Most phishing websites "made from kits"
By Rene Millman,
Almost all phishing websites are made from off-the-shelf components available from the internet, new research has found.
The study carried out by IBM's Internet Security Systems subsidiary found that 92 per cent of new phishing web sites were kit-based. The company's X-Force research team found that out of 3,544 phishing websites recently identifies, 3,256 of them used tools that allows a non-technical attacker to rapidly deploy multiple phishing websites (with multiple DNS host entries for virtual hosts) on a single host (i.e. a compromised computer).
Further research by the team discovered that those phishing kit sites led back to 100 registered domains (compared to the 288 non-kit phishing websites that made use of 276 registered domains). The majority of these domains (44 per cent) were registered with a Hong Kong (.hk) address.
Gunter Ollmann, director of security strategy for IBM Internet Security Systems said that the research showed that the use of phishing kits (with their multiple sites hosted on a single server) greatly inflated the total number of phishing sites that are commonly reported each week, and that this number does not adequately correlate to the number of hosts that are actually involved in a phishing scam.
"This differentiation between hosts that are running phishing kits and those that aren't is pretty important," said Ollman. "In my mind it's analogous to classic network hack attempts and whether you count the number of attack probes detected, or you count the number of attackers actually launching the probes."
He said there is a big difference between observing twice as many attacks and having twice as many attackers targeting your organisation - "the later actually has importance in the way you should be responding to the threat," he said.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Do British police get cyber security?
Davey Winder listens to telephone conversations between the FBI and the Metropolitan Police, courtesy of Anonymous, and isn't impressed.
- Who to trust after the VeriSign hack?
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





