Share

Related Links

  • Kaspersky Lab
  • Elsevier Ltd is not responsible for the content of external websites.

Related Stories

  • GFI Software warns on impending Halloween malware
    The latest (September) malware report from GFI Software includes a warning that net users are very likely to see a volume of Halloween-based malware in the month ahead – a trend that the IT security vendor has been seen over the last three years.
  • From the Eye of the Storm: 2011 Information Security Predictions
    Last January, Infosecurity magazine published prognostications by the (ISC)² Advisory Board of the Americas (ABA) regarding the information security field in 2010. Unlike many who have attempted to envision the future, the ABA has gone back and reviewed the accuracy of its predictions and provided a letter grade for each. The ABA will then offer new predictions for 2011.
  • Valentine's Day – 10 days away, but already causing IT trouble
    Valentine's Day may be still 10 days away, but the volume of phishing and malware-infected email is already starting to rise, judging from reports from Trend Micro.
  • CA identifies fakeware, search engines and social networks as major information security threats of 2009
    In its year-end report on the state of IT security, Computer Associates (CA) has noted that fake security software (fakeware), poisoned search engine results and social networking sites such as Bebo, Facebook and Myspace, were the major information security threats of 2009.
  • Cisco annual information security report highlights
    Cisco has released its annual information security report for 2009 and the year-end analysis makes for some interesting reading, not least because it highlights the impact of social media on network security and the critical role that people - not technology - play in creating opportunities for cybercriminals.

Top 5 Stories

News

ISSE 2009: Geographically targeted attacks could be future of social network threats

07 October 2009

Just as social networks such as Facebook are seeing advertisement targeted depending on users’ settings and geographical location, so could malware and other threats be targeted specifically, said Stefan Tanase, senior security researcher at Kaspersky Lab, Romania, at the ISSE 2009 conference on 7 October.

He told the audience that messages on social networks could read along the lines of “a bomb has just gone off in xxx”, where the location is filled in on a city near the user based on geographical IP information.

Tanase said it is only a matter of time before these targeted attacks will become automated.

The same logic of fooling victims by using geographical information is being used by Nigerian phishing scammers that use translation software to target potential victims in their own language.

Social networks: increasing popularity = increasing threats?

In the ISSE 2009 presentation, Tanase demonstrated the increasing popularity, and importance placed on, social networks and how this makes them attractive to cybercriminals.

Recently, Facebook reached over 300 million users world wide, and with such a wide user base, social networks become more and more attractive to malware writers and cybercriminals.

According to Kaspersky figures, there were 43 000 samples of social networking malware at the end of 2008 and the number more than doubled every year.

A particular trait of social networking malware is that it tends to exploit the human factor luring users to infect their own computers.

The Web 2.0 worm Koobface, has proven itself very effective, Tanase said. It only spreads through social networks and its ‘success’ rate is much higher than for traditional email worms. Social networking worms have a 10% success rate, whereas email worms have a 1% success rate – perhaps because people trust direct messages from ‘friends’ more than emails from unknown senders. Social network malware exploits trust relationships, Tanase added.

Social networks do not pay enough attention to security as their main focus is to have high visibility and keep up with users and their demands. As a result, applications offered within social networks could contain malware running behind them without users being aware.

This article is featured in:
Application Security • Malware and Hardware Security • Public Sector

 

Comment on this article

You must be registered and logged in to leave a comment about this article.