All the latest UK technology news, reviews and analysis

Malware writers mixing up attack tools

by Shaun Nichols

02 Mar 2011

Be the first to comment

  • Tweet this

Cyber criminals are increasingly employing multiple malware botnets for their attacks, according to a recent report from Symantec MessageLabs Intelligence.

The company said in its monthly security report that through late January and February, researchers spotted evidence that attacks from multiple malware families and botnets were coming from a single source.

Researchers noted that attacks from the Zeus, BredoLab and SpyEye malware all shared common characteristics and signs pointed to a collaborative effort between different malware families.

"During the first two weeks of February, MessageLabs Intelligence identified at least four different polymorphic engines in use by these server-side packers being used to change the code structure of the Zeus, Bredolab and SpyEye malware and to increase the number of variants of each," said MessageLabs Intelligence senior analyst Paul Wood.

"Considering the technical difficulty of maintaining this number of polymorphic engines and that each evolves quickly to generate such a large number of variants across these three families, this is one of the first times that MessageLabs Intelligence has identified malware collaborating on a technical level to this degree and volume."

Over the month, researchers also spotted an increase in the use of PDF files as attack vectors. Symantec noted that PDF attacks rose from 52.6 per cent of targeted attacks to 65 per cent. The company estimates that at the current pace, PDF files will deliver more than three quarters of targeted malware attacks by the middle of this year.

Symantec estimated that last month 1 in every 139 emails sent in the UK contained malware, while spam messages accounted for 81.1 per cent of the total volume.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

39%

0%

10%

51%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.