Data protection
Some crime-ware writers offer service contracts

Malware mimicking legitimate business

R&D budgets, outsourcing models and support services

Written by Iain Thomson

It is like trying to fight a competitor that's changing its products every week

Richard Archdeacon Symantec

Malware development is now closely mimicking the legitimate business world, according to Symantec's latest internet security threat report.

Criminals are increasingly outsourcing parts of the malware process, be it writing code or developer tools, distributing the finished product or even setting up support services for organisations that buy the software.

Some crime-ware writers also offer service contracts, so that if one piece of malware is blocked another is sent to customers immediately.

"It is fascinating how the market has developed. It has been a phenomenal 12 months," Richard Archdeacon, Symantec's technical services director, told vnunet.com.

"It is completely business-oriented. They supply product in the same way as any software business."

Archdeacon described how malware groups are investing in software automation to make generation and distribution as easy as sending spam, and that cottage industries are springing up to find vulnerabilities in specific software.

All this has made life much tougher for the security software industry. Symantec said that new malware threats rose from 74,482 in 2006 to 499,811 in 2007.

"It is like trying to fight a competitor that's changing its products every week," said Archdeacon. "The only thing now is to update tactics to disrupt their business and break the business model."

Further evidence of the commercialisation of the malware industry can be seen in price differentials in the value of stolen data.

For example, a compromised US credit card can be had for as little as 40 cents, while prices for EU and Asian cards can go as high as $20.

The Symantec report, which covers July to December 2007, found a further decline in the use of worms to infect computers in favour of Trojan attacks that allow for full control of a PC.

There has also been a return to methods not seen since the beginning of the computer age, according to Archdeacon.

"The first viruses were distributed on floppy discs, and this technique is back in fashion, although this time it's via USB sticks," he said. "We have found code that targets those devices and spreads that way."

Financial sites still make up the bulk of targets for phishing attacks, but attacks on ISPs now make up 18 per cent of the total.

This is because the web space that often comes with such accounts can be used to host valuable phishing sites and email accounts for spam.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Hacking

Cyber-crooks turn to managed services

Easy-to-use crime-ware toolkits on the rise 08 Apr 2008

 

Big names fail VB100 antivirus test

McAfee and Trend Micro 'named and shamed' 04 Apr 2008

USB malware on the rise

Memory sticks identified as fast growing attack vector 02 Apr 2008

Teenager admits to million-PC botnet scam

18 year-old unlikely to get jail senence 01 Apr 2008

Cyber crooks net €300,000 in 22 days

Malware writers reap big reward from bank Trojan 01 Oct 2009

Recession prompts shift in cybercrime tactics

Stricter credit checks lead to more instances of hijacked accounts 24 Sep 2009

A week in security: malware targets banks and defence firms

V3.co.uk rounds up the top security stories 03 Jul 2010

related white papers

today's top stories

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

When business brains turn to crime

Cyber criminals are far better organised and more sophisticated than most legitimate e-commerce operations, writes Stuart Sumner 08 Sep 2010

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Genuinely intuitive technology is years away

If the aim of technology is to simplify our lives, then it has failed 07 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

Clouds reflected in office blockFeatures

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

Dale VileFeatures

Defining cloud computing

Making sense of what cloud means to your business involves evaluating the options and clarifying the benefits you expect from its implementation, writes Dale Vile 08 Sep 2010

Primary Navigation