M86 Security Labs report provides insight to plan security for 2012

Opinion
Feb 10, 20126 mins

The researchers at M86 Security Labs have just released their semiannual report about security trends and malware, spam and phishing activities they observed in the latter half of 2011. Use the 20/20 hindsight of this report to plan ahead for your security measures in 2012.

M86 Security Labs just released its latest Security Labs Report detailing key trends and developments in Internet security. M86 is a group of security researchers who specialize in Web and email threats. They follow Internet security trends and monitor and analyze malware activity, spam and phishing, including newly discovered vulnerabilities and the exploits using them in the wild. Data and analysis from M86 Security Labs is continuously updated and always accessible online at https://www.m86security.com/labs.

This recent report covering the last half of 2011 highlights some interesting emerging trends:

• Targeted attacks have grown more sophisticated, with evidence that cybercriminals are pursuing not only commercial organizations, but also government and infrastructure targets. Moreover, with the growing use of fraudulent and/or stolen digital certificates, these attacks have become more successful and evasive.

TECH DEBATE: Are we winning the cybersecurity war?

• The exploit kit market has shifted dramatically toward the Blackhole exploit kit, which has the capability to update frequently and rapidly to take advantage of application vulnerabilities.

• Even though there has been a precipitous drop in spam volumes, more spam messages are likely to contain malicious links or attachments.

• There has been a significant increase in fraud and malware proliferation using social networks as a conduit.

Targeted attacks are growing more sophisticated

While targeted attacks are not new, the serious growth in incidents during the second half of 2011 is real cause for concern, not just for companies but for entire countries. According to the report, targeted attacks became sophisticated and pursued a wider range of organizations, including commercial, national critical infrastructure and military targets.

One of the new attack vectors researchers identified is the use of fraudulent digital certificates. The report indicates the DigiNotar intrusion resulted in the “fraudulent issuance of hundreds of digital certificates for a number of domains, including Google, Yahoo!, Facebook, and even for some intelligence agencies, such as the CIA, the British MI6 and the Israeli Mossad.”

M86 Security stresses that organizations must plan and deploy a multi-layered security policy to minimize risks of a successful targeted attack. Recommendations are provided in the report.

Exploits: Don’t fall into a Blackhole

The exploits monitored during the second half of the year targeted a variety of products, including Microsoft Internet Explorer, Oracle Java, Microsoft Office products and, quite commonly, Adobe Reader and Adobe Flash. What’s really astonishing is that some of the top vulnerabilities that criminals continue to exploit have not only been known for years, but fixes have also been available for years.

For example, M86 found that the most exploited Web-based vulnerability is Microsoft Internet Explorer RDS ActiveX, which was both discovered and patched in 2006. Here we are, six years later, and this vulnerability still affects 17.7% of the pages that contain Web exploits as observed by M86 Secure Web Gateway. The M86 report states the obvious: “Many users and organizations do not patch all their installed software in a timely manner, and attackers leverage this weakness to their advantage.”

The report also indicates that exploits shifted focus from malicious attachments to malicious links that led to exploit kits, in particular, the Blackhole exploit kit. During this time the Blackhole kit accounted for 95% of all malicious URLs, indicating that Blackhole is now the dominant exploit kit which leverages more than half of the currently most exploited vulnerabilities. Webopedia describes the Blackhole kit “as a type of crimeware Web application developed in Russia to help hackers take advantage of unpatched exploits in order to hack computers via malicious scripts planted on compromised websites. Unsuspecting users visiting these compromised sites would be redirected to a browser vulnerability-exploiting malware portal website in order to distribute banking Trojans or similar malware through the visiting computer.”

Spam gets more dangerous

There’s good news and bad news in the spam observations. On the bright side, the volume of spam is at its lowest level in years. Anecdotal evidence suggests that the 2011 disruptions to the Kelihos, Mega-D and Rustock botnets are a reason for the precipitous drop in spam monitored by M86. Still, 90% of all spam comes from just eight well-known and established botnets. If only we could kill them as well!

The bad news about spam trends is that, increasingly, the messages are more than just annoying — they are dangerous as well. By the end of 2011, 5% to 10% of all spam contained links or attachments which redirected users to malicious or compromised sites that delivered a malware payload. The top four spam categories are pharmaceutical (pills and remedies), replicas (fake designer watches and bags), gambling (online casinos) and dating (online dating websites). While those topics might not draw email recipients into the scam, the fifth and sixth place categories of software and anti-malware just might.

On the rise: duping users of social media

A troubling trend is cybercriminals exploiting the popularity of social media and the apparent blind trust of the users by duping them with fake (and infected) notification messages to “Friend Me” on Facebook or inviting them to join a LinkedIn network. For instance, a campaign last August led people to a fake Facebook login page and ultimately to the Blackhole exploit kit and a Zbot Trojan. In addition, many of these campaigns propagate the spread of spam and malware by enticing users to share posts for “rewards” or “gift cards” with their friends.

Recommendations from M86 Security

The M86 Security Labs team provides recommendations to administrators, website owners and end users to help them mitigate the identified exploits. Here are just a few of the tips for administrators:

• Educate your workers. Social engineering techniques often circumvent protection technologies. In particular, educate your users to pay attention to browser warnings, especially those regarding digital certificates.

• Use Certificate Revocation Lists (CRL) or configure your security products to deploy CRLs.

• Disable any risky and unnecessary features, such as execution of JavaScript code within PDF files, execution of Macros in Microsoft Office files, etc. Many of these features can be disabled via group policy.

View more recommendations on the last page of the report found at https://www.m86security.com/documents/pdfs/security_labs/m86_security_labs_report_2h2011.pdf.

Brian Musthaler is a principal consultant with Essential Solutions Corporation. You can write to him at Bmusthaler@essential-iws.com.

______________________________________________________________

About Essential Solutions Corp:

Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.