Simple clear advice in plain English

Keystroke logging on increase

Malware brings in bountiful harvest for cyber criminals

security/padlock-key

Keystroke loggers pose more risk to PC users than any other tool used for committing cybercrime, according to Kasperksy Lab.

In its latest report, Keyloggers: how they work and how to detect them part 1, published today, the security company said this threat was even more difficult to combat than phishing attacks.

Because this malware has proved so successful, the number of keystroke loggers has risen rapidly. It found a growth of 500 per cent between January 2003 and July 2006.

The Kaspersky Lab database currently contains records for more than 300 families of keyloggers – and this number does not include keyloggers that are just one component of compound threats, in which the spy component provides additional functionality.

The reason for the growth in this malware said Kaspersky is it works so well. The personal information keystroke loggers harvest paves the way for more serious targeted attacks and it is difficult for the end user to detect and remove.

Kaspersky senior technology consultant David Emm said: "Another problem is that a keystroke logger isn't necessarily harmful - it can be neutral. If it comes wrapped with a Trojan then obviously it is and security products will find this.

"But as this software can be neutral, people use it, for example, to check what their children have been doing online, or suspicious spouses use it to check up on their partner. It therefore has to be identified as potentially unwanted by security software."

Unfortunately for consumers, keystroke loggers are becoming more sophisticated. They can be inadvertently downloaded from an infected website, email attachment or by clicking on links.

Once on a PC, they can track websites visited by the user and only log the keystrokes entered on the websites that are of particular interest to the cybercriminal; for example bank sites.

Many keyloggers now use rootkit technology to prevent detection manually or if the person is using an internet security product such as anti-spyware and anti virus products.

Once a cybercriminal has a user’s confidential data, they can easily transfer money from the user’s personal accounts. Keyloggers can also be used in industrial and political espionage to access proprietary commercial information and classified government data.

Kaspersky said there should be more proactive protections such as an increased use of one-time passwords or two-step authentication put in place so that this information is of no use to the criminals.

The company will release the second part of the report on 12 April 2007.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

computer security

Stories about indestructible TDL-4 botnet "alarmist" says Kaspersky

Security company says TDL-4 rootkit is sophisticated and intelligent but can be avoided

virus-threat-flying-saucers-illustration

Kaspersky warns of a virtually indestructable malware

Security company raises warning about the most sophisticated malicious software it has seen to date

f-338-don-t-pay-for-security

Get free PC security software

Free security tools can keep your computer safe – we provide a list of free security software and explain how to get the programs that suit you best

Question & Answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Q.How do I stop Windows 7 search?

> Read the answer

Best deals on the web

img

Apple iMac 21.5" (MC309)

£929.00- Buy it now

img

Dell Inspiron 620 ST Intel Core i3-2100 3.10GHz / 3GB / 500GB / DVDRW / Win 7 Home Premium

£299.00- Buy it now

img

Apple iMac 27" (MC813)

£1353.99- Buy it now

Great benefits for subscribers!

Most popular articles

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

CAD

Computer Aided Design. Software used to create 3D models.

Great shopping deals from Computeractive