Story Tools: PRINT | Text Size: S M L XL | REPORT TYPO | SEND YOUR FEEDBACK

In Depth

Technology

2007: A banner year for online crime

Last Updated December 24, 2007

As 2007 comes to a close it's natural for us to look back and analyze the year past so as to prepare for the year ahead. One particular thread that stands out is the incredible growth of cyber crime.

In October I wrote about the rise of the storm worm, and while it has since diminished in size, it continues to evolve and remain active, symbolic of the explosion of malware (software with malicious intent) that has fuelled the greatest boom in internet crime seen to date. In fact, beginning Christmas Eve, the storm worm began sending out messages enticing people to visit a site called merrychristmasdude.com, at which point their computers will be infected and taken over by the worm.

The security company F-Secure has been studying and cataloging malware for more than two decades, and in 2007 it added 250,000 new entries to its index, which was more than all previous years combined. This malware is almost entirely built for criminal purposes, whether for fraud, identity theft, data mining, or serving out spam.

Increasing sophistication

The organization of all this criminal activity manifests in the form of bot nets (see sidebar) such as the storm worm, networks of hijacked machines that allow criminals to engage in their activities without being traced or identified. The sophistication of these bot nets has increased so rapidly that many observers have begun speculating that we're witnessing the early stages of a new online arms race, a cyber cold-war in which new weapons and tactics are being developed and tested.

Botnets

A botnet, or robot network, is a group of web-linked computers — sometimes called zombies — that have been commandeered, in some instances by criminals, to perpetrate all kinds of online nastiness. Typically a bot is installed on a machine through a trojan, an insidious program that can find its way into an insufficiently protected computer in a variety of ways, such as when a user clicks on a link to an infected web page or e-mail message, views an infected document or runs an infected program. Once the bot has made itself at home, it opens the doors of its new host computer to its master, who can instruct the machine to engage in various activities such as sending out spam and phishing e-mails, or launching the distributed denial of service or DDOS attacks like the kind that almost brought down the internet. In some cases, these nasty little robots can steal personal data and return it to a central site to be used for identity theft purposes.

For example, in May, Estonia's internet infrastructure was attacked and forced off-line for several days. In November, the British security service MI5 contacted 300 major corporations to inform them about successful attacks made by hackers employed by the Chinese government. The New York Times recently reported that the U.S. Department of Homeland Security had pointed the finger at Chinese hackers as being responsible for an intrusion into the computer network of the nuclear weapons research facility at Oak Ridge National Laboratory in Tennessee.

There were also massive security breaches and exposures of consumer data in 2007. Approximately 100 million consumers were affected by the computer break-in at TJX, which occurred over a period of several years but was only disclosed in 2007. Monster.com was hacked and 1.3 million users had their personal information stolen. In November, the U.K. government's Revenue and Customs Department disclosed it had lost two discs containing the personal information of 25 million British citizens.

While the last example apparently was due to a mistake rather than a criminal attack, it highlights a year in which computer security and privacy were under constant pressure.

Social networks like Facebook are responsible for some of the momentum behind the rapid loss of privacy. However, the real difference lies in the evolving methods being employed by criminals online, and the way in which they combine sophisticated technology with clever language and techniques to get people to click on links and visit sites that will compromise their computers.

The methods of attack are diverse, but what most have in common is the focus on attempting to trick the user into taking action. That could include installing software, opening an e-mail attachment, visiting a website, opening a video or image, even calling a phone number to speak to an experienced con artist. Whether pharming, phishing, or fraudulent bank e-mails, the purpose is to fool you into a false sense of security so you can either voluntarily give up personal information or allow access to your computer so someone else can steal it — or spy on you to steal it later.

Cybercrime a growing franchise

One of the main reasons we're seeing such creativity combined with advanced technology is the way in which the online criminal industries have embraced the franchise model of doing business. No longer do you need technical skills to get in at the ground level of online crime; now for a reasonable price you can buy software, services and support to help you build your own army of hijacked computers.

These cyber crime kits, such as Mpack and IcePack in particular, are not only available to buy — free versions are also circulating widely. The difference, however, is that the free versions have an added back door that allows the authors to monitor and control their franchises.

