Friday, 19 October 2012

India leads the world in spam distribution, everyone else is to blame


Tired of getting spam in your mailbox? Don’t blame India.

According to SophosLab’s most recent “dirty dozen” report, Indians lead the world for the third quarter in a row in spam distribution. It’s like the worst hat trick ever.



So why shouldn’t we blame them?

India doesn’t lead the world in spam production — only distribution. And in the case of spam, these are very different. As it turns out, most spam is distributed unknowingly through malware-infected computers. The users don’t even know they’re spamming. So all this study really shows is that Indians are not using proper security measures on their machines and, because of this vulnerability, are used extensively for botnet spam distribution.

According to Spamhaus, an international non-profit that tracks spam production and distribution, the United States, China, and Russia are responsible for the top spots in world spam production. In fact, India doesn’t even make the top 10 on their list.



Sophos senior technology consultant Graham Culey made this very point when speaking on the newest Dirty Dozen report.
The latest Dirty Dozen report suggests that a not insignificant number of PCs in India are harbouring malware infections that turn PCs into spam-spitting zombie slaves, controlled by the cybercriminals who make money by punting junk emails to promote questionable goods, or simply use malicious spam to infect more computers.  The authorities in India need to make IT security education a priority.  One would be safe to assume that, if computer users in the country are being targeted in order to relay spam, they are likely victims of other online threats such as fraud. [Sophos]
 What researchers ought to be looking at are the dynamics of internet access in a fast developing country like India. Indians make up 5.3% of the world’s internet users, but only 10.2% of Indians use computers. So the fact that this small piece of the global internet pie is dishing out 16% of its spam is concerning and should certainly be something we watch as internet access expands in other developing countries.

Monday, 15 October 2012

Proxy service infects users


Here’s a fun fact: Not all cybersecurity services are equal.  Some might offer great monthly rates, but terrible bandwidth. Others might seem fast, but cost an arm and a leg. Still others might infect you with malware and turn your computer into a digital zombie.

That’s exactly what happened to hundreds of thousands of users subscribed to the Russian proxy service ProxyBox.

For the uninitiated, proxy services, like VPNs, allow users to connect to the internet through servers that assign a new IP address and location to the user. Unlike VPNs, proxy servers hardly encrypt anything and operate on speeds comparable to the United States Postal Service.

Anyhow, this particular site charged users $40/month for access to an extensive list of proxy servers all over the world. Not a bad deal for access to thousands of servers. The catch, though, is your computer is immediately enlisted in a botnet army using a Trojan called Backdoor.Proxybox.

As security company Symantec investigated the malware, researchers discovered it was also tied to three other websites, but all linked to one user.

The advertisements by this user provide a link between four dubious websites, all authored by the same individual: an entrepreneurial Russian hacker. These websites all revolve around proxies and malware distribution. One website provides proxy access (proxybox.name), another provides VPN services (vpnlab.ru), one provides private antivirus scanning (avcheck.ru), and one provides proxy testing services (whoer.net). These four sites are also connected by static cross-linking advertisements. The author of these websites provides the same ICQ support number to the users of the Web services. Several of these websites offer services for money and the payment gateways used are always the same: WebMoney, Liberty Reserve, and RoboKassa. 
We started to look into the payment accounts associated with these websites, and found out that they were tied to an individual with a Ukrainian name living in Russia. The additional details associated with this WebMoney account are undisclosed as we work with law enforcement in countries associated with the command-and-control servers.

Thursday, 11 October 2012

Kaspersky says 42% of laptop owners use their computers for both work and personal tasks

Sometimes it feels like we just don't really need that much security. After all, what do I care if Joe Hacker gets ahold of my photo albums or iTunes collection? Unfortunately, most of us also use our computers for things like online banking and other tasks involving sensitive data.

But a new survey conducted by the security gurus at Kaspersky says that 42% of users use their laptops for both work and play.
This is you giving away all your sensitive work info.
The survey shows that 27% of Apple owners and 25% of other laptop owners use their mobile devices for work. A personal laptop which is not reliably protected from cyber-threats as well as a corporate laptop used for personal purposes could cause a leak of confidential company data. If compromised, a personal device used for work can cause problems across the entire corporate network. [ITNewsAfrica]
And sadly, too many people apply their concepts of personal security to work.

But there is good news. First, most companies have some level of required security. Although we've seen about a bajillion instances of this being compromised or insufficient, it's something. Second, there are excellent options available to secure your personal devices to make them safe for work-related material.

Clearly, the best option here, is a good VPN. As I've said, probably a thousand times now, a solid VPN is the best line of security available to prevent cybercrime. Feel the urge to upload sensitive work documents to a company server via an unsecured WiFi connection? While surrounded by a platoon of hackers? Go for it.

A VPN like SumRando will encrypt absolutely everything coming out of your computer. So next time you want to email your medical records, or chat with your boss, think about doing it safely and securely with SumRando.

Wednesday, 3 October 2012

Google says state-sponsored attacks are on the rise

Back in June, Google's Gmail service began warning users it suspected were being targeted in state-sponsored cyber attacks.


Now, Google's information security team is telling us the threat is bigger than they thought. The team has apparently done some research and has, based on new evidence, found thousands of new cases of cyber attacks that are likely to originate from Middle Eastern states.
By Tuesday afternoon, several people--many of them American journalists and foreign policy experts--had already taken to Twitter to say they had seen the warning. Noah Schactman, the editor of Wired's national security blog "Danger Room," tweeted: "Aaaaand I just got Google's 'you may be a victim of a state-sponsored attack' notice. #WhatTookYouSoLong?" Daveed Gartenstein-Ross, a senior fellow at the Foundation for Defense of Democracies, also reported getting the message. As did Joshua Foust, a fellow at the American Security Project, a nonprofit research organization, who has written extensively about Afghanistan. [NYTimes]

Google’s team has declined to pinpoint any particular countries in the Middle East, but says there is a “slew” of them.

All we know is there is no time like the present to secure all of your digital data with a strong VPN like SumRando.