symantec November Report:

Ron Paul, MP3s, and global warming…what do they all have in common? No, it’s not some new presidential campaign. They were all topics leveraged in new spam tactics in October.

Even as the game becomes more sophisticated, most spam isn't effective unless it can lure a human being into whatever scheme it is attempting to pull.

Spam is already being seen that impersonates (spoofs) presidential candidates and claims to support environmental causes.

In the case of spam that impersonates environmental causes, a lot of them might include a survey asking for a lot of personal and financial information.

So far as the election campaign spam going around, we will probably see attempts to misdirect campaign contributions, commit identity theft and possibly even be used as a tool to spread misinformation (smear tactics).

One thing to remember is that giving out information to someone you really don't know tends to put you at an extreme risk of becoming an identity theft victim.

So far as financial scams go, the spammers also appear to be very interested in the real estate market:

Last month, Symantec reported how spammers had taken an interest in the housing market slowdown by offering different home refinancing deals. In an ongoing attempt to leverage capital by any means possible, the latest variations suggest releasing equity from your parents’ home.


Anyone, who falls for a not very legitimate scheme involving real estate is probably going to be taken to the cleaners. Sadly, fraudsters often target desperate people looking for a (too good to be true) way out of the mess they are already in.

The current real estate crisis is giving them an easy vehicle to do this!

With a reported 1,000,000 foreclosures pending in the United States and a possible loss of $200 billion to the lenders, this trend particularly bothers me.

The report also mentions Russian Bride scams, pump and dump stock scams using MP3, and spam e-mails using links containing Google searches.

The links containing Google searches misdirect the user to pretty questionable e-commerce sites, which could be (probably are) nothing more than a ploy to steal someone's money.

The information on the links using Google searches is explained in full on the Symantec blog, here.

This latest report indicates that spam is a problem that isn't going away in the near future. Spam is a known vehicle for everything from deceptive advertising to outright scams on the Internet.

Besides protecting your system, which Symantec is in the business of doing, being aware of the social engineering lures is the key to not becoming a Internet fraud statistic. It's refreshing to see Symantech address this with these reports, also.

For the full report, which has more spam variations than I've mentioned in this post, click here.

Symantec also does a blog on current online fraud schemes that are circulating, which can be seen, here.

Friday, August 24, 2007

Internet criminals stealing information from job sites isn't anything new!

The recent reports about 1.3 million Monster users having their information stolen from the job site has become somewhat of a major news story. While this seems shocking, the truth is that job sites have been targeted for the information they contain, or to recruit people to commit crimes (sometimes unknowingly) for quite awhile now.

Jim Finkle at Retuers (courtesy of the Washington Post) recently covered this story:

Monster.com waited five days to tell its users about a security breach that resulted in the theft of confidential information from some 1.3 million job seekers, a company executive told Reuters on Thursday.

Hackers broke into the U.S. online recruitment site's password-protected resume library using credentials that Monster Worldwide Inc said were stolen from its clients, in one of the biggest Internet security breaches in recent memory.

They launched the attack using two servers at a Web-hosting company in Ukraine and a group of personal computers that the hackers controlled after infecting them with a malicious software program known as Infostealer.Monstres, said Patrick Manzo, vice president of compliance and fraud prevention for Monster, in a phone interview.
Symantec -- who broke the story has published some of the examples of the fake job offers being sent to people -- posting their resumes on Monster, here.

People can protect themselves by being aware of the social engineering aspects of these scams. The job offers are always too good to be true and normally don't make very much sense.

Most of them are ploys to either cash bogus financial instruments, or launder the proceeds of Internet crime. Another red flag is that the employee is solicited to wire money, normally across a International border.

The employee (victim) then ends up financially liable, and in some instances, can even end up facing criminal charges. In most areas, cashing bogus financial instruments and money laundering is considered a crime.

The scammers, who offer these jobs intend to get someone else to take all the risk for them, while they reap most of the financial rewards.

