Malware Openly Available in China, Researchers Say

Researchers at the Black Hat conference this week said that China is becoming a hotspot for hacking activities at least partly de to easy access to malware tools.

By Jaikumar Vijayan
Thu, July 29, 2010

Computerworld — LAS VEGAS -- China's rapid emergence as a hotspot for criminal hacking activities is enabled by the open and unfettered availability of sophisticated hacking tools, according to security researchers attending the Black Hat conference here this week.

Many of the hacking tools are inexpensive, highly customizable, and easy to use.

How to Fight Malware
A CIO's Guide to China

Most of the early users of the the malware products have sought to steal has been from from online gaming accounts inside China. But now experts are seeing much broader use of such tools.

Hackers in China are developing malicious software "almost like a commercial product", said Val Smith founder of Attack Research, a Los Alamos, N.M.-based security firm. The products come complete with version numbers, product advertising, end-user license agreements and 24-hour support services, he said.

They are "rapidly deploying very easy to use tools for cutting edge exploits," Smith said at a Black Hat presentation on Wednesday. "Their community is huge because [the malware] is easy to use," while at the same time many of the exploits are very advanced, he added.

Unlike in the U.S, the buying and selling of hacker tools in China takes place mostly in the open, said Anthony Lai, a security researcher with Valkyrie-X Security Research Group (VXRL) a Hong Kong based non-profit firm. Often, all that's required to find and purchase a malware program often is the ability to use a browser and search engine, he said during a talk at Black Hat.

Most of those selling malware products make little effort to conceal their activities. In fact, many openly advertise their wares and their capabilities through search engines like Baidu.com, he said. Customers can buy the malware they need for less than $20 or sign up as subscribed members and get regular updated supplies of the tools, Lai said.

The hacking tools run the gamut and are often designed for off-the-shelf use. Many offer exploit generators that allow more sophstocated hackers to carefully customize malware for specific needs by using graphical user interfaces, Lai said. The GUIs let wannabe hackers specify what they want the program to do, for instance, whether they want it to steal data, capture screens, log keystrokes, remotely control a system or undertake any other task.

Some check boxes lets malware purchasers decide what kind of obfuscation and hiding methods they want to use to evade detection by security tools, while others walk them through the deployment and updating process, Lai said.

Continue Reading

Originally published on www.computerworld.com. Click here to read the original story.
Twitter search results powered by Topsy

Get up to speed on mobile security.

Learn More »
Loading...
Most Recent Security Stories
Sign up for a free 30-day trial of Red Condor and you'll receive a free copy of "Email Security Solutions" (Retail Value: $295), an independent study by Miercom. The study includes side by side comparisons of the top email security vendors including Red Condor, ProofPoint, MxLogic, MessageLabs, and Cloudmark.
View an online demo that shows how you can enforce your AUP and protect your company with iPrism Web Filter, and you'll not only be
eligible to receive a free year of web filtering, but you'll also receive a free TCO analysis report.
This book gives you a holistic, cost-effective strategy to secure your sensitive data and achieve compliance across regulations by:
Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many don't understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle.
This paper explores the problem of malware and how it is increasingly being delivered through legitimate Web sites. It also introduces new techniques from IBM that are designed to go beyond standard security measures to help organizations proactively defend against threats by scanning their Web sites for instances of embedded malware.
This whitepaper by Marc Staimer, Dragon Slayer Consulting, reviews urgent issues facing organizations such as the inability to recover and restore data when required and mounting financial and legal risks. It also covers an on-demand approach that instantly and cost-effectively solves these issues.
Calculate the True Cost of Your Current or Proposed Strategies
Recent headlines about data breaches have brought payment security to the forefront. How do you manage payment data security and PCI compliance, without breaking the bank? What PCI strategies should you recommend? Learn to develop a framework to compare the costs of these different approaches.

Join us Tuesday, September 14 at 11am PST/ 2pm EST

You'll learn:
* How to create your own cost model framework to compare payment security strategies
* Which costs are often overlooked or underestimated
* Why PCI validation is a small component of the overall costs
* How costs tend to run over time
* What merchants are doing to reduce their PCI footprints
Join us for a one-hour Web seminar where members of our security research team will discuss these techniques, highlight how their approaches to vulnerability detection compliment one another and share best practices for embedding application security testing across the software development lifecycle.
Join us for a one-hour Web seminar where members of our security research team will discuss these techniques, highlight how their approaches to vulnerability detection compliment one another and share best practices for embedding application security testing across the software development lifecycle.
Enterprises are adopting cloud technologies for speed to market, business flexibility and cost control. But serious questions still abound on the security vulnerabilities of cloud deployment. Midsized to large enterprises face entirely different issues than smaller companies when considering cloud technology.
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer provide guidance on business resiliency, security and cloud computing. What steps should you take to achieve a more pro-active, comprehensive approach to risk management?
With almost everything now connected through the Internet, organizations become more vulnerable to cyber intrusion. As a result, cyber security is a senior management issue, not just a technical problem. Join Accenture and Forrester to explore the current global cyber security situation and learn how your organization can adopt a proactive cyber security approach.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center