Crimeware toolkits take off in August


Crimeware toolkits take off in August

Antony Savvas

The distribution of Crimeware software kits soared in August, with the numbers used against websites and end-users outstripping the total for the three preceding months.

The level of attacks using the hacker kits has been uncovered by Finjan and its Finjan SecureBrowsing service.

Finjan SecureBrowsing is a browser plug-in that adds safety ratings to URLs of search results, Web 2.0 services and websites. Finjan SecureBrowsing identified ten different types of crimeware toolkits in August alone.

These crimeware toolkits are being sold by hackers for only a few hundred pounds.August's crimeware toolkit list included the known MPack, NeoSploit, IcePack, WebAttacker, WebAttacker2 and MultiExploit toolkits, as well as new toolkits such as Random.js, Vipcrypt, Makemelaugh and Dycrypt.

Each of these crimeware toolkits is being updated frequently to include recent exploits and new anti-forensic techniques that allow them to bypass and escape detection by traditional signature, reputation and URL based security products.

The dozens of versions for each of the crimeware toolkits provide the basis for hundreds of unique toolkits in use by cyber-criminals today, said Finjan.

In July, Finjan detected 58 criminals who used the MPack toolkit to successfully infect more than 500,000 unique users in a single month.

The IcePack toolkit was used to infect the Bank of India website last week, with the bank having only just recovered from the attack after initially being forced to take the site down.

Download Finjan's Web Security Trends Reports.

Download Finjan's Malicious Page of the Month reports.

Email Alerts

Register now to receive IT-related news, guides and more, delivered to your inbox.
By submitting your personal information, you agree to receive emails regarding relevant products and special offers from TechTarget and its partners. You also agree that your personal information may be transferred and processed in the United States, and that you have read and agree to the Terms of Use and the Privacy Policy.

COMMENTS powered by Disqus  //  Commenting policy