Published: May 19, 2011
The evolution of IT threats in the first quarter of 2011
Kaspersky Lab's experts identify a number of important trends following the results of its quarterly malware report
Abingdon, UK, 19 May 2011 - Cyber criminals have capitalised on the recent growth in popularity of the Android mobile platform. Based on the number of new mobile malware signatures detected during this period, Kaspersky Lab's experts believe that the total volume of mobile malware in 2011 will be at least double that of 2010. That growth will be driven by the emergence of new methods of infecting users' computers.
For instance, over 50 malicious Android OS applications were detected in Q1 that were written by cybercriminals and distributed via the Android Market. These malicious programs are re-packaged versions of legal software alongside malicious Trojan components. Kaspersky Lab's experts predict that the number of embedded malicious programs distributed via online app stores will keep increasing in the future. Firstly, a developer's account is cheap and secondly, checking the code of newly published applications is highly labour-intensive and difficult to automate.
The situation concerning mobile threats is further complicated by the fact that personal smartphones are increasingly used to store and send confidential corporate information. At the same time, company employees tend to underestimate the importance of protecting data stored on such devices. Furthermore, smartphones are likely to be widely adopted as ‘mobile wallets' in the near future, reinforcing the importance of mobile security products.
The increasing number of attacks on different organisations was another significant trend in the first quarter of 2011. In addition to conventional DDoS attacks that block access to corporate servers for indeterminate periods of time, there were also many that focused on gaining unauthorised access to such servers in order to steal information. All the signs indicate that some professional cybercriminals have switched from mass home computer infections to hacking major corporations. This practice naturally involves more risk for the attackers; however, the stakes and the potential rewards associated with targeted attacks on corporations are higher and there are fewer competitors in this segment of the black market.
The first quarter also saw a wave of so-called protest attacks carried out by cybercriminals in order to damage company reputations rather than make a profit. A notable example of such an attack was the hacking incident targeting HBGary, an IT security company based in the US. Having gained access to confidential information belonging to the company, the hackers then made it public. These days, such a practice is exceptional; information is typically stolen by cybercriminals in order to sell it or to extort payment to prevent its publication.
At the end of Q1, a new variant of the dangerous GpCode ransomware appeared. This Trojan encrypts data on infected computers and then demands a ransom from the owner. Unlike its previous variants that deleted encrypted files, the new GpCode versions overwrite files with encrypted data, making them practically unrecoverable. Interestingly, the cybercriminals only attacked users in Europe and the former soviet republics, while the attack lasted for several hours only. Such cautiousness demonstrated by the writer of the Trojan indicates that the intention was not to cause a massive infection that would almost certainly draw the attention of law enforcement agencies. It is likely that future attacks of the encrypting Trojan will also be carefully targeted.
Yet another trend which directly impacts IT security is the growing popularity of social networks, blogs, torrents, YouTube and Twitter, which increasingly alters the digital landscape. These services facilitate the swift and simple exchange of data between users located in every corner of the world. Data published in users' blogs is often deemed as being as credible as that from official media outlets. The popularity of such resources has already caught the attention of cybercriminals. In future, the number of attacks carried out on and via these services is only likely to increase.
Click here to view the full version of spam in the first quarter of 2011.
-ENDS-
Kaspersky Lab Newsroom
Kaspersky Lab has launched a new online newsroom, Kaspersky Lab Newsroom Europe (http://newsroom.kaspersky.eu/en), for journalists throughout Europe. The newsroom is specifically designed to serve many of the media's most common requests, making it easier for journalists to find product and corporate information, facts and figures, editorial copy, images, videos and audio files, as well as details about the appropriate PR contacts.
About Kaspersky Lab
Kaspersky Lab is the largest antivirus company in Europe. It delivers some of the world's most immediate protection against IT security threats, including viruses, spyware, crimeware, hackers, phishing, and spam. The company is ranked among the world's top four vendors of security solutions for endpoint users. Kaspersky Lab products provide superior detection rates and one of the industry's fastest outbreak response times for home users, SMBs, large enterprises and the mobile computing environment. Kaspersky® technology is also used worldwide inside the products and services of the industry's leading IT security solution providers. Learn more at www.kaspersky.co.uk. For the latest on antivirus, anti-spyware, anti-spam and other IT security issues and trends, visit http://www.securelist.com.
Editorial contact:
Berkeley PR
John Paul Charles
kasperskylab@berkeleypr.co.uk
Telephone: 0118 988 2992
Fax: 0118 988 6911
Three Mile Cross
RG7 1BA, Reading
Kaspersky Lab UK
Ruth Knowles
Ruth.Knowles@kasperskylab.co.uk
Telephone: 0871 789 1633
Fax: N/A
Milton Business Park
OX14 4RY, Oxford
© 2010 Kaspersky Lab. The information contained herein is subject to change without notice. The only warranties for Kaspersky Lab products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. Kaspersky Lab shall not be liable for technical or editorial errors or omissions contained herein.
Copyright © 2012, Realwire
Copyright © 2012, NewsBlaze,
Daily News