Saturday | 4 September, 2010
CSO
90 percent of e-mail is spam, Symantec says
Some spammers are dropping the use of botnets in favor of massive spam blasts

Spammers seem to be working a little bit harder these days, according to Symantec, which reported Tuesday that unsolicited e-mail made up 90.4 percent of messages on corporate networks last month.

That represents a 5.1 percent increase over last month's numbers, but it's nothing out of the ordinary. For years, spam has made up somewhere between 80 percent and 95 percent of all e-mail on the Internet.

Symantec reported that nearly 58 percent of spam is now coming from so-called botnets --networks of hacked computers that can be misused by criminals to steal financial information, launch attacks or send spam. The worst of the spamming botnets -- called Donbot -- generates 18.2 percent of all spam, according to Symantec.

These botnet computers can be rented out on the black market by anybody, but in recent months some spammers have been moving away from botnets, experimenting with a new way to sneak their unwanted e-mail past corporate filters, according to Adam O'Donnell, a researcher with antispam vendor Cloudmark.

"Some of the larger ISPs are seeing a lot of non-bot-driven spam," O'Donnell said. With these campaigns, the spammer will rent legitimate network services, often in an Eastern European country such as Romania, and then blast a large amount of spam at a particular ISP's network. The idea is to push as many messages as possible onto the network before any kind of filtering software detects the incident. Spammers are sending hundreds of thousands of messages per day using this technique, O'Donnell said.

Social networks are also becoming an increasingly important spammer's tool. Over the past week, criminals began taking over both Facebook and Twitter accounts, stealing users' passwords with different phishing attacks.

These stolen accounts are then used to spam the friends of the phishing attack victims.

In the case of the Twitter attack, the hacked accounts were used to send out bogus Twitter messages promoting a free trial of an acai berry dietary supplement. Security experts say that social-networking spam is particularly effective because it can't be filtered at the corporate firewall and appears to come from a friend of the recipient.

Symantec's report can be found here (pdf).

Comments

Fraud

Spam, scam and fraud are everywhere and just sitting in a corner waiting for their next victim. Well, good news is that one of them, named Kevin Trudeau is already captured again after he was imprisoned several years ago for the same violation of law. He is into selling product which is not really as effective as he was trying to portray on his infomercial show on tv. He has been slapped with a $37 million fine thanks to a 2005 lawsuit. It looks like Kevin Trudeau has some credit repair to do, if that quack had any in the first place.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the CSO Online comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content
 
Whitepaper

Automation Makes Perfect: Taking the Time Crunch Out of IT Compliance with Automation

Automation makes compliance part of day-to-day operations, enabling CIOs to shift time to more important things—like a security strategy that protects the business, rather than simply pleases an auditor. Read this exclusive white paper from compliance leader Tripwire to learn how a Protect, Detect, and Correct compliance strategy can give you back your most precious resource: time.