This site uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Find out more.X

Mass injection web hacks yield to targeted attacks

Share this article:

Malware authors targeting websites have begun trading quantity for quality, according to web security firm Websense.

During the second half of 2009, attackers shifted their strategy away from mass-injection campaigns and instead focused on launching targeted attacks to infect high-profile websites, concluded Websense's State of Internet Security report for the third and fourth quarter of 2009, released on Thursday.

There was a sharp increase in the number of infected websites during the first half of last year, when attackers launched the mass-injection campaigns Gumblar, Beladen and Nine-Ball. But then, from July until December, the number of malicious websites decreased 3.3 per cent compared with the first half of the year.

“It doesn't necessarily mean things are getting better,” Patrik Runald, senior manager of security research at Websense, told SCMagazineUS.com on Wednesday.

“The bad guys are going after high-profile, high-volume websites, instead of going after the smaller websites, which are easier to inject code into.”

There was an increase in attacks on highly trafficked sites such as Web 2.0 properties and news organisations during the second half of 2009, Runald said. Hackers have realised that targeting fewer websites, but ones with higher traffic, can be more efficient and effective, the report states.

Also, during the same period, attackers increasingly launched targeted attacks, which often start with an email containing a malicious link.

One such high-profile attack called Operation Aurora leveraged a previously unknown vulnerability in Internet Explorer to compromise systems at Google, Adobe and more than 30 other large companies.

During the second half of 2009, 81 per cent of email contained a malicious link, the report states. In addition, 58 per cent of all data-stealing attacks were conducted over the web.

Websense predicted that blended attacks attempting to steal sensitive information and attach compromised machines to botnets will increase over the next 12 months.

Share this article:

SC webcasts on demand

This is how to secure data in the cloud


Exclusive video webcast & Q&A sponsored by Vormetric


As enterprises look to take advantage of the cloud, they need to understand the importance of safeguarding their confidential and sensitive data in cloud environments. With the appropriate security safeguards, such as fine-grained access policies, a move to the cloud is as, or more, secure than an on-premise data storage.


View the webcast here to find out more

More in News

China refutes new FBI hacking claims

China refutes new FBI hacking claims

It's been another week of claims and counterclaims as the US and Chinese governments accuse each other of deviant cyber security practices.

SC Exclusive: Bank of England to appoint new CISO in January

SC Exclusive: Bank of England to appoint new ...

Bank of England Chief Information Security Officer (CISO) Don Randall is to leave his post in the New Year to take up an unspecified supervisory role, with William Brandon set ...

Sandworm vulnerability seen targeting SCADA-based systems

Sandworm vulnerability seen targeting SCADA-based systems

Hard on the heels of the `Sandworm' spy group revealed by iSIGHT Partners earlier in the week, Trend Micro says its has spotted the zero-day vulnerability of the same name ...