Monster isn't the only place, where this happens. The risk is there on just about any of the Internet job sites, including Craigslist.

If you use these sites, it's a good idea to verify, who you are talking to before accepting a job offer.

The Privacy Rights Clearinghouse has an excellent page about job scams on their website, here.

Because these fake employers gather their victims's personal and financial information, they are likely to become an identity theft victim, also.

The page on the Privacy Right Clearinghouse site gives good advice on how to deal with this, also.

The good news is these scams are pretty easy to spot and a little awareness can prevent them from happening altogether.

Reuters story (courtesy of the Washington Post), here.

Friday, April 13, 2007

Symantec's Family Resource Web Site

Symantec has launched a new web page designed to educate children (and their parents) about how to avoid the (sometimes) murky waters of the Internet.

The goal of the page is to (in their own words):

Our goal is to help parents provide guidance to their children who are using the Internet . We want you to keep your children and your computer safe online, and help you make sure your children are good cybercitizens. With your direction and supervision, the Internet can be a positive, safe place for your child to research, learn, communicate, and socialize.

The page can be viewed, here.

Symantec has also hired someone to administer this effort (Marian), who writes columns to support the page.

You can even submit a question to her, here.

The page has links to other sites on this important subject, also:

iKeep Safe

Web Wise Kids

National Cyber Security Alliance

Taking the time to educate our children, as well as ourselves, on how to safely use the Internet is an important effort!

Thursday, April 12, 2007

Sage Predictions on the State of Cyber Crime from McAfee

According to McAfee, cyber crime is growing and as soon as the good guys (white hats) close one loophole, the bad guys (black hats) exploit another.

Unfortunately, technology grows faster than laws and security fixes. Criminals, who are becoming increasingly organized, realize and exploit this fact, frequently.

The report confirms predictions that exploiting VoIP and mobile devices will become more common.

Vishing will probably become more dangerous than phishing - it adds a more personal (voice) touch to tricking people into giving up their personal details. VoIP (cheap long distance) is one of the reasons for this. Since caller-id spoofing is easily available and legal, it makes sense that a lot of people are going to fall victim to vishing attacks.

Also covered is the growth in music and software privacy. Billions of dollars are being lost in both these areas - systems are now being sold with pirated software already installed on them.

To me, this shows how organized, the activity is becoming!

The report also covers RFID technology (quickly becoming commonplace) and how easily it can be exploited. Despite warnings from a lot of concerned experts, we seem to be implementing this technology at a foolish pace (my emphasis).

McAfee deserves recognition for having the courage (there is a lot of money behind RFID technology) to point out the dangers behind this highly profitable, but dangerous (my emphasis), technology.

Enough ranting for the moment, I highly recommend reading the full report, which can be viewed, here.

Monday, April 09, 2007

Fake e-mail claiming U.S. has attacked Iran contains Trojan

If you receive a e-mail that Iran has been toasted by a U.S. strike, be careful of clicking on the attachment. Doing so, might toast your computer system.

John McDonald posted this information on the Symantec blog:

Over the weekend Security Response received samples of the latest variants of Trojan.Peacomm and W32.Mixor doing the rounds. The social engineering trick employed this time is in appealing to people's sense of fear as well as natural curiosity of a possible Middle East war involving the United States, Iran and Israel.

Subjects include "USA Just Have Started World War III" / "Missle Strike: The USA kills more then 20000 Iranian citizens" / "Israel Just Have Started World War III" / "USA Missile Strike: Iran War just have started". From the sample emails that we have seen to date, the actual email body is blank, and the attached files have various names such as "video.exe", "movie.exe", "click here.exe", "clickme.exe", "readme.exe" and "read more.exe".
More on this on the Symantec blog, here.

An unprotected computer might be turned into a zombie, which becomes part of a botnet (used to harass the rest of us with lots of more spam) if one of these attachments is clicked on.

Spam is often used to facilitate financial crimes, such as identity theft.

It pays be to EXTREMELY careful before clicking on any (unknown) attachments received via e-mail.