Showing posts with label chinese spam. Show all posts
Showing posts with label chinese spam. Show all posts

Wednesday, March 31, 2010

Gaming Apps Increase Spam, Phishing by 50 Percent

Gamers beware – the next person you add to your gaming social network could be a spammer or phisher.

A new report from BitDefender found that gaming applications increase spam and phishing by more than 50 percent in social networks.

While most users of social networks are somewhat selective in who they add to circle of friends – filtering out those they suspect to be spammers – gamers often willingly add suspicious friends in an effort to expand their player community. Some entertainment apps require users to amass a large number of friends and supporters in order to attain high scores, prompting players to add people they might not normally add.

The most "successful" spammers are those that copy existing profiles.

BitDefender researchers created fake accounts to test this theory – one with no photo and few details, another with a photo and limited information, and a third with a photo and detailed personal information.

BitDefender used these profiles to subscribe to a generic interest group. After an hour, the first profile made 23 connections, the second made 47, and the third made 53. When BitDefender subscribed to social games groups, however, the acceptance rate increased. After 24 hours, the first profile had 85 connections, the second had 108, and the third had 111 connections.

"Users are more likely to accept spammers in their friends list when they are in a social network than in any other online communication environment," George Petre, BitDefender threat intelligence team leader and author of the case study, said in a statement.

Once spammers or phishers are accepted into a group, members run the risk of data and ID theft, hijacked accounts due to malware, and other threats. BitDefender found that 24 percent of people who accepted friend requests from the dummy accounts clicked a shortened URL even though they didn't know the person or where the link led. pcmag.com

Thursday, February 25, 2010

Microsoft uses law to cripple hacker spam network

Microsoft on Thursday said it combined technology with an "extraordinary" legal maneuver to cripple a massive network of hacked computers that had been flooding the Internet with spam.

The software titan's Digital Crime Unit got clearance from a US judge to virtually sever the cyber criminals' command computers from hundreds of thousands of machines worldwide infected with a Waledac virus.

"We decided the best tactic would be to literally build a wall between the bot-herder, the command computer, and all of the other computers -- effectively cutting the umbilical cord," said Microsoft attorney Richard Boscovich.

Microsoft got a US judge to grant an ex parte temporary restraining order that let the firm erect the cyber blockade without warning bot-herders, masters of the "botnet."

"It was of crucial importance that when we went out to sever the connection between the bot herder and the bots, that severing had to be done without him knowing," said Boscovich, who works in the digital crime unit.

Microsoft drafted a complaint that made a case to the court that the damage to computer owners worldwide, and to the software firm, was major enough to warrant "this rather extraordinary order," Boscovich said.

The mission to take down one of the ten largest botnets in the United States was referred to internally at Microsoft as "Operation b49."

Waledac is estimated to have infected hundreds of thousands of computers worldwide, letting its masters mine machines for information or secretly use them to fire off spam email.

Hackers typically infect computers with malicious codes by tricking owners into clicking on booby-trapped email messages or Internet links that plant viruses.

Bot-herders are then free to hire out botnets for nefarious tasks such as spewing spam or overwhelming legitimate websites with myriad simultaneously requests in what are known as distributed-denial-of-service attacks.

The Waledac botnet was believed to be capable of sending more than 1.5 billion spam email messages daily.

During a three week period in December, Waledac-infected machines sent approximately 651 million spam email messages to users of Microsoft's free Hotmail service, according to the software firm.

The spam included messages pitching online pharmacies, knock-off goods, and penny stocks. smh.com

Tuesday, November 24, 2009

Hong Kong man, three others jailed for spam scheme



A Hong Kong resident and three other men, including the self-proclaimed "Godfather of Spam," were sentenced to prison on Monday for their roles in an email stock fraud scheme, the Justice Department said.

The sentences, ranging from 32 to 51 months in prison, were handed down by US District Judge Marianne Battani in federal court in Detroit, the department said in a statement.

How Wai John Hui, 51, a resident of Hong Kong and Canada, was sentenced to 51 months in prison for wire fraud, money laundering and conspiring to commit wire fraud, mail fraud and to violate the Spam Act, it said.

Hui, the former chief executive of a company called China World Trade, was sentenced to three years of supervised release following his prison term and agreed to forfeit 500,000 dollars to the United States, it said.

