Malware enters new phase

Malicious code makes a new turn as profit-driven gangs take over from hobbyists

Written by Tom Young

The hacking community has run out of fresh ideas when it comes to creating malware, according to security vendor Kaspersky Lab.

The company’s report, Malware Evolution: July - September 2006, says: ‘Threats are no longer global, and are not effective for as long as they used to be.’

David Emm, senior technology consultant at Kaspersky Lab, says there has been no significant development in malware code for some time.

‘Periodically there is a leap forwards where something new develops,’ he said.

‘We are seeing many threats in terms of volume but it is the same old stuff, and we have not seen any breakthrough developments in the malware field for a while.’

But Emm says this does not mean the security industry has finally won the battle against malware authors.

‘For the past two to three years the type of malware we have seen has been tailored to make money, to launch extortion attacks and to steal confidential data,’ he said.

‘If something works for these guys – and it clearly does – then why change it?’

Fernando de la Cuadra, international technical editor at Panda Software, says reusing code makes malware both easier and more difficult to combat.

‘Codes are certainly not as high-quality as they used to be. Authors take existing code and change something, add a new function or change some lines to avoid detection,’ he said.

‘On the one hand, fewer quality codes mean the behaviour of the codes is easily predictable, but it also means more codes than ever before.

‘In the first half of this year we found more different codes than in the previous 15 years.’

Simpler codes are an indication of malware being used by financially motivated criminal gangs, rather than hobbyists who are better programmers, says de la Cuadra.

‘To combat them we have to develop a new technology that can detect virus codes based just on the behaviour of the codes. Many of the codes will try to do the same things, so the behaviour is very similar,’ he said.

Andy Kellett, senior research analyst at Butler Group, says this lapse in quality simplifies the task of tackling malicious code.

‘From a security point of view, things that come from a common source are easier to combat,’ he said.

‘More of the same is better, even if there is a lot more of the same. For example, if you look at the spam marketplace, the volumes there do not seem to faze security filters.’

But Kellett says this does not necessarily mean that authors will not improve their code if they need to.

‘Profit-motivated malware authors probably fall into the cleverer elements anyway. They are constantly looking at using resources to maximise the threats they pose,’ he said.

‘If ever they become less effective, of course they will evolve their code.’

What do you think? Email us at feedback@computing.co.uk

Further Reading:

Writers block hits malware authors

Social sites open to malware

Websense finds malware with Google

reader comments

related articles

 

Security experts warn of smartphone hacking risk

But disagree over when attacks will appear 01 Oct 2008

Malware jumps over 200 per cent in 2008

Symantec reports huge rise in malicious attacks, and warns of the smartphone risk 14 Apr 2009

Twitter users plagued by rogue anti-virus attack

Video link pushes covert downloads of 'scareware' apps 04 Jun 2009

related whitepapers

today's top stories

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Open source bites back

Recession-hit companies are tired of vendors holding a gun to their heads over software licensing, says CEO of Ingres 09 Jul 2009

"We will ensure Britain remains at the forefront of the digital revolution"

As new trials of superfast broadband get under way, minister Pat McFadden explains the government’s digital vision 09 Jul 2009

Put social networks to work on your career

Increasing numbers of IT professionals using sites such as LinkedIn to grow contacts and find jobs 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation