Welcome to the age of localized malware

February 21, 2008, 11:01 AM —  IDG News Service — 

The program is nasty. It deletes pictures and movies from your hard drive and
then it teases you: "Even though Mr. Kaneko was found guilty, you are still
using Winny. I really hate such people," taunts an animated woman on your
screen.

Welcome to the age of localized malware.

Over the past two years virus writers have increasingly targeted their malicious
programs to users in different regions of the globe, creating programs that
are specially designed to infect users in countries like Japan, Brazil, China
or Germany.

Take the taunting Trojan, which goes after users of the Winny file-sharing
program. (Winny creator Isamu Kaneko was convicted of abetting copyright violations
in late 2006) Winny is file-sharing software that is incredibly popular in Japan,
but virtually unknown outside of the region. Still, it's been the target of
several malware programs, according to Dave Marcus, security research and communications
manager for McAfee Avert Labs. "Japan has some really unique factors that
we just don't see anywhere else," he said. "There are a couple of
malware writers in Japan who don't like people who illegally share content."

Previously, attackers would write programs that would affect the largest possible
number of users, but that's no longer necessarily the case, Marcus said. "What
we've noticed over the last couple of years is that a growing amount of malware
is localized."

McAfee believes that there are a few reasons behind this shift. For one thing,
writers no longer want the worldwide attention and law enforcement action that
was garnered by outbreaks such as Sasser and Netsky.

And with users becoming more wary, hackers have to be crafty with their attacks
-- creating more targeted malware that victims are unlikely to have seen before.
Another factor is that criminals are increasingly targeting their attacks to
regions that have weak cybercrime enforcement, McAfee believes.

Regional attacks also cater to regional tastes. Online banking is widely used
in Brazil, so much of the malware there tries to steal banking usernames and
passwords. In China, online gaming is so popular that Chinese World of Warcraft
password stealers are now the second-largest class of malware tracked by McAfee,
Marcus said.

These regional attacks are part of an explosion of viruses and Trojan programs
that is making life more difficult for people companies like McAfee that track
and intercept the malware. In 2006, the company identified 53,537 unique pieces
of malware according to data
set to be published Thursday
in Sage, McAfee's semi-annual magazine devoted
to security issues.

Last year that number jumped 246 percent to 131,862, and it could double again
this year. By the end of 2008, McAfee expects to be identifying about 750 pieces
of malware per day.

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff

Crimeware: Understanding New Attacks and Defenses
By Markus Jakobsson, Zulfikar Ramzan
Published Apr 6, 2008 by Addison-Wesley Professional. Part of the Symantec Press series.
Enter now! | Official rules | Sample chapter

Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures
By Peter Thermos, Ari Takanen
Published Aug 1, 2007 by Addison-Wesley Professional.
Enter now! | Official rules | Sample chapter

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources