Data protection
Some crime-ware writers offer service contracts

Malware mimicking legitimate business

R&D budgets, outsourcing models and support services

Written by Iain Thomson

It is like trying to fight a competitor that's changing its products every week

Richard Archdeacon Symantec

Malware development is now closely mimicking the legitimate business world, according to Symantec's latest internet security threat report.

Criminals are increasingly outsourcing parts of the malware process, be it writing code or developer tools, distributing the finished product or even setting up support services for organisations that buy the software.

Some crime-ware writers also offer service contracts, so that if one piece of malware is blocked another is sent to customers immediately.

"It is fascinating how the market has developed. It has been a phenomenal 12 months," Richard Archdeacon, Symantec's technical services director, told vnunet.com.

"It is completely business-oriented. They supply product in the same way as any software business."

Archdeacon described how malware groups are investing in software automation to make generation and distribution as easy as sending spam, and that cottage industries are springing up to find vulnerabilities in specific software.

All this has made life much tougher for the security software industry. Symantec said that new malware threats rose from 74,482 in 2006 to 499,811 in 2007.

"It is like trying to fight a competitor that's changing its products every week," said Archdeacon. "The only thing now is to update tactics to disrupt their business and break the business model."

Further evidence of the commercialisation of the malware industry can be seen in price differentials in the value of stolen data.

For example, a compromised US credit card can be had for as little as 40 cents, while prices for EU and Asian cards can go as high as $20.

The Symantec report, which covers July to December 2007, found a further decline in the use of worms to infect computers in favour of Trojan attacks that allow for full control of a PC.

There has also been a return to methods not seen since the beginning of the computer age, according to Archdeacon.

"The first viruses were distributed on floppy discs, and this technique is back in fashion, although this time it's via USB sticks," he said. "We have found code that targets those devices and spreads that way."

Financial sites still make up the bulk of targets for phishing attacks, but attacks on ISPs now make up 18 per cent of the total.

This is because the web space that often comes with such accounts can be used to host valuable phishing sites and email accounts for spam.

reader comments

related articles

Hacking

Cyber-crooks turn to managed services

Easy-to-use crime-ware toolkits on the rise 08 Apr 2008

 

Big names fail VB100 antivirus test

McAfee and Trend Micro 'named and shamed' 04 Apr 2008

USB malware on the rise

Memory sticks identified as fast growing attack vector 02 Apr 2008

Teenager admits to million-PC botnet scam

18 year-old unlikely to get jail senence 01 Apr 2008

Web threats continue to rise

Latest Symantec threat report finds a big increase in site specific attacks 08 Apr 2008

vnunet.com analysis: The malware 'shadow economy'

Online criminals using techniques of the free market 09 Jan 2008

McAfee predicts 2008's worst security threats

Social sites likely to be big targets for cyber criminals 16 Nov 2007

related whitepapers

today's top stories

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis 07 Oct 2008

Where to offshore (and why not here?)

Tholons, the research firm founded by well-known offshoring guru Avinash Vashistha , has just published some new research in Global Services magazine... 07 Oct 2008

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

The pIT stop Q&A: How can I measure the business success of IT applications?

Ou expert panel answers readers' real-life IT questions 07 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

Ethernet cableVideo

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Latest in-depth articles

Features

How to ensure progress in programming

Best practice advice from Forrester Research 02 Oct 2008

BT workersAnalysis

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

Advertisement

Primary Navigation