::Trend Micro Threat Resource Center::

27 June 2009

Simple steps to keep your identity safe online

June is Internet Safety Month, and simple identity theft protection steps such as shredding your mail and keeping careful tabs on your bank accounts and credit cards are essential first layers of protection against identity thieves. But there is an open door in many homes that is inviting criminals into personal information, and it is often left unprotected - the computer.

A recent study by online security provider Tiversa found more than 13 million online files have been breached over the last year, and P2P sharing services seem to be a popular way for criminals to get in.

There are steps consumers can take to reduce their risk for identity theft through the use of P2P file sharing services. LifeLock offers the following online safety tips:

* Install file-sharing software carefully, taking special note of default settings and permissions
placed on shared folders

* Use security software and make sure you keep it up-to-date. You can set most anti-virus and
anti-spyware protection programs to update automatically and regularly

* Be sure to close your connections when you are done with a file-sharing session. Closing the
window doesn't automatically close the connection, which could leave your computer's information vulnerable

* Maintain backups of all important documents. This will ensure your information is maintained
for your personal use should you need to delete it from your computer or any file

* Talk with your family about safe file-sharing practices, and create separate user accounts for
others who may use your computer. By separating accounts you can prevent others from
installing software on your computer that may expose your information

* Before providing personal information to your doctor, attorney, insurance company, employer
or anyone else make sure to ask for details on how they will keep this data secure

Identity theft is costing Americans more than $1.8 billion annually, according to the Federal Trade Commission, and the latest FTC reports show the number of identity theft complaints has grown by 80 percent since 2000. Among the forms of identity theft and fraud reported to the FTC in 2008 are credit card fraud, medical benefit fraud and falsified government or employment documents.

26 June 2009

Hackers Targeting Social Network Users

Users of online social networks may be more vulnerable to financial loss, identity theft and malware infection than they realize, according to a new survey from security software firm Webroot.

The survey found two-thirds of respondents don't restrict any details of their profiles from being visible through a search engine like Google and over half are not sure who can see their profile.

About one third include at least three pieces of personally identifiable information and more than one third use the same password for multiple sites. In addition, one quarter accept "friend requests" from strangers.

"The growth of social networks presents hackers with a huge target. The amount of time spent on communities like Facebook last year grew at three times the rate of overall Internet growth," said Mike Kronenberg, chief technology officer of Webroot's Consumer business.

"Three in ten people we polled experienced a security attack through a social network in the past year, including identity theft, malware infection, spam, unauthorized password changes and 'friend in distress' money-stealing scams. The first step to staying protected is being aware of what the threats are and knowing how to help prevent them."

Cybercriminals use various types of trickery and malware to take advantage of risky behaviors. One common tactic is phishing, which hackers use to entice victims into downloading an infected file, visiting a risky site outside the social network, or wiring money to a "friend in distress."

Webroot says in recent months it has seen an increase in these types of attacks on social networks, including "Trojan-MyBlot," which targeted users of MyYearbook.com and others targeting Facebook users.

"Hackers lure users into taking actions they shouldn't by making it appear as if a friend within their social network has sent them a message - only the message is from a hacker who's hijacked the friend's account," continued Kronenberg.

"We've seen instances where a salacious yet poorly worded message like, 'This video of u is evrywhere' includes a link that, when clicked, prompts the user to download a seemingly legitimate file which, once on your PC, can do a number of things -- spam your friends, monitor your online activity or record your personal information."

25 June 2009

Survey reveals social networkers' risky behaviors

Members of online social networks may be more vulnerable to financial loss, identity theft and malware infection than they realize, according to a new survey from Webroot.

Surveying over 1,100 members of Facebook, LinkedIn, MySpace, Twitter and other popular social networks, Webroot uncovered numerous behaviors that put social networkers' identities and wallets at risk. Among the highlights:

* Two-thirds of respondents don't restrict any details of their personal profile from being
visible through a public search engine like Google;
* Over half aren't sure who can see their profile;
* About one third include at least three pieces of personally identifiable information;
* Over one third use the same password across multiple sites; and
* One quarter accept "friend requests" from strangers

Social Networks Present New Opportunities for Cybercriminals
Cybercriminals employ various types of trickery and malware to capitalize on risky behaviors. One common tactic is phishing, which hackers use to entice victims into downloading an infected file, visiting a disreputable site outside the social network, or wiring money to a "friend in distress."