Alan Ralsky, 64, of West Bloomfield, Michigan, and his son-in-law, Scott Bradley, 48, also of West Bloomfield, were sentenced to 51 months and 40 months in prison respectively on the same charges. AFP

Thursday, October 1, 2009

New computer viruses target banks, social networks


* Facebook, Twitter increasingly interesting for hackers

* Eight e-mails out of nine were spam in Q3

* Bank fraud software now cover tracks, use money mules

By Tarmo Virki, European technology correspondent

HELSINKI, Sept 30 (Reuters) - Cyber criminals are increasingly focusing their attacks on the hundreds of millions of users of social networks and on loopholes in bank security systems, security software vendors said on Wednesday.

At the same time, spam e-mail messages rose sharply in the third quarter, Symantec Corp (SYMC.O) said.

And as Facebook reached 300 million accounts in September, social networks and social media continued to attract criminals, smaller research firm F-Secure (FSC1V.HE) said in its quarterly virus report.

"As Twitter has grown in popularity, it has been increasingly targeted by worms, spam and account hijacking," F-Secure said.

Cyber criminals choose targets that are widely used, allowing them to go after the largest number of potential victims.

"Cyber criminals continue to follow the money," said Yuval Ben-Itzhak, technology chief at a small security software vendor Finjan, who on Wednesday revealed a new method criminals use to steal money from bank accounts and hide their tracks.

Finjan said it expects a growing trend of using new software that forges on-screen bank statements, concealing the true transaction amount to dupe account holders and their banks, and then sends the stolen money to money mules accounts.

"With the combination of using sophisticated Trojans for the theft and money mules to transfer stolen money to their accounts, they minimize their chances of being detected," Ben-Itzhak said.

SPAM, SPAM AND SPAM

The amount of spam in all e-mail traffic rose to 88.1 percent in the third quarter from 81 percent a year ago, said Symantec's MessageLabs in its quarterly report.

MessageLabs said botnets are now responsible for sending 87.9 percent of all spam.

Hackers take advantage of the PC vulnerability by booby- trapping websites with a malicious code that loads onto computers. Infected PCs are commandeered into a botnet, a network of hijacked computers. They are used for identity theft, spamming and other cyber crimes.  Continue (Reuters)

Tuesday, September 22, 2009

Chinese cyberattacks target media ahead of anniversary



BEIJING (Reuters) - Foreign media in China have been targeted by emails laden with malicious computer software in attacks that appear to be tied to the run-up to the National Day military parade on October 1.

While spam and viral attacks are not uncommon, the latest wave is part of a pattern of increasingly sophisticated emails tailored to tempt foreign reporters, rights activists and other targets to open infected attachments.

On Oct 1, the Communist Party is celebrating 60 years of rule over mainland China with a military parade. Beijing has tightened security ahead of the anniversary, with armed paramilitary troops at subway exits during rehearsals and neighborhood residents recruited to watch over the streets.

"There is definitely a pattern of virus attacks in the run-up to important dates on the Chinese political calendar," said Nicholas Bequelin of Human Rights Watch in Hong Kong. He noted that non-government organizations are also favorite targets.

"Whether the government is behind it, closes its eyes to it, supports it or has nothing to with it is unclear. There are also patriotic hackers, so there is no way to know for sure who is behind it."

While poor English used to be a giveaway, new techniques include mimicking a known and trusted sender, or resending legitimate emails from activist organizations with a fake, malware-laden attachment.

The impersonating emails require more effort by the mystery senders but they are also more likely to be opened than easily identifiable, anonymous spam.

Chinese employees working for foreign news organizations in Beijing and Shanghai got identical emails on Monday, each with an attachment carrying malware meant to exploit Adobe Acrobat software, a common application used to read PDF files.

The email, which appeared to be from an economics editor named Pam Bouron, was a polite request for help lining up interviews during an upcoming visit to Beijing. It was tailored so that "Pam" appeared to work for each news organization.

The clue was that Reuters does not have an economics editor named Pam Bouron. Others who received the "Pam Bouron" email include the Straits Times, Dow Jones, Agence France Presse, and Italian news agency Ansa.

Similar emails carrying viruses, also attacking foreign news agencies and non-government organizations, were common ahead of the Beijing Olympic Games last year. In March this year, researchers at Infowar Monitor in Canada found widespread cyber-infiltration of the Tibetan government in exile.

The "Pam Bouron" emails on Monday targeted Chinese news assistants, whose names often do not appear on news reports and who must be hired through an agency that reports to the Foreign Ministry.

They were followed by two suspicious emails on Tuesday morning received by many foreign reporters in Beijing. (Editing by Jan Dahinten)
Reuters