Study: Malware risks are growing exponentially

By Elinor Mills, CNET News.com
Wednesday, October 22, 2008 10:21 AM

A new report from security services provider ScanSafe finds that companies are at increasing risk of having employees inadvertently download backdoors and password stealers onto corporate computers from Web sites that have malicious software hidden on them.

A company in ScanSafe's focus group faced a nearly 500 percent greater risk of exposure to those threats in September than was faced in January of this year, according to ScanSafe's Global Threat Report released on Tuesday.

Companies in the energy sector are at greater risk from Web-based malware than other industries, the report concludes. The energy sector, worldwide, faces a 189 percent higher risk of exposure from workers visiting sites with malware on them than other industries, followed by the pharmaceutical and chemicals industry, construction and engineering, and media and publishing.

"On a more positive note, government agencies were at 0 percent, which indicates they were at neither higher nor lower rates of exposure compared to other verticals," Mary Landesman, senior security researcher at ScanSafe, writes in a blog post.

The industry with the lowest rate of exposure was aviation and automotive. Landesman says she cannot say exactly why one sector is more at risk than another but expects to release more findings soon that could help answer that question.

Overall, there was a flattening in the volume of threats in August and September, although ScanSafe is seeing a spike in October. Landesman says things could get ugly from a malware perspective throughout the rest of this year.

The holidays tend to be busy for socially engineered-types of malware, Landesman said. Plus, "the economy is hurting people's finances and this could encourage criminals to up their efforts to gain more money through illicit means", she said.

Also on Tuesday, security firm MessageLabs released statistics on the numbers of phishing attacks related to the banking crisis.

MessageLabs intercepted 7,000 phishing attacks exploiting Bank of America on October 16 and 15,000 on October 17, reaching 125,000 total e-mail messages over that weekend. American Express was the focus of a phishing attack that started on October 20 and reached 35,000 e-mail messages for the day.

The Cutwail botnet, which controls more than 1 million active unsuspecting zombie computers on the Internet and is believed to be the largest botnet, is responsible for those phishing attempts, MessageLabs said.

This article was first published as a blog on CNET News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web