Old security threats continue to evolve

 

Summary

Social networking sites are new targets for cybercriminals but users still need to beware of previous security threats such as vishing and spim, caution security experts.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

While social networking sites are now targets for cybercriminals, users still need to be alert of older security threats that have evolved with advanced technology, advice security experts.

With the growing popularity of social networking sites, cybercriminals see users on these platforms as ideal targets for identity theft and vehicles for spreading malware.

But while users should be wary of these emerging risks on social networks, they should not let their guard down against previous security threats that target other platforms such as telephone and instant messaging (IM).

Paul Ducklin, Asia-Pacific head of technology at Sophos, noted that cybercriminals can still exploit the telephone to spread voice-based spam and run scams as well as vishing. In vishing, which is a variant of phishing, fraudsters use stolen identities to set up voice-response systems and collect local VoIP (voice over Internet Protocol) phone numbers.

Ducklin told ZDNet Asia that cybercriminals spam users and trick them into listening to recorded advertisements guised as voicemail messages. These tricksters also use "missed call" spamming tactic where they would hang up immediately after the phone rings, in hopes that the user will return the call only to listen to a recorded advertisement.

He said phone spamming incidents are on the wane in Sydney where he is based, but cybercriminals are turning to social networking sites to lure people into spam and scams.

He also pointed to vishing as a security threat that is still relevant today, noting that he still receives recorded messages from unsolicited callers, though, only occasionally. Returning such scam calls costs time, effort and money, he added.

In a previous ZDNet Asia report, Jim Dowling, Sophos director of sales for Asia, noted that vishing could lead to serious consequences when deployed alongside caller ID spoofing, where calls are made to seem like they come from a trusted source.

Ducklin cautioned users against returning calls and messengers unless they are certain of the caller's identity.

Instant messaging threats
While threats related to IM have been circulating since 2001, cybercriminals are now combining information gathered from social networking sites and IM platforms to bait users into clicking links that prompt the victim's computer to install malware, such as the recent attacks that targeted Google.

Spamming via IM, or spim, occurs because users place too much trust on "friends" and "buddies" online, even when they don't know who these people are in real life, said Nicholas Tay, Asia-Pacific regional director for FaceTime Communications.

These users do not think twice about clicking on links "friends" or someone posing as their friends send, Tay said in an e-mail. "A successful spim attack could lead to a client list being leaked, not to mention the potential loss in [brand] reputation and a hefty fine from an industry body," he said.

Just last month, Microsoft secured an injunction against a Hong Kong-based company requiring to stop spimming customers and contacts of Windows Live Messenger and pay the software vendor a settlement amount.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

RT @zdnetasia: Homegrown smartphone OSes gaining favor in China. http://t.co/lL8KbccW

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia: Big data acquisition... http://t.co/r6taCmG1 #ITNews #BigData

Big data acquisitions pave way to fast, effective innovation - Zd Net http://t.co/d9k21ro5: David G... http://t.co/4JgaOz8g #bigdata #sna

Big data acquisitions pave way to fast, effective innovation - Zd Net http://t.co/fbori8UQ: Incr... http://t.co/nuEeUbj7 #ITNews #BigData

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/iFQ74xYI #Bigdata #analytics

@ChemarieMonica : Integration, focused investments to propel Windows Phone - ZDNet As... http://t.co/ZVPDpbxH http://t.co/1QrdIsaV #tech

China social media companies have global potential
http://t.co/p8fkRbfD Chinese social media companies such as #Renren and #Sina might...

China social media companies have global potential
http://t.co/Y3x1qBI1 Chinese social media companies such as #Renren and #Sina might...

#radio Radio United Kingdom by EnjoyIT 1.0 http://t.co/YoV1dcFJ

#radio Radio United Kingdom by EnjoyIT 1.0 http://t.co/CbzcXPPO

Integration, focused investments to propel Windows Phone - ZDNet Asia: Gadget Helpline (blo... http://t.co/JZwEJCen http://t.co/KpTZdvuO

'Scramble' among vendors to acquire #bigdata co.s to bolster product offerings, manpower and market position. http://t.co/YWjgqj4r #in

Homegrown smartphone OSes gaining favor in China thanks to integration with local online services: IDC http://t.co/PJFx58yp #in

Companies see sustainability as critical for future biz growth, but face low margins in short term: study. http://t.co/I7jI8uix #in

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

5 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

5 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate