Phish hook

Phishers snare victims in customised nets

Targeted phishing attacks pose a growing threat according to security firm MessageLabs

Written by Phil Muncaster

Phishing attacks are growing more sophisticated and will represent a major security threat in the future as the number of converged spyware, spam and virus attacks grows, according to the chief technology officer of a major email and web security firm.

Mark Sunner of MessageLabs told IT Week that researchers at his firm have recently seen phishing attacks that employ information collected from users’ PCs by spyware. The criminals aim to make their scam messages more targeted and effective by using the inside information gained in this way.

"We're now in the midst of a new level of convergence triggered by the necessity [to make money] from targeted attacks," Sunner explained. "In 12 months we'll pinpoint this time as the moment spam and viruses converged with spyware."

Sunner likened the importance of the development to the period in 2003 which saw "the botnet phenomenon take-off overnight" and the first time that criminals merged spam and viruses with the release of the Sobig.A virus.

"We're seeing it in an embryonic phase with phishing attacks targeting people who actually use that bank, not a scattergun approach," Sunner said. "They use the customer's real name, address and [other details]." He added that as this type of attack becomes more popular, it is likely to bring to a head the issue of banks footing the bill for customers who become victims of phishing fraud.

"You used to be able to educate against phishing attacks but now [they are becoming harder to spot] and it will begin to get under people's radars," he said. "The banks' problem is they don't know where the customer has been before [and if their PC has been infected with spyware]…but they will cover this cost as long as possible."

Social networking sites such as MySpace represent a particular risk if criminals also begin to mine them for personal information in the future, to use in similar attacks, Sunner added. He also argued that instant messaging threats could rocket in about a year's time as the four public IM clients bow to pressure to interoperate, creating one giant messaging ecosystem offering criminals a much more profitable target for attack.

In other news, anti-virus specialist Kaspersky Lab last week released a new report warning that ransomware authors are using increasingly sophisticated encryption algorithms when blackmailing firms. In the future these techniques could even outwit the anti-virus industry, said the firm.

Tags:

reader comments

related articles

 

Virus and phishing attacks soar in September

Second surge of email attacks targeted at executives 27 Sep 2007

Spam emails rocketing

Spammers and cybercriminals using new techniques to bypass filters 03 Jun 2008

Storm botnet blows itself out

But overall malware volumes still rising fast 01 May 2008

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation