Tenfold rise in phishing sites hosting key-logging software
Tenfold rise in phishing sites hosting key-logging software

Key-loggers the new phisherman's friend

Combination attacks becoming the norm as users wise up to the scam

Iain Thomson

Phishing attacks are increasingly using key-loggers as another method to steal personal information, according to the Anti-Phishing Working Group (APWG).

These attacks usually redirect users to a bogus website and record details once they are entered. But the past six months has seen a tenfold rise in the number of phishing sites hosting key-logging software which can be transferred to a user's PC via an improperly patched browser.

Advertisement

"Phishing techniques are evolving in sophistication and complexity at a rapid pace," warned Mark Murtagh, technical director at Websense, a member of the APWG.

"As awareness of phishing among web users has grown, fraudsters are using new attack methods in addition to fake websites.

"One of the most common forms is where malicious code modifies host files and points end users to a fraudulent site despite them having typed the correct URL into their browser."

At the end of last year there were only 10 phishing sites being found each week hosting such code, but by March this had risen to 100. Some web pages remained up for over a month, but the average time to take down a phishing site was 5.8 days.

The move to key-loggers could reflect growing security awareness among consumers regarding online commerce.

Banks have always told customers that they do not ask for personal information via email, and are working with police and the government on other ways to fix the problem.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Firefox toolbar provides information on a website's hosting location

Firefox toolbar blocks phishing sites

Software cuts down on scams by spotting fraudulent URLs

Phishing IQ Test hopes to educate users

Surfers urged to take Phishing IQ Test

Get smart, not ripped off

Phishing attacks up by a third

Over 1,500 bogus websites discovered in November 2004

Gone phishing

Phishing is becoming ever more prevalent and ever more dangerous

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

BlackBerry Storm

Video Review: BlackBerry Storm

Technology editor Daniel Robinson looks at the first touch-screen device from Research in Motion

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Google Chrome

Microsoft has no need to worry about Chrome OS

Redmond may actually welcome the new arrival

Dr Aladdin Ayesh

Is it time for the Turing Test to retire?

It is nearly 60 years since Alan Turing devised a...

Security double standards

Broadband provider Tiscali has launched new figures showing an alarming...

Beach

Top 10 holiday gadgets

A wry look at the must-have beach items for any...

Primary Navigation