Phishers focus on China e-commerce sites

By Vivian Yeo, ZDNet Asia
Tuesday, June 09, 2009 07:10 PM

update Banks were the most spoofed sites in many countries, but in China, phishers zoomed in on e-commerce brands, according to a new report.

Symantec's latest State of Phishing Report revealed that all of the Chinese brands targeted during the month of May were from the e-commerce sector. This was consistent with the report for April, which also showed Chinese e-commerce sites being targeted for spoofing.

India and Malaysia also made it to Symantec's top 15 entries for targeted brands by country. In both countries, spoofed sites were all from the banking sector.

Sharp rise in phishing toolkits
The security vendor said there were a total of 28,800 phishing URLs in May, an increase of about 15 percent from the last two months. Phishing attacks using IP domains also increased 2 percent--1,237 phishing sites hosted in 77 countries were observed last month.

About 42 percent of phishing URLs were generated by automated toolkits that aided the creation of phishing sites. Such toolkits allow lay persons without the necessary technical know-how, to carry out phishing attacks.

Eric Hoh, Symantec's vice president of Asia South and head of global accounts for Asia-Pacific and Japan, told ZDNet Asia in an e-mail that toolkit activity often fluctuates with command and control server and botnet activity.

"The observed increase in phishing toolkit activity [in the latest report] in all likelihood indicates that some old botnets have been brought back online along with some new ones that are created," he explained. "Thus the trend indicates that the numbers are gradually reaching the pre-McColo shutdown levels as the fraudsters have found new homes to leverage the spam and phishing activities."

Forty-four percent of the phishing sites were hosted in the United States. Germany was in second place accounting for 5 percent, while China was No. 3 with a 4-percent share.

San Diego took the honor of being the top host of phishing sites, followed by two Taiwanese cities--Taipei and Taichung. Symantec noted that phishing sites with IP domains are continuing to originate from more and more new cities every month.

In the report, Symantec said the phishing sites connected with the attacks targeting Facebook in May, were mostly based out of China and Latvia. According to the vendor, the domains hosting the phishing sites comprised country codes as part of what appeared to be haphazardly-generated names.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Code concepts: Visual Studio's T4 templates

Web Development

The T4 templating system is used to programmatically generate artifacts. Here's an overview about why the templates are useful and how to work with them.


Read more »


 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




Where have all the bosses gone?

Blog thumbnail

I've had dreams of opening my own cafe or bistro...cum music store...cum music school. But, I soon gave up that dream when I realized it would require significant investment and..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web