Web Threats Booming: APWG First Half Report

The Anti-Phishing Working Group (APWG) released their first half "Phishing Activity Trends Report" with some startling statistics. For those that have not heard of the APWG, the organization devoted to the elimination of phishing and identity theft scams.

The report gives statistics on many trends inlcuding phishing trends, rogue AV, keyloggers and others and fully reinforces the fact that the number of threats on the internet continues to grow.

Some of the staggering statistics:

  • "Rogue anti‐malware programs are proliferating at anunprecedented rate. In Q1, 2009, more new strains of rogue antimalware were created than in all of 2008. In H1, 2009, the number of such programs grew 585 per cent."
  • "Banking trojan/password‐stealing crimeware infections detected increased during more than 186 percent between Q4, 2008 and Q2, 2009."
  • Total number of infected computers rose more than 66% between Q4 2008 and Q2 2009.
  • 16.9% of scanned computers were infected with a banking trojan or keylogger.
The graph below details the massive explosion of Rogue AV programs. There is seemingly hundreds of variants and new distribution sites added daily. As noted by PandaLabs Technical Director Luis Corrons, "The primary reason for the creation of so many variants is to avoid signature‐based detection by legitimate antivirus programs. The use of behavioral analysis is of limited use in this type of malware because the programs themselves do not act maliciously on computers, other than displaying false information.”



This exponential increase and persistent threat of Rogue AV has some (maybe just me) calling 2009 the year of Rogue AV.

 
Another alarming trend detailed by the report was the increased amount of infections, particularly banking trojans and password stealers. With 55% of machines scanned infected with some type of crimeware and 17% of those machines with a banking trojan, it's clear this is a dangerous time for the web.

Also of note is that China has surpassed the US in the hosting of phishing based Trojans and Downloaders, a trend which figures to continue.

The full report can be downloaded at:  http://www.antiphishing.org/reports/apwg_report_h1_2009.pdf

Note: Graphics and Quotes taken directly from the PDF above
 

Green Cloud Security

Web security and converged threats are among the biggest issues in network security. Green Cloud Security provides the latest information on these threats.

Follow us on Twitter and RSS!

twitter / greencloudsec



Term of Use

My Blog List

SANS ISC SecNewsFeed

Security Bloggers Network