KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

MS: Trojan Horses Increase 300 Percent


section: microsoft, for your questions: KezNews forum, 24.4.2008

If your system gets hacked, chances are it will be from a Trojan. A Microsoft (NSDQ:MSFT) Security Intelligence report tabulated a 300 percent increase in the number of Trojan downloaders and droppers the last half of 2007 -- a trend which security experts say will continue to exponentially grow.




Consistent with malware trends, the biggest security threats are moving to the Web and consequently experts say that they expect to see the number of Trojans rise exponentially. The reason? Trojans are by far the most "financially interesting" malware, experts say.

"It's the path of least resistance," said Doug Camplejohn, CEO and cofounder of security company Mi5. "For most enterprises, it's where they're least protected."

These Trojans allow attackers to install a small downloader onto unsuspecting users machines, usually without their consent, in order to record passwords, credit card, bank account numbers and other personal identifying information.

The significant increase in Trojans far outweighed the upswing in previous years, becoming increasingly evident that Trojan downloaders are replacing other types of malware, such as infected e-mail files and attachments, security experts said.

"Executables used to be delivered by other mechanisms," said Jimmy Kuo, principal architect for the Microsoft Malware Protection Center. "Now almost all other methods have gone by the wayside to those that simply lure people to [infected] Web sites."

Camplejohn said that the shift to Web-related threats was tied largely to the prolific, and rapidly self-replicating nature of botnets.

"If you think about it, Trojans kind of provide the best bang for the buck for a malware writer," said Camplejohn. "A smart hacker is going to spend their time and efforts to create a Trojan, in the long run, they're going to be rewarded better for that effort.

"Botnets bring money. Therefore Internet criminals write Trojans," he added. "Why do you write Trojan? Because that's where the money is today."

Microsoft's fourth Security Intelligence Report, which examined the security landscape between July and December 2007, provided analysis and perspective on software vulnerabilities, exploits, malicious software and potentially unwanted software -- software that occupies a gray area, such as adware -- observed by Microsoft security professionals over the last several years.

Meanwhile, the report found that the prevalence of rogue security software also continues to increase, which can be delivered via Trojans as well as by other social engineering methods, such as phishing.

Not surprisingly, the report found that newer versions of Microsoft applications were more resistant to vulnerabilities -- a fact which security experts said was due to increased awareness of security threats rather than failing to incorporate security into its products.

"We all make mistakes, and we learn from those mistakes," said Kuo. "Basically it's not that we didn't think of security, we just know more about it now."

Unlike previous versions, numerous current versions of Microsoft products now incorporate automated software updates, and are less prone to infection in general, Kuo said.

Surprisingly, not everything was on the rise. Bucking recent trends, exploits, malware and hacking accounted for only 13 percent of security breach notifications during the second half of 2007 and only 23 percent of all security breach notifications between 2000 and 2007.

Also countering previous security trends was a decline in the disclosure of vulnerabilities rated as high severity -- altogether, only 32.2 percent of known security vulnerabilities in the analyzed products had publicly available exploit code in 2007. In addition, vulnerabilities requiring a low level of complexity to exploit also continued to decrease.

source: crn.com

send email Send link 2 friend  |  Permalink
<< previouse article
Multilingual User Interface (MUI) Packs for Windows Vista SP1 Updated
next article >>
Automatic distribution of Windows Vista SP1 begins today

MORE RELATED ARTICLES:
Google vows to increase Gmail storage limit || Microsoft Eyes 40 Percent of Smartphone Market by 2012 || New MSN Messenger Trojan Spreading Quickly || Better living without MS Office || Who uses MS Live Search?

Comments(4)

Should scan first

By Dodger on 25.04.2008 - 02:04
will if people knowingly go to bad web sites, open bad email attachments and download files without scanning them first they deserve to get infected regardless of the os. idiots!

Something doesn't meet the eye...

By whozzit on 25.04.2008 - 03:04
i've been running xp professional since it was in it's beta form, along with appropriate third party protection. these machines are online 8 to 12 hours a day. trojans have not been a problem.

Common Sense. Use it.

By ham on 25.04.2008 - 10:04
vista, no protection, did a virus scan about 2 days ago, nothing, only some tracker cookies.

virus protection is not going to keep up with the viruses, only safe browsing is.

hints: don't download keygens/etc... stay off of crack/serial/p2p/etc... if it seems shady, don't download/install it... use common sense.

Hail the experts

By Bounz on 25.04.2008 - 13:04
ah yea sure, wait till the company releases an official kgen


Add a Comment



Subject:
Your name (nick):
Text:
HTML, BBCode disabled in comments