The most visible impact of all this criminal activity is spam. The security research firm Barracuda Networks recently released a study that claimed 90 to 95 per cent of all e-mail in 2007 was spam. The majority of these messages employed identity obfuscation techniques — i.e., they appear as if they're from your friends, contacts or trusted institutions, and their subject lines are relevant to your personal life. The ones I've been receiving lately, for example, have to do with last-minute gift shopping and New Year or holiday greetings.

Looking ahead

So what's in store for the new year other than even more spam?

The explosion in the popularity of social network sites like Facebook will continue to attract criminals looking to harvest identify information and target potential victims. Blogs have already been under attack by spam bots and are starting to be used in infection schemes in which malicious code is installed on a target computer via an infected widget or software add-on. A similar exploit can be used via the Facebook application platform or Google's Open Social initiative.

All of these attacks assume inevitable detection, but they only require a few hours or a few days of activity to be effective.

Mobile devices (the iPhone in particular) will be attractive targets in 2008 as they become smarter and more powerful. They are always connected to the internet, so they present a perfect opportunity for criminals wanting access to our information and money. As the Royal Bank here in Canada tests technology that turns cellphones into electronic wallets, you can also expect there are efforts underway by criminals to learn how to access them illegally.

The thing to keep in mind is that the success of cyber criminals lies not so much in their ability to break into computers or compromise technology, but in their understanding of how people use technology every day. They are using the habits and behaviour of people to gain access to their information. Social engineering is the core trait of the hacker, and appropriated by the cyber criminal, it has now become a profitable means of doing business online.

Yet profit is not the only motive for those with the power to mobilize armies of zombie computers and deceive the internet masses.

The general consensus among security research companies focusing on the year ahead is that in addition to continued growth, the technology and tactics demonstrated in this online criminal economy will be applied to the 2008 U.S. presidential election. More on that in my next article.

Jesse Hirsh is based in Toronto and can be contacted via jessehirsh.com

Go to the Top

Story Tools: PRINT | Text Size: S M L XL | REPORT TYPO | SEND YOUR FEEDBACK

World »

new U.K. preps for possible copycat attacks after hacking death
Britain is bracing for clashes with right-wing extremists and possible copycat attacks after the brutal slaying of a young soldier although an official say no specific threats had been detected.
Man ‘lucky to be alive’ after Washington bridge collapse video
A Washington state bridge over a river collapsed last night, dumping two vehicles into the water and sparking a rescue effort by boats and divers who searched the chilly waterway north of Seattle.
new Jet with smoking engine lands safely at Heathrow
A British Airways jet made an emergency landing at London's Heathrow Airport Friday after developing a technical problem after takeoff. TV footage showed smoke streaming from one of the engines.
more »

Canada »

updated Mike Duffy says he wants to give Canadians 'the whole story' video
Senator Mike Duffy says he wants a "full and open" inquiry so Canadians can get all the facts about the scandal that has rocked the Senate and the Prime Minister's Office and that he has no plans to resign.
live Rob Ford allies set to take over if mayor steps down video
Members of Rob Ford's executive committee say they are prepared to take over the day-to-day running of the city if the Toronto mayor is no longer able to perform his duties, amid a scandal involving allegations he was caught on video smoking crack cocaine. CBCNews.ca is livestreaming a press conference from Deputy Mayor Doug Holyday.
analysis Greg Weston: Senate scandal may be Harper's worst hour
The widening Senate scandal that the prime minister flippantly tried to dismiss as a 'distraction' just days ago has instead become arguably Stephen Harper's worst hour.
more »

Politics »

updated Mike Duffy says he wants to give Canadians 'the whole story' video
Senator Mike Duffy says he wants a "full and open" inquiry so Canadians can get all the facts about the scandal that has rocked the Senate and the Prime Minister's Office and that he has no plans to resign.
analysis Greg Weston: Senate scandal may be Harper's worst hour
The widening Senate scandal that the prime minister flippantly tried to dismiss as a 'distraction' just days ago has instead become arguably Stephen Harper's worst hour.
Federal Court won't remove MPs over election robocalls
The Federal Court didn't throw six MPs out of their seats over allegations of widespread vote suppression through automated robocalls in the 2011 federal election. But Judge Richard Mosley did find that fraud occurred, linked to the Conservative Party's database.
more »

