Malware authors are producing variants in bulk, replacing innovation with
volume and mass-produced kit malware. But while new techniques weren't
developed-the existing techniques were refined and adapted for much greater
effectiveness to create some very dangerous faces in the big crowd
What F-Secure saw during the whole of 2007 was voluminous increase in malware,
with the authors becoming increasingly professional at their business. Kits and
commodities markets are the result.
The tools of online crime are being produced professionally. The purchased
kits are producing malware in bulk. The stolen data is traded as commodities on
underground auction sites. It's easy money with plenty of cover from law
enforcement.
Storm-Botnet 2007
Using sensationalized versions of real headlines as a template proved to be
a very clever bit of social engineering and was initially very successful.
However, the headline technique's success declined as it was repeated too often.
So the gang behind Storm adjusted their procedures. During the second half of
2007, they have continuously updated their social engineering tactics. Targeting
the US-they have used holidays such as Labor Day and seasonal events such as the
beginning of the National Football League season.
They has also altered Storm's infection vector as detection of Storm
increased and e-mail attachments were blocked. Instead of attaching the malware
to the e-mail messages as before, they spammed messages with links to malicious
web pages. When the detection of the web pages increased, they cleaned up the
pages and instead linked to the malware from the page. So the vector evolution
moved from e-mail attachments to web pages pushing files to web pages linking to
files.
The computers responsible for sending Storm spam and for the hosting of
Storm's web pages are they themselves part of the Storm botnet. And that botnet
is rather unique as it utilizes peer-to-peer (P2P) protocols. Traditional
botnets use a centralized approach. If the server is located and taken out of
service, then the botnet's head is decapitated. Storm is a collective with no
central point to shut down. There's no central command-and-control point to
kill.
Banking trojans
It is as easy to host multitudes of phishing sites as it is to host one.
This ease of creation contributes to saturation and so there is a gradual
reduction in the overall effectiveness. People are a bit more wary of phishing
bait. So what do you do if you want to steal banking information? Use banking
trojans.
Banking trojans sit and patiently wait for any banking activity. Trojans, by
definition, use a decoy or ploy to get installed. Bank names are not mentioned.
If the decoy uses clever social engineering, the victim may never realize what
they have really installed on their computer.
Monitoring browser activity (URLs) for banking keywords is the Trojan's task.
When banking is discovered, a number of different techniques can be employed to
steal the data.
There is growing evidence of banking malware injecting itself into the
browser. This allows some of the techniques above to be done as
Man-in-the-Browser (MitB) attacks. These types of attacks allow the malware to
use the browser as its platform. Encrypted banking sessions occur within the
browser, so that's where banking malware wants to be, before the banking session
leaves the browser. We'll see more of this trend in 2008.
Trojan password-stealers
Another segment of interest this year has been Trojan password-stealers,
specifically those that target online games. Online games continued to grow in
popularity throughout the year 2007. More importantly-revenues continued to
increase. More revenues means customers are spending more money, that's the
reason online game customers are increasingly becoming targets.
The economics are relatively straightforward even if the market is a bit of a
novelty. Virtual commodities exist in the virtual worlds of online games. Many
players of such games are willing to spend real money on these virtual
commodities.
So the value of these goods is real even if they are not physically real. And
things of real value are the targets of theft. The stolen commodities get
auctioned off and the thieves are difficult to identify because the crime is
completely online.
In short, the money being spent within virtual games and communities has
increased-so we've seen a corresponding increase in the growth of this segment
during 2007.
Mac DNSChanger
Social engineering is used to persuade users to enter their admin password
for the install-not a big problem for clever social engineering. Getting a Mac
user to type his password for an easily installed 'video codec' isn't a
significant challenge to overcome, at least it hasn't been a challenge for
password protected Windows malware.
We're seeing a growing number of Mac DNSChanger variants. The previous lack
of Mac OSX malware could be a distinct disadvantage for its users. Social
engineering can short-circuit a false sense of security.
Apple Mac's marketshare is now significant enough for the Zlob parasites to
target, as malware gangs don't make an effort to develop something without the
promise of a profitable return.
Apple's Safari browser for Windows likely contributed to this development.
Released in mid-June, researchers seized upon the Safari for Windows Beta and
many security flaws were discovered. Many of those flaws were mirrored in the
Mac version of Safari.
![]() |
| At the start of 2007, Fsecure's number of malware detections equaled a quarter-million. At the end of 2007, these estimates are to be equal to half-a-million |
Mobile security
Symbian S60 3rd Edition leads the world's marketshare of smart phones. Mobile
malware discovered during the second half of the year affects older S60 2nd
Edition phones.
What we continue to see on 3rd Edition platforms are spy-tools. The
application vendors are able to get their spy-tools signed by submitting them as
'backup' software. The signed application is then also marketed for dubiously
legal purposes. This trend matches what we saw during H1 and we expect it to
continue.
S60 3rd Edition is more tightly controlled than previous versions and thus
the lack of malware so far. However, the iPhone demonstrates that some users of
tightly controlled devices want to 'unlock' those devices. During October there
were Symbian platform 'hacks' posted.
The hacks used a bug in the firmware update package software to completely
unsecure Symbian 3rd Edition phones. If more users opt to unsecure their phones,
it will have an effect on the future of mobile security.
One additional thought, as commercial vendors use what amounts to social
engineering to get their questionable software signed, can malware authors be
far behind? With a system that relies on humans to sign software, humans are, as
with PC malware, the weak link.
Database breaches
Reports of database breaches and data losses are becoming routine. There are
massive amounts of personal data vulnerable to theft stored in databases
worldwide.
January started the year with a bang. TJX companies exposed 45.7 million
credit card numbers and transaction details. Poor Wi-Fi security configurations
and outdated WEP encryption was the culprit.
November caps off the year nicely in the UK with the HM Revenue and Customs
losing 25 million names, addresses, and national insurance numbers. Two CDs
containing information on parents, their children, and some portion of their
bank account information was lost in the mail.
The use of personal data for ID theft is one obvious concern. Another newer
concern is mass targeted attacks and mass spear phishing. Targeted attacks and
spear phishing employ very detailed personal information as part of its social
engineering. The target is called by name and the details of the message match
their own personal details. Include additional factual
details and the victim lowers their guard exposing themselves to phishing,
trojans, backdoor, and more.
Personal information available for exploit is everywhere. With the popularity
of social networking sites it's ever more readily available to the bad guys.
We'll see more bulk targeted attacks via spam as database leaks are used to
enhance social engineering during 2008.
What will we see in 2008? More of the same-lots more of the same but better,
stronger, faster. The criminals have the technology. Everything will continue in
bulk to ensure broad coverage. And as the bulk increases individual security
awareness, new improved technology power social engineering will strip that
awareness away again. 2008 will be a challenge of endurance.
F-Secure Corporation
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us/dqc/media/post_attachments/ce50460ed4c9b5c3058042bd085d4ba28f957703873bcdd7ac3795fbf69169d6.jpg)