Directories

Blackhole Exploit Toolkit 2.0 and Mobile Banking Malware Are Top Trends In AVG’s Q3 Threat Report

AMSTERDAM & SAN FRANCISCO ---- AVG Technologies (NYSE: AVG), the provider of Internet and mobile security to 128 million active users, today released its Q3 2012 Community Powered Threat Report. This quarter’s report investigates a number of malicious software developments including the newly launched 2.0 version of the Blackhole Exploit Toolkit, the evolution in malware targeting mobile banking services, a surge in malicious ads targeting social network users and a trick to hide malware inside image files.

Blackhole Exploit Toolkit 2.0

‘Commercial’ toolkit, Blackhole, continues to lead with 63 percent malware market share and almost 76 percent share of the toolkits market. With the ‘release’ of the Blackhole Exploit Toolkit 2.0 in September, it has increased its threat capabilities significantly and is set to grow its market share and impact even further. We can expect to see an upsurge in large scale attacks that will likely be more aggressive as a result of the new evasion techniques introduced in this latest version.

Prior to this in August, AVG Threat Labs identified an explosion of Blackhole attacks that targeted key social networks including Facebook and left users unable to log-on to their accounts or access any games or apps. Cybercriminals coordinated the attacks from multiple external advertising servers, which generated an exceptional increase from 250,000 attacks initially to over 1.6m recorded events within an eight hour period.

“Blackhole is a sophisticated and powerful exploit kit, mainly because it is polymorphic and its code is heavily obfuscated to evade detection by anti-virus solutions. The rapid update capabilities of the kit have also made it challenging for traditional antivirus vendors to track, which are the main reasons it has a high success rate,” said Yuval Ben-Itzhak, Chief Technology Officer at AVG Technologies. “Through our multi-layered security approach with real-time analysis at the endpoint, AVG has been detecting a much higher rate of Blackhole Toolkit-based attacks than other toolkits, as Blackhole’s creator seeks to stay ahead of their competition.”

Mobile banking attacks engineered with Zeus-in-the-Mobile

With the continued rapid uptake of mobile devices, mobile banking services come under the spotlight this quarter as an increasingly lucrative target for cybercriminals. ‘Traditional’ mobile monetization methods help criminals steal small amounts per victim to stay unnoticed. With these more advanced malware, which circumvents the two-factor authentication process some banks use, criminals can empty a victim’s bank account in one go. A 2012 PriceWaterhouseCoopers’ report projected that digital banking would become the norm globally by 2015, so these attacks can only be expected to become increasingly advanced and more prevalent.

Hiding malware in image files

Image files are typically considered safe as they aren’t executed. However, AVG has tracked a new attack looking at how a compromised webserver can be made to execute image files. Innocent looking image files can then be used to deliver malicious payload to unsuspecting visitors to the compromised website.

Keep up to date with our regular threat bulletins on the AVG News & Threats blog.

About the report

The AVG Community Protection Network is an online neighborhood watch, where community members work to protect each other. Information about the latest threats is collected from customers who participate in the product improvement program and shared with the community to make sure everyone receives the best possible protection.

The AVG Community Powered Threat Report is based on the Community Protection Network traffic and data collected from participating AVG users over a three-month period, followed by analysis by AVG. It provides an overview of web, mobile devices, spam risks and threats. All statistics referenced are obtained from the AVG Community Protection Network.

AVG has focused on building communities that help millions of online participants support each other on computer security issues and actively contribute to AVG’s research efforts.

About AVG Technologies (NYSE: AVG)

AVG's mission is to simplify, optimize and secure the Internet experience, providing peace of mind to a connected world. AVG's powerful yet easy-to-use software and online services put users in control of their Internet experience. By choosing AVG's software and services, users become part of a trusted global community that benefits from inherent network effects, mutual protection and support. AVG has grown its user base to 128 million active users as of June 30, 2012 and offers a product portfolio that targets the consumer and small business markets and includes Internet security, PC performance optimization, online backup, mobile security, identity protection and family safety software.

Related Downloads

Pcvim Internet Security

Pcvim Internet Security 7.6

Pcvim Internet Security gives you the best protection available today. TheTriple Threat Protection is a unique set of technologies that protect against identity theft, confidential data leakage and all Internet threats. Add privacy and parental...

Webroot SecureAnywhere Internet Security Plus 2013 8.0.2.43

The internet security choice of computer experts to protect your computers, mobile devices and identity without slowing you down Groundbreaking Protection - Defeats viruses, spyware and online threats Works Fast and Quietly - Proven fast scans,...

SDL Threat Modeling Tool

SDL Threat Modeling Tool 3.1

As part of the design phase of the SDL, threat modeling allows software architects to identify and mitigate potential security issues early, when they are relatively easy and cost-effective to resolve. Therefore, it helps reduce the total cost of...

NeXpose Community Edition 2011 Summer

NeXpose Community Edition is powered by the same scan engine as award-winning NeXpose Enterprise and offers many of the same features. Support is available via the extensive online Community.

Organizations should upgrade from the NeXpose...

Immunet Protect 3.0.8.9025

Do you know anyone who has been infected by a computer virus? If you do, it's not surprising. Conservative estimates are that more than two million viruses will be created in 2009; that's 5400 every 24 hours and nearly all of these threats are...

Security Shield 2009 12.0

Security Shield 2009 7.0 is a software anti-virus, spyware, and adware detection program that provides users with triple protection and monitors their computers to prevent infection of the malicious behavior type. The Security Shield 7.0 program...

ClamAV Virus Databases for Windows 12-04-2013

ClamAV for Windows utilizes advanced Cloud-based and community-based detection methods. Developed by Immunet, these detection methods leverage the computers of your friends, family and a worldwide global community to harness their collective...

Advanced Windows Service Manager 3.1

It offers many powerful and unique features which sets it apart from built-in Service Management Console as well as other similar softwares.

Some of the classic features include Detection of Malicious/Rootkit Services, Automatic Threat...

Ainvo Antivirus 2.3.2.351

Thank you for using our product. This popular free application perfectly removes malicious software from your computer. Thousands of people use it to safely enjoy the most advanced Internet technologies. Everything is very convenient. Start searching...

Panda ActiveScan 1.0

Panda ActiveScan is an online scanner that scans your PC for all types of malicious software. It scans your PC completely, checking the memory and all files on disk to find any threat (active or latent) such as viruses, trojans, worms, spyware,...