Bill Mullins’ Weblog – Tech Thoughts

Stay On Top of Malware – PandaLabs Second Quarter Malware Report

July 7, 2009 · 2 Comments

Courtesy of Panda Labs

Panda Security, the Cloud Security Company, announced yesterday that PandaLabs, Panda Security’s laboratory for detecting and analyzing malware, announced the findings from its second quarterly report of 2009 and determined that Trojans accounted for 70 percent of all new malware between April and June 2009. The full report can be downloaded from Panda Security.

image

One of the most notable findings of the report is the 6.25 percent drop in spyware, which now represents just 6.9 percent of all new malware. In contrast, adware rose dramatically over this period, from 7.54 percent in the previous quarter to 16.37 percent.

This is largely due to the increase in fake antivirus applications, a type of adware that passes itself off as a legitimate security solution. As for worms, their percentage has also risen slightly, now accounting for 4.4 percent of all malware.

Trojans were also responsible for more infections than any other type of malware over this period. This type of malware was behind 34.37 percent of all infections detected by PandaLabs, an increase of 2.86 percent with respect to the previous quarter.

image

Adware infection levels remained stable, accounting for 19.62 percent of the total.

Worms increased slightly (0.89 percent), staying in the picture due largely to the effectiveness by which they spread. Dialers, at 4.48 percent, stubbornly refused to disappear despite the overriding trend for broadband instead of dial-up connections.

In terms of specific strains of malware, the number one ranked specimen between April and June 2009 was Downloader.MDW, a Trojan designed to download other malware on to computers. The Virtumonde spyware and Rebooter.J Trojan were also among the malicious codes that caused most infections.

image

When broken down geographically, Taiwan continues to top the list with 33.63 percent of computers infected with active malware. Turkey and Poland come next, with just under 30 percent. Three Scandinavian countries, Sweden (14.2 percent), Norway (12.48 percent) and Finland (12.17 percent), are the countries with the lowest number of computers infected by active malware during the first half of 2009.

Malicious use of Twitter

A worm appeared in April which used a cross-site scripting technique to infect Twitter users when they visited the profiles of other infected users. It then infected the new user’s profile to continue propagating. New variants appeared, and finally the creator’s identity was revealed: an individual named Mikey Mooney, who apparently wanted to attract users to a service competing with Twitter.

In early June, Twitter was the focus of other attacks, this time using different techniques, most predominantly, BlackHat SEO. Twitter has a feature called “Trending Topics”, which is a list of the most popular topics that appears in the interface of all Twitter users. When users select a topic through this feature, they  see all ‘tweets’ published that are related to this issue.

In this case, malicious users were writing tweets about the topics listed in Twitter Trends with links to malicious Web pages from which malware was downloaded. The first attack focused on just one of the topics, but just a few days later the scope of the attack increased and all popular topics contained malicious links.

When the actor David Carradine died, there were hundreds of malicious tweets in just a few hours, and the same thing occurred with other popular issues on Twitter.

The second anniversary of Collective Intelligence, a detailed analysis of the Waledac worm, trends regarding the sending of malware via spam and the evolution of BlackHat SEO techniques are just some of the other issues covered in the PandaLabs Quarterly Report.

If you have a serious interest in keeping up with prevailing trends in malware, this report is a must read.

Download at: Panda Security.

Categories: Don't Get Hacked · Interconnectivity · Internet Safety · Internet Security Alerts · Malware Advisories · Malware Reports · Online Safety · Panda Security · PandaLabs · Tech Net News · Viruses · Windows Tips and Tools · worms
Tagged: , , , , , , ,

2 responses so far ↓