But contact information is sparse - probably because the merchandise advertised on the site isn't exactly legitimate. What's available there is malicious code that webmastersComputer Security Made Easy ebook
As organised gangs of crooks increasingly turn to cybercrime, Web sites like that one are coming to represent the new face of malware development and distribution, according to security researchers. They said that unlike earlier malware writers, who tended to distribute their code to tight groups of insiders or within underground newsgroups, the new breed hawks its wares in a more professional manner.
Over the past year or so, "we've been seeing a growth of highly organised 'managed exploit providers'" in countries that don't have extradition treaties with the U.S., said Gunter Ollmann, director of security strategies at IBM's Internet SecurityIBM 1898 KidDesk Internet Safe
The available exploit code is usually encrypted, uses a range of morphing techniques to evade detection by security software and can exploit various vulnerabilities, according to Ollmann. He added that many exploit providers simply wait for Microsoft Corp.'s monthly patches, which they then reverse-engineer in an effort to create new code that can take advantage of the disclosed vulnerabilities.
Don Jackson, a security researcher at SecureWorks Inc. in Atlanta, discovered one such site in January while investigating a Trojan horse called Gozi. Jackson said Gozi was designed to steal data from encrypted Secure Sockets Layer streams and send it to a server in St. Petersburg, Russia. The program took advantage of a vulnerability in the iFrame tags of Internet Explorer and had apparently been planted on hosted Web sites, community forums, social networking sites and sites belonging Small BusinessesMicrosoft Access Small Business Solutions
According to Jackson, criminals looking for stolen passwords, credit card numbers and other personal information could log in, view indexed data and run queries. He said each query had a price associated with it, stated in WMZ - a form of electronic currency supported by Moscow- based WM Transfer Ltd's WebMoney OnlineMake Money Online Yahoo Google
The Gozi code itself appears to have been purchased by 76Service from a Russian hacking group called the Hang Up Team. Jackson said such code typically costs about $1,000 to $2,000, depending on how sophisticated it is. Often, he added, groups such as the HangUp Team also offer a detection-monitoring service through which they keep an eye on antivirus vendors so they know when security tools can detect their malware.
"We're not talking about kids doing it for kicks over the weekend anymore," said Yuval Ben-Itzhak, chief technology officer at Finjan, a San Jose-based security software vendor. "This is real cash, real money Learn Forex Trading Money Online in easy steps
0 Response to 'Malware Attacks on sale?'
Post a Comment