'Celestial alignment' for ideal cybercrime world

 

Summary

Three distinct elements are currently in place for cybercriminals to thrive, but lack of clear monetization stream hampering their progress, say RSA execs.

Events

IT Priorities 2010

Sydney, Australia - 27 Jul 2010
Melbourne, Australia - 28 Jul 2010
Mumbai, India - 4 Aug 2010
Delhi, India - 6 Aug 2010

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

SAN FRANCISCO--The availability of high-grade Trojans, simple but easily executed distribution techniques and the bad global economy are three elements that are in "celestial alignment" today to create a cybercrime haven.

This perspective was put forth by Uri Rivner, head of new technologies at RSA, the security division of EMC. Speaking Wednesday in a presentation at the RSA Conference, he noted that security practitioners need to view the fraud environment as an "ecosystem" where cybercriminals are competing against each other in their respective specialties, rather than as individual entities.

According to Rivner, online and e-commerce fraud amounted to US$200 million losses for affected business and individuals in the United Kingdom alone. In comparison, credit card fraud losses, which he described as the predecessor of online fraud, currently amounts to US$1.5 billion in the same country.

Three factors driving cybercrime
On high grade Trojans, Rivner cited studies conducted by RSA that put the Zeus Trojan as the main tool used by fraudsters to conduct online criminal activities. According to the studies, 92 percent of all Trojan toolkits used are for Zeus.

Not only are the kits easily available online and affordable, variants of such Trojans can be "created on the fly", he added.

To support his stance, Rivner showed a screen-shot of a Zeus Trojan dashboard, which comprised a collection of major antivirus (AV) vendors. On the dashboard, users of the toolkit will be able to tell which AV vendor has a signature against their malware.

"With this information, Zeus users just need to click a button to create a variant, check again to see that the same AV vendor has no recognition of the new variant, and another Trojan is created," he said.

He also noted that today's Trojans do not just mine for individuals' financial information, as was the case previously, they are "stealing everything that we do", from a person's blood type to the type of partners they would like to date.

But having Trojans that can be executed well would be useless without having an effective method of distributing them, Rivner said.

Citing figures for Sinowal, he pointed to a huge spike of computers infected with this Trojan from mid-2008, which he attributed to the introduction of drive-by downloads.

An example of such drive-by downloads was musician Paul McCartney's personal Web site. His site was infected with the Trojan and anyone who visited the site would have unknowingly downloaded the same malware onto their computers, said Rivner.

Besides famous celebrities and their Web pages, social networking sites such as Facebook are another platform that cybercriminals are increasingly using to spread their malware, he added.

The global recession of the past year has also played its part in contributing to online fraud, as more cybercriminals recruit their "mules"--or Internet users who collaborate with them unknowingly--through fake company Web sites, noted Rivner.

"By calling for eligible candidates to apply for a phony position in the company and assuring them that they are joining a legitimate organization, fraudsters can make use of these people to transfer anything from money to personal information siphoned from someone else," he explained. "This is known as reshipping recruitment scams."

All of these developments, he said, point to one fact: the "battlefield" for information security has shifted from networks to its users, and as such, potentially has more wide-ranging repercussions.

Christopher Young, senior vice president of products at RSA, noted also during the presentation that through infecting employees' computers, cybercriminals can have a foothold into the organization and be able to swipe any information they want.

The saving grace, though, is that the monetization for all the information harvested by these online fraudsters is still "not streamlined", said Young, which gives corporations the time needed to fight back.

"This problem is now receiving board-level attention and the industry understands the need to build a new defense doctrine,” he said. The call for security to be embedded into cloud computing by RSA President Art Coviello in his keynote speech on Tuesday, is one example of the shift in security perspective, Young added.

Kevin Kwang of ZDNet Asia reported from the RSA Conference in San Francisco.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Access data anywhere in the private cloud & enable entirely new efficiencies with EMC VPLEX.
Tech Vendor: EMC

ZDNet Asia Live

US court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/aCqko4

great! US court rejects class action status for Intel antitrust suit http://bit.ly/9acwER Good day!

Shocked! RT: @danielgoh: Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

Non-green IT products 'marketing suicide': By Munir Kotadia, ZDNet Australia on July 30, 2010 (8 minutes ago) Vend... http://bit.ly/aCqko4

Asian firms aware of IT snoops. http://bit.ly/9eGRxG

sg marketeers not chirping to twitter's tune http://bit.ly/aRAa1Y - baby steps baby steps

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/cEkDUD

Non-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4

1 hour 5 minutes ago by greentreats on topsy

Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com

RT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY

2 hours 2 minutes ago by phyllis777loves on topsy

RT @HazelHassan: Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh

RT @zdnetasia: 10 questions to ask when http://www.zdnetasia.c...

RT @zdnetasia: S'pore marketeers not chirping to Twitter's tune http://bit.ly/bF2aoa

Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh

2 hours 18 minutes ago by hazelhassan on topsy

S'pore marketeers not chirping to Twitter's tune: Marketing via Twitter has not picked up in Singapore, where it s... http://bit.ly/9GEDJS

great! S'pore marketeers not chirping to Twitter's tune http://bit.ly/dotZES Good day!

http://bit.ly/8v7Ov3 S'pore marketeers not chirping to Twitter's tune - ZDNet Asia http://is.gd/dSngs

4 hours 10 minutes ago by easytweeting on topsy

in the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/

4 hours 41 minutes ago by findpdf on Researchers find workaround for Adobe PDF fix

Just want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...

4 hours 49 minutes ago by winsource on Making the case for Filipino IT entrepreneurship

Hi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks

1 day 42 minutes ago by Pacific Time Pte Ltd on Recycle your HP print cartridges and get rewards

Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...

2 days 47 minutes ago by yedwin on iPhone 4 shows prudence in procrastination

While I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...

2 days 59 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastination

The online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)

2 days 57 minutes ago by mingnow on iPhone 4 to ring in Singapore on Friday

After an awful silence, finally the prices are out..

2 days 52 minutes ago by melvinchia on iPhone 4 to ring in Singapore on Friday

Glad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...

3 days 59 minutes ago by gnome_refugee on Smitten with Xfce 4

yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...

3 days 57 minutes ago by ggolemg on Smitten with Xfce 4

@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...

3 days 3 minutes ago by fredericmuller on Taobao initiates Chinese open source revolution

Geez. I would think giving free books and getting kids to school would be a better place to start.

3 days 11 minutes ago by mingnow on India's US$35 tablet--how low can it go?

I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...

4 days 57 minutes ago by mingnow on Taobao initiates Chinese open source revolution

hey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...

4 days 28 minutes ago by wendy on iPhone 4 shows prudence in procrastination

It could be done without all these. Just use the opacity addon of Compiz.

4 days 52 minutes ago by hariks0 on How to get RGBA support in Ubuntu