Malware chooses blogs over e-mail

 

Summary

With the Web as the most popular means of malware infection, more malicious content is finding itself on social networking sites and blogs, says Sophos.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

More malware is hopping onto the Web 2.0 boat as the choice transportation, overtaking e-mail.

According to IT security company Sophos, the number one malware Web host is Blogspot.com, a site which provides a template and hosting space for users to create their own blogs for free.

Hackers have used the site to set up malicious blogs, and also used their Blogspot.com accounts to add comments containing dangerous Web links on other innocent blogs, detailed Sophos in its latest security threat report.

And yet Blogspot.com accounts for just 2 percent of all the malware hosted on the Web.

Other social networking sites such as Facebook and LinkedIn have not been immune to such threats. The Web is the preferred mode of attack for "financially motivated cybercriminals", noted the report, and amongst the social networking sites, LinkedIn affects more business users as a result of its enterprise audience.

Compromised LinkedIn accounts give cybercriminals a way to execute spear-phishing attacks on "new and unsuspecting" employees by way of corporate directories accessible through such vulnerable accounts, said Sophos.

Thousands of enterprise Web sites and government agencies have also been compromised, putting visitors at risk of infection and identity theft.

Graham Cluley, Sophos senior technology consultant, said in the report: "Businesses need to bite the bullet and take better care of securing their computers, networks and Web sites. They are not only risking having their networks broken into, but are also putting their customers in peril by passing on infections."

Office workers, too, need to be more vigilant when visiting Web sites so as not to be a cybercriminal's entry point into their organizations.

"All organizations should ensure employees are fully educated about the dangers of posting too much information on these sites, and of accepting unsolicited friend requests," said the report.

Sophos explained that over 90 percent of infected sites spreading spyware are legitimate sites, but hacked through SQL injection attacks, which insert malicious code into the database running a Web site.

With hackers gaining access into backend databases, users who visit vulnerable sites--especially banking sites--risk having sensitive information stolen, too.

According to Sophos, the first half of this year saw an "explosion" in threats spread over the Web, with 16,173 malicious Web pages seen everyday--or one every five seconds--three times faster than last year's rate of infection.

But attacks via e-mail have gone down this year. Malicious attachments were found in one out of every 2,500 e-mail messages this year, compared to one in 332 last year, according to the report.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Malaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP

RT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news

#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity

http://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN

Pacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0

Malaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir

http://t.co/VNaUVSe1 Malaysia organizations don't realize severity of cyberattacks: Cyberatt... http://t.co/TA5zWvUI http://t.co/wiqTBKkj

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/x1BJ0qSK

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/3Yaa40JE

Malaysia organizations don't realize severity of cyberattacks, country's minister of sci, tech, innovation says http://t.co/KGEHLi18 #in

Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

Malaysia offers some manufacturing benefits over China - ZDNet Asia http://t.co/j04OySNl

RT @zdnetasia: Idea Cellular follows Airtel, cuts India 3G tariffs. http://t.co/WNjnBHSX

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

4 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

4 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate