IT security and control firm Sophos has published its Security Threat Report 2009 examining the threat landscape over the last twelve months, and predicting emerging cybercrime trends for 2009.
The Sophos Security Threat Report reveals that more malware is hosted on U.S. Web sites and more spam is relayed from American computers, than any other country. As evidence of this, when an American Internet company, accused of collaborating with spammers and hackers, was disconnected from the Net in November, there was a staggering 75 percent drop in spam.
"Not only is the United States relaying the most spam because too many of its computers have been compromised and are under the control of hackers, but itís also carrying the most malicious webpages," said Graham Cluley, senior technology consultant for Sophos. "We would like to see the States making less of an impact on the charts in the coming year. American computers, whether knowingly or not, are making a disturbingly large contribution to the problems of viruses and spam affecting all of us today."
Sophosís research reveals that in 2008 organized criminal gangs tripled their attacks against innocent Web sites, injecting malicious code to infect visiting home users and businesses. In addition, 2008 has seen concerted campaigns by hackers to pose as legitimate anti-virus vendors, creating new professional-looking Web sites and applications every day with the intention of scaring users into believing that their computers have been compromised. On average, Sophos identifies five new scareware Web sites every day, with the figure peaking at over 20 per day on occasion.
The detailed report, which documents the major Internet attacks of 2008, also reveals a startling rise in hackers spamming out malicious attachments, designed to compromise PCs in order to steal identities, money and resources. By the end of 2008, Sophos was tracking five times more malicious attacks arriving through files attached to emails than at the start of the year.
Furthermore, spammers and malware authors have shown a deadly interest in Web sites like Facebook, breaking into innocent usersí accounts to take advantage of trusted social networks, and send spam and malware.
"The last year proved beyond doubt that Internet hacking gangs are organized like never before, often working across borders to steal money and data from unsuspecting users. The volume of attacks has increased, with hackers using automated systems to break into vulnerable websites or generate new variants of their malware," continued Cluley. "People need to wake up to the reality that the completely legitimate website they are visiting could be harboring a dangerous malware infection planted by hackers. As we enter 2009 we are not expecting to see these assaults diminish. As economies begin to enter recession it will be more important than ever for individuals and businesses to ensure that they are on guard against Internet attack."
Internet attacks are overwhelmingly orchestrated via networks of innocent home computers that have, unknown to their owners, been commandeered by hackers. Sophos urges home users and businesses to properly defend their PCs with up-to-date anti-virus software, security patches and firewalls.
Stats and Findings at a Glance
- Biggest malware threats: SQL injection attacks against Web sites and the rising tide of scareware.
- New Web infections: one new infected Web page discovered by Sophos every four and a half seconds (three times faster than in 2007).
- Malicious e-mail attachments: five times more at end of 2008 than at the beginning.
- United States hosts the most malware on the Web (37 percent), usurping Chinaís position in 2007.
- U.S. computers relay the most spam (17.5 percent).
- Increasing allegations of state-sponsored cybercrime, as China, North Korea, Russia and Georgia are among those accused of espionage and assaults via the Internet.
U.S. Is the #1 Country Hosting Malware in 2008
In 2007, China was responsible for hosting over 50 percent of all web-based malware. However, in 2008 this position was stolen by the United States.
The top ten list of malware-hosting countries in 2008 reads as follows:
- United States 37.0%
- China (incl. HK) 27.7%
- Russia 9.1%
- Germany 2.3%
- S Korea 2.1%
- Ukraine 1.8%
- United Kingdom 1.7%
- Turkey 1.5%
- Czech Republic 1.3%
- Thailand 1.2%
For more information, including statistics on e-mail threats, detection techniques and spam-relaying countries, please download the 2009 Sophos Security Threat Report 2009.
Sophos provides solutions that enable enterprises all over the world to secure and control their IT infrastructure. Sophosís network access control and endpoint solutions simplify security to provide an integrated defense against malware, spyware, intrusions, unwanted applications and policy abuse. Sophos complements these solutions with innovative e-mail and Web security products that filter traffic for security threats, spam and policy infringements. With over 20 years of experience, Sophosís reliably engineered security solutions and services protect more than 100 million users in over 140 countries. Recognized for its high level of customer satisfaction and powerful yet easy-to-use solutions, Sophos has received many industry awards, as well as positive reviews and certifications.