Malware
About one per cent of web requests now deliver an infected page

New malware-infected site found every five seconds

Experts warn of 'dramatic rise' in web-based threats

Written by Robert Jaques

The US and China have long held the top two spots in this hall of shame

Carole Theriault Sophos

The first quarter of 2008 has been marked by a "dramatic increase" in web-based threats, with a new infected webpage being discovered every five seconds, security experts warn.

Sophos identified an average of more than 15,000 newly infected web pages each day from 1 January to 31 March 2008.

The security firm warned that 79 per cent of these malware-hosting sites are found on legitimate websites that have been hacked.

February saw the website of UK broadcaster ITV fall victim to a poisoned web advert campaign which targeted Windows and Mac users.

In March a Euro 2008 football ticket website was hacked by cyber-criminals in an attempt to infect unwary fans.

In contrast, just one in every 2,500 emails is now infected, compared to one in every 909 in 2007.

The top two web threats, Mal/Iframe and Mal/ObfJS, which are together responsible for more than half of all online malware found by SophosLabs, are programmed to infect websites by taking advantage of vulnerabilities.

"About one per cent of web requests now deliver an infected page, most of which are legitimate websites belonging to people just trying to earn a living, " said Carole Theriault, senior security consultant at Sophos.

"Already in 2008 we have been reminded that it is not just the small, independent sites that are being hacked.

"With compromised websites of household names now serving up malware, it is more important than ever for users to ensure that they use a fully protected machine, and for businesses to protect their web servers from attack."

Sophos reported that the list of countries hosting the most infected web pages shows some "interesting changes" since 2007.

The US, in particular, has experienced unprecedented growth, from hosting less than 25 per cent of all infected pages overall in 2007, to almost half in the first three months of 2008.

China has demonstrated the biggest drop, from hosting more than half of all infected pages seen by Sophos in 2007, to just under a third in the first quarter of 2008.

Elsewhere in the chart, newcomer Thailand was responsible for hosting one per cent of all malware infected pages, while the UK hosted 1.1 per cent, down from three per cent in the same period last year.

"The US and China are no strangers to this chart, and have long held the top two spots in this hall of shame," said Theriault.

"However, the bottom half of the chart remains fluid, indicating that users need to remain vigilant.

"Those hosting websites need to ensure that they have patched against vulnerabilities that might be lurking on their site to avoid becoming part of the problem."

Further reading

'Subpoena' spear phishing attacks mount

Senior executives tricked into downloading Trojan   More...

Malware writers cash in on Olympics

Rootkit-laden video is latest to exploit Tibet protests   More...

Remote workers present biggest security threat

Sales staff are primary bandwidth hogs of corporate internet   More...

US surfers 'alarmingly' ignorant over botnet danger

NCSA warns over danger posed by cyber criminals' weapon of choice   More...

Related articles

Angelina Jolie 'nudes' fuel malware spike

Oldest trick in the spammers' book   More...

Cyber-criminals launch PDF malware offensive

PDFex storms into the charts   More...

Hackers hit US Consulate General in Russia

Malicious code waiting for web surfers   More...

Russia emerges as spam superpower

Dramatic rise in junk email from compromised Russian computers   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement