About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Malware
Construction kits used to create shape-shifting malware are now readily available
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Shape-shifting malware hits the web

Cyber-criminals changing malware signatures every few hours

Clement James, vnunet.com 15 May 2008
ADVERTISEMENT

Security experts have warned that new developments in malware are allowing criminals to stay one step ahead of security software.

Marc Henauer, head of the cyber-crime division at the Swiss Justice and Police Department, said in an interview last week that viruses and other malware now have the capability to change their signature every few hours.

This means that the attackers are often one step ahead of protection software.

Geoff Sweeney, chief technology officer at Tier-3, a behavioural analysis IT security firm, echoed the remarks.

"Self-changing code designed to dynamically evade recognition is a fact of life," he said. "It automatically adapts to the anti-spam and anti-malware engines that it encounters."

Unfortunately the know-how and construction kits used to create this shape-shifting threat are now readily available and are unleashing a wave of malware based on social engineering techniques.

"Highly targeted emails containing personalised information and shape-shifting Trojan attachments are the latest development," said Sweeney.

"Each positive infection increases the 'hit rate' for the next wave of emails sent out by the self-learning automated engines used by sophisticated attackers. "

Sweeney believes that a non rules-based monitoring process must be set up to defend all ingress and egress points covering SMTP, DNS, HTTP(s), IM etc.

"Once this is in place, defence against shape-shifting threats becomes possible as does the removal of any previously established covert data leakage channels that will be revealed and dealt with," he said.

See also:

MicrosoftThree 'critical' one 'moderate'  14 May 2008
SpamBogus fuel discount vouchers flooding inboxes  12 May 2008
GoogleBrowser monitoring extended to roaming users and off-site workers  09 May 2008
MP3Bogus movie and song files used to spread malware  07 May 2008

All Hacking
Tags: Malware

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Guildford, Surrey, United Kingdom | Enstar
 IT Development Manager/IT Development Project manager - Guildford - £40k - £60k plus benefits   Enstar (EU) Limited (formerly Castlewood (EU) Limited) is seeking an IT Development Project Manager and an IT Development Manager to ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
London, United Kingdom | Utilyx
Senior Business Analyst - London Highly professional individual capable of working at senior / board level with blue chip clients - shaping and driving the analysis and design of their energy management solutions Proven capability ... more >
(Poole, Bournemouth, Dorset, Hampshire), United Kingdom | RNLI
Analyst - Network & Telecoms - £35,000+ - Poole, Bournemouth, Dorset, Hampshire Our data and voice network team's impact on the organisation is considerable. And with something in the region of 5,000 direct users connected ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT