Hackers adopting new strategies to target Corporate India

author-image
DQChannels Bureau
New Update

Bangalore

November 5th, 2007

The latest Internet Security Threat Report (ISTR), Volume XII released in
India by Symantec Corporation concludes that cyber criminals are employing
business-like strategies to increasingly target tier-II cities, while
maintaining their focus on impairing enterprises and consumers based in metros.
Cities like Bhopal, Hyderabad, Noida, Pune and Surat now feature alongside
Mumbai, Chennai, Bangalore and New Delhi in the list of bot-infected cities in
India.

Advertisment

"As cyber-threats continue to grow in India with more than 30 million
Internet users across tier I & II cities, it has never been more important
to remain vigilant and informed on the evolving threat landscape," said
Vishal Dhupar, MD, Symantec India. "The Internet Security Threat Report
provides critical information on the latest online security trends, helping
enterprises and consumers to better protect their infrastructure, information
and interactions."

Small and medium businesses in India are increasingly targeted by phishing,
spam, bots, and malicious code (malcode) attacks that are created to target
these organizations for information that can be used for financial gain. These
businesses are also victims of data theft and data leakage as they lack a
strategy of multiple layers of security defenses ("defense in-depth").

The report also states that cyber-criminals are increasingly becoming more
professional with focused commercial intent in the development, distribution and
use of malicious code and services. While cyber crime continues to be driven by
financial gain, cyber-criminals are now utilizing more professional attack
methods, tools and strategies to conduct malicious activity.

Advertisment

During the reporting period of January 1, 2007, through June 30, 2007,
globally, Symantec detected an increase in cyber-criminals leveraging
sophisticated toolkits to carry out malicious attacks. One example of this
strategy was MPack, a professionally developed toolkit sold in the underground
economy. Once purchased, attackers could deploy MPack's collection of software
components to install malicious code on thousands of computers around the world
and then monitor the success of the attack through various metrics on its
online, password-protected control and management console. MPack also
exemplifies a coordinated attack, which Symantec reported as a growing trend in
the previous volume of the ISTR, where cyber criminals deploy a combination of
malicious activities.

Key findings:

The Symantec Internet Security Threat Report, Volume XII covers the
reporting period of January 1, 2007, through June 30, 2007. Accordingly, credit
cards were the most commonly advertised commodity on underground economy
servers, making up 22 percent of all advertisements; bank accounts came in a
close second with 21 percent. Symantec documented 237 vulnerabilities in Web
browser plug-ins. This is a significant increase over 74 in the second half of
2006, and 34 in the first half of 2006. Malicious code that attempted to steal
account information for online games made up 5 percent of the top 50 malicious
code samples by potential infection. Online gaming is becoming one of the most
popular Internet activities and often features goods that can be purchased for
real money, which provides a potential opportunity for attackers to benefit
financially. Spam made up 61 percent of all monitored e-mail traffic,
representing a slight increase over the last six months of 2006 when 59 percent
of e-mail was classified as spam.

Theft or loss of computer or other data-storage medium made up 46 percent of
all data breaches that could lead to identity theft. Similarly, Symantec's IT
Risk Management Report found that 58 percent of enterprises expect a major data
loss at least once every 5 years.

Advertisment