On CBS.com: Play Survivor Video Trivia Now
BNET Business Network:
BNET
TechRepublic
ZDNet

By Alorie Gilbert
Posted on ZDNet News: May 5, 2005 2:07:00 AM

Phishers are increasingly using new methods to nab sensitive information from Internet users, according to data from Websense Security Labs.

In recent months, the researchers at security software company Websense detected a rise in schemes involving malicious programs known as keyloggers, according to the March phishing trends report released Wednesday by the Anti-Phishing Working Group.

Related feature
Have you been phished?
Check here to see whether an e-mail that appears to be from your bank or an online merchant is actually an attempt to defraud you.

The technology, which records the keystrokes of people using infected machines, could be designed to help phishers stay one step ahead of honest folk. In the past, attackers have relied mainly on e-mail messages that lure victims to malicious Web sites, where they are duped into disclosing logins and usernames for banking sites and other sensitive online accounts. The messages are typically spoofed to look like they come the bank or other trusted provider.

The keylogger programs are built specifically to capture login names and passwords for online bank accounts and to send them to the attackers, Websense Security Labs said. They typically exploit vulnerabilities in Microsoft's Internet Explorer browser program.

Each week in March and February, Websense uncovered as many as 10 new keylogger variants and more than 100 new Web sites set up to infect computers with them. That's up from November and December, when the company's researchers identified an average of one-to-two new variants and 10 to 15 Web sites per week.

People can infect their machines with keylogger programs in numerous ways, including opening bogus e-mail attachments, downloading programs online or simply visiting a fraudulent Web site.

Keylogger attacks are a particular problem in Brazil, where recent two schemes targeted more than 100,000 .br e-mail accounts, the report found. However, the machine that hosted the malicious code in one of the attacks was located in California.

Phishers have previously turned to instant messaging, faked news feeds and have preyed on people that mistype the Web addresses of popular online destinations, such as Google.

The United States is host to more phishing sites than any other country, followed by China and Korea, according to the APWG report. In March alone, people reported more than 13,000 phishing-scheme e-mails to the group.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 33 Talkback(s)
we are waiting .....
for the IP address of that zombie you claim! proof it. (Read the rest)
Posted by: matrixdomain Posted on: 05/06/05 You are currently: a Guest | | Terms of Use
Here's a question ...  worknman | 05/04/05
Step up MS  Richard Flude | 05/04/05
Duh, reply to story is the other button  Richard Flude | 05/04/05
You're making an assumption...  gfeier | 05/04/05
Not just an assumption  Richard Flude | 05/04/05
That leaves 66 %...  gfeier | 05/05/05
Absolutely right  ebrke | 05/05/05
To easy to avoid detection  voska | 05/05/05
MS Windows is the problem, it's insecure and flawed!  matrixdomain | 05/04/05
I tell ya, I'm going BACK to my Mac for online banking...  BitTwiddler | 05/05/05
B of A  Bill4 | 05/05/05
Blame the OS  bobiroc | 05/05/05
The myth that MS is attacked because its more popular  whisperycat | 05/05/05
The myth that MS is attacked because its more popular  whisperycat | 05/05/05
The Big Picture  bobiroc | 05/05/05
Sorry but the MS marketing argument won't work  whisperycat | 05/06/05
No!  bobiroc | 05/06/05
Now if I was a scammer ...  George Mitchell | 05/05/05
Guys like you give Linux a bad name  Squawkbox | 05/05/05
Thanks for another unbiased post  I_am_hellion_z | 05/05/05
What we need to do!  chalkbd@... | 05/05/05
Not to worry  nucrash | 05/05/05
3.0 Mike Cox I am not.  nucrash | 05/05/05
Don't be so hard on yourself  Michael Kelly | 05/05/05
Not A Problem At Our Organization  itanalyst | 05/05/05
7.5 for the rookie  luke_sg | 05/05/05
If this ever becomes a problem with Linux ...  George Mitchell | 05/05/05
you wish because you don't know  matrixdomain | 05/05/05
MS is to blame b/c they have done nothing to fix the probs!  kbeartxzd | 05/05/05
Linux isn't exactly innocent  severian@... | 05/06/05
really?  matrixdomain | 05/06/05
you are a fraud  matrixdomain | 05/06/05
we are waiting .....  matrixdomain | 05/06/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here