Network World – A few weeks ago I sat in the conference room of the small corporate office of Malcovery Security in Birmingham, Ala. Gary Warner, Malcovery’s co-founder and chief technologist, held up his computer for all in the room
to see. “Here is a known phisher’s Facebook page. Here’s his picture, and another photo of him playing with his children.
Here is his email address and where he works,” Warner calmly stated.
Warner went on to tell us that this particular guy has been attacking banks in Europe with a series of phishing campaigns.
“The reason we know it is him is that the email address behind this Facebook page is actually the same email address where
login credentials stolen via his phishing campaigns are being mailed to,” said Warner.
It was done 23,000 times in the past year. Malcovery has been able to identify the email addresses of the criminals behind
similar attacks. Of course, once law enforcement agencies have identifying information like that, it’s not difficult to dig
a little further to get a physical address where they can show up to bust the guy.
While Malcovery experts do work closely with law enforcement agencies around the world to aid in take-downs and arrests, the
company’s main services are for companies whose brands are often abused in phishing campaigns, as well as for owners of large
networks where hostile phishing emails come