Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Don’t Focus on Headlines: Worry About More Common Attacks, Says Expert

Although Groups Like LulzSec and Anonymous Have Created Headlines with Very High Profile Attacks, They Represent a Tiny Fraction of the Online Crime that Happens Around the World Each Day

The amount of new malware being created shot up 60 percent during the first half of 2011, according to a new report from Sophos.

Although Groups Like LulzSec and Anonymous Have Created Headlines with Very High Profile Attacks, They Represent a Tiny Fraction of the Online Crime that Happens Around the World Each Day

The amount of new malware being created shot up 60 percent during the first half of 2011, according to a new report from Sophos.

In their Mid-Year 2011 Security Threat Report, Sophos researchers stated they are identifying an average of 150,000 malware samples each day – a number that breaks down to one unique malware file being created every half-second. That figure represents a 60 percent increase over the number analyzed by Sophos in 2010, the company said. Additionally, some 19,000 malicious URLs are identified daily, with 80 percent of those being legitimate sites that were compromised.

“The percentage of malicious URLs hosted on legitimate sites has risen slightly since we compiled data for our last report back in January,” Richard Wang, manager of SophosLabs US, told SecurityWeek. “Then over 70 percent of malicious URLs were hosted on legitimate sites, (and) now it’s over 80 percent. The increase is probably the result of a couple of factors. First is the ongoing lack of security applied to many websites, often something as simple as keeping your blogging software up to date…The second factor is the continued appetite for compromised sites from the attackers themselves. As sites are found and cleaned they must add more to their armory… continue to do so in a highly automated manner.”

One of the main fronts in the fight against malware is social networks. These attacks have varying degrees of success, but once such scams are released they spread themselves, meaning there is little or no cost difference to the scammer between targeting 100 or one million people, Wang said.

Meanwhile, e-mail-based attacks seem to be on the decline. Just .16 percent of e-mail attachments contained threats in the first quarter of 2011, compared to .27 percent of e-mail attachments in the first quarter of 2010. Interestingly, a comScore report released in February found that e-mail use by people between the ages of 12-17 years old dropped 59 percent in 2010, Sophos noted in its report.

“As use of email declines the attackers will undoubtedly increase their efforts in other communications channels,” Wang said. “To make money they need to find victims and that means following the crowds. At the moment the Web is still the primary means of attack but the criminals are exploring more ways to make money from social network-based attacks and translating their old scams to newer forms.”

Malware Hosting Countries 2011

The U .S. still holds the top spot on the list of countries hosting malware, although the total percentage of malware hosted by the U.S. dropped to 37.9 percent during the first half of 2011, down nearly 1 .5 points from 39 .39 percent in 2010. The Russian Federation now claims the number two spot, a position held last year by France, Sophos reported.

Advertisement. Scroll to continue reading.

“Although (LulzSec has) grabbed headlines with very high profile activities they represent a tiny fraction of the online crime that happens daily around the world,” Wang said, adding that “organizations must not become so preoccupied with defending against LulzSec et al that they forget to protect themselves from the much more common attacks that are less newsworthy but much more likely to strike.”

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.