Health »

Chronic fatigue may be reversed with exercise
Taking it easy is not the best treatment for chronic fatigue syndrome, rather exercise and behaviour therapy are, a large study finds.
AT&T buys T-Mobile USA for $39B US
AT&T Inc. said Sunday it will buy T-Mobile USA from Deutsche Telekom AG in a cash-and-stock deal valued at $39 billion US, becoming the largest cellphone company in the U.S.
Milky Way home to 50 billion planets: NASA
Scientists have compiled the first cosmic census of planets in our galaxy: at least 50 billion planets are estimated to call the Milky Way home.
more »

Arts & Entertainment»

2nd jewel theft during Cannes Film Festival
Thieves outsmarted 80 security guards in an exclusive French Riviera hotel and made off with a necklace that creators say is worth a staggering €2 million ($2.7 million Cdn) — in the second such jewelry heist during this year's Cannes Film Festival.
Quebec film wins screenplay prize at Cannes
Le Démantèlement, a movie by Quebec director Sebastien Pilote, has won one of the main prizes of sidebar program Critics Week at the Cannes Film Festival.
new Amanda Bynes arrested for allegedly tossing bong out window
Police say actress Amanda Bynes has been arrested in midtown Manhattan after she heaved a marijuana bong out of a window.
more »

Technology & Science »

new 3D printers give rise to 'desktop manufacturing'
Customizable objects from plastic dollhouse furniture to medical prosthetics can now be designed and printed out by almost anyone at the press of a button, and is going to lead to an 'explosion of new stuff,' predicts author Chris Anderson.
new U.S. space chief updates on asteroid lasso mission
Surrounded by engineers, NASA chief Charles Bolden inspected a prototype spacecraft engine that could power an audacious mission to lasso an asteroid and tow it closer to Earth for astronauts to explore.
Canada's privacy laws inadequate for digital age, watchdog says
Canadians' trust in the digital economy is at risk because our laws don't have enough teeth to compel companies to protect consumers' privacy, Canada's privacy commissioner says.
more »

Money »

German brewers worry fracking will compromise beer quality
German brewers are worried that fracking, the process of extracting natural gas from underground shale deposits, will jeopardize the quality of their beer by contaminating the water supply and have asked their government to hold off on passing the fracking regulations it has been drafting for months.
new National Bank hikes dividend
Canada's sixth-largest bank is hiking its dividend and buying back some of its shares, National Bank announced Friday along with a second-quarter profit that beat analyst estimates by a wide margin.
SNC-Lavalin letter says Gadhafi son offered VP post: RCMP
SNC-Lavalin's ties to Libya's former dictatorship ran so deep the company offered the son of Moammar Gadhafi a six-figure job as a vice president in 2008, according to a newly unsealed RCMP affidavit.
more »

Consumer Life »

Honda recalls Fit subcompacts
Honda Canada says it will recall 14,640 of its 2009 and 2010 Fit subcompact cars to replace lost motion springs.
U.S. travel fee proposal criticized by Harper
Prime Minister Stephen Harper says he doesn't think much of a new border tax that's being proposed by the United States, calling it a cash grab designed to help a budget crisis.
Bell class action suit approved by Que. court
A Quebec Superior Court judge has authorized a class action lawsuit to go ahead against Bell Mobility.
more »

Sports »

Scores: NHL NBA

Stanley Cup Stories: Red Wings take control
The Detroit Red Wings put the Chicago Blackhawks in an unfamiliar spot and New York Rangers coach John Tortorella had a special request for the media in the top NHL stories from Thursday.
blog Rangers' Tortorella defends decision to bench Richards
Rangers coach John Tortorella defended his choice to bench struggling sniper Brad Richards, and it appears to have paid off with New York's 4-3 overtime win Thursday.
analysis Reed: German soccer strength on display in Champions League final
German soccer is no longer under the radar. It's about to be showcased in all its glory in Saturday's Champions League final between Bayern Munich and Borussia Dortmund, writes Nigel Reed.
more »

Diversions »

[an error occurred while processing this directive]
more »