SANTA CLARA, CALIF. ?– A new report from Mcafee Labs warns of SMS-stealing banking malware, fraudulent dating apps, data-stealing apps and more ransomware samples in 2013 than in all previous periods combined.
The McAfee Threats Report: Second Quarter 2013, found that Android-based malware achieved a 35% growth rate not seen since early 2012. The rebound was marked by the continued proliferation of SMS-stealing banking malware, fraudulent dating and entertainment apps, weaponized legitimate apps, and malicious apps posing as useful tools.
McAfee Labs claims it registered twice as many new ransomware samples in Q2 as in Q1, raising the 2013 ransomware count higher than the total found in all previous periods combined.
The second quarter also saw a 16% increase in suspicious URLs, a 50% increase in digitally-signed malware samples, and notable events in the cyber-attack and espionage areas, including multiple attacks on the global Bitcoin infrastructure and revelations around the Operation Troy network targeting U.S. and South Korean military assets. ?
"The mobile cybercrime landscape is becoming more defined as cyber gangs determine which tactics are most effective and profitable,?" said Vincent Weafer, SVP for McAfee Labs, in a release. ?"As in other mature areas of cybercrime, the profit motive of hacking bank accounts has eclipsed the technical challenges of bypassing digital trust. Tactics such as dating and entertainment app scams benefit from the lack of attention paid to such schemes, while others simply target the mobile paradigm?s most popular currency: personal user information.?"
The anti-virus software company says it has identified a set of common mobile strategies employed by cybercriminals to extract money and confidential information from victims, including the following:
- Banking malware: Many banks using two-factor authentication require customers to log into their online accounts using a username, password and a mobile transaction number (mTAN) sent to their mobile device via a text message. McAfee Labs researchers identified four significant pieces of mobile malware that capture traditional usernames and passwords, and then intercept SMS messages containing bank-account login credentials. The malicious parties then directly access accounts and transfer funds.
- Fraudulent dating apps:? McAfee Labs discovered a surge in dating and entertainment apps that dupe users into signing up for paid services that do not exist. Users attempt to access potential partners? profiles and other content only to become further frustrated when the scam is recognized. The profits from the purchases are later supplemented by the ongoing theft and sale of user information and personal data stored on the devices.
- Trojanized apps: Research revealed the increasing use of legitimate apps altered to act as spyware on users' devices. These threats collect a large amount of personal user information (such as contacts, call logs, SMS messages and location) and upload the data to the attacker?s server.
- Fake tools: Cyber criminals are also using apps posing as helpful tools, such as app installers that actually install spyware that collects and forwards valuable personal data.
The second quarter also revealed the continued adaptability of attackers in adjusting tactics to opportunities, creating challenges to infrastructure upon which commerce relies, and utilizing a creative combination of disruption, distraction and destruction to veil advanced targeted attacks:
- Ransomware: ? Over the past two quarters McAfee Labs has catalogued more ransomware samples than in all previous periods combined. The number of new samples in the second quarter was greater than 320,000, more than twice as many as the previous period, an indicator of the profitability of the tactic.
- Digitally-signed malware: ? Malware signed with legitimate certificates increased 50% to 1.2 million new samples, rebounding sharply from a decline in the first quarter.
- Suspicious URLS: The second quarter?s increase in suspicious URLs shows how important ?infected? sites remain as a distribution mechanism for malware. At June?s end, the total number of suspect URLs tallied by McAfee Labs reached 74.7 million, which represents a 16% increase over the first quarter.
- Spam volume: ? Global spam volume continued to surge through the second quarter with more than 5.5 trillion spam messages. This represented approximately 70 per cent of global email volume.