In recent months, Webroot has seen an increase in these types of attacks on social networks, including "Trojan-MyBlot," which targeted users of MyYearbook.com, and others targeting Facebook users including "Koobface" and several spread through the domains "mygener.im," "ponbon.im" and "hunro.im."

Sophisticated means to execute attacks on social networks: The Webroot survey respondents who reported experiencing identity theft, a hijacked account and unauthorized username or password changes may have been victimized by hackers who were able to access their profiles and guess their passwords based on the personal information they included.

For a summary of the key findings, pls read here.

24 June 2009

Microsoft's launches free AV offering

Microsoft launched a beta version of its forthcoming free antivirus software on Tuesday, aiming to protect users who, for one reason or another, have not installed security applications on their computers from other providers.

The security software, dubbed Microsoft Security Essentials, will block known viruses and prevent some malicious behavior normally associated with stealthy malicious software known as rootkits, the company stated. Microsoft will create the definitions for the product using samples collected from more than 450 million PCs around the world.

The company flagged rogue security software as a key problem that its software could eliminate by offering a free, trusted alternative.

"With malware attacks increasing in both number and severity and the increasing incidence of rogue security software, quality anti-malware protection delivered from a trusted source is a must-have for today's PC users," the company stated.

Microsoft announced in November that it would be phasing out its Windows Live OneCare service, instead offering a limited free antivirus service to Windows users. The software will not provide other security measures — such as managed firewalls, performance tuning and data backup services — common in other security products, include Microsoft's Windows Live OneCare service. Instead, the company aims to create a basic anti-malware service that does not impact PC performance in hopes that attackers will have more trouble infecting customers' computers.

The company plans to allow customers to download the initial beta of the software on Tuesday, starting from 9 a.m. PT and launch the final product by the end of the year.

23 June 2009

Although Facebook is supposed to have clear privacy restrictions, it appears that a loophole has been identified.

FBHive reported the following: "With a simple hack, everything listed in a person’s “Basic Information” section can be viewed, no matter what their privacy settings are. This information includes networks, sex, birthday, hometown, siblings, parents, relationship status, interested in, looking for, political views and religious views."

In the next few days we can expect to see how this hack worked and how the problem was uncovered in the first place.

It took Facebook 15 days to fix the problem and today they issued the following statement: "We have identified this bug and closed the loophole. We don’t have any evidence to suggest that it was ever exploited for malicious purposes."

19 June 2009

Finjan Finds Infected PCs Selling For Half A Cent

Most people know that powerful computer criminals don't all have setups similar to those of James Bond villains; a lot of damage can be done with just a little bit of outdated equipment. But a new report from Finjan drives home how very accessible botnets have become.

People who live in certain Asian countries are able to buy batches of 1,000 infected PCs for just $5, according to Finjan. This means just about anyone who can touch a computer, whether it be at a friend's apartment or an Internet cafe, can afford "in."

The highest price Finjan found elsewhere was in Australia, where the same number of infected PCs go for $100. A middle-class eight-year-old might be able to handle that with his Christmas money.

This is all possible due to the existence of the Golden Cash network. A Finjan statement explains, "The trading platform utilizes all necessary components (buyer side, seller side, attack toolkit, and distribution via 'partners')." And if that sounds pretty sophisticated, the statement does continue, "This advanced trading platform marks a new milestone in the cybercrime evolution."

Yuval Ben-Itzhak, CTO of Finjan, also added, "Looking at the list of compromised PCs we found, it is clear that no individual, corporate or governmental PC is safe."

Unfortunately, such trading platforms are probably here to stay. Cybercriminals can make as much as $400 in profit off of each batch of infected PCs, and so will be sure to keep at it for as long as possible.

Finjan just recommends using a Secure Web Gateway to help stop your computers from becoming infected in the first place. The full second issue of Finjan's Cybercrime Intelligence Report is also available for free if you'd like additional information regarding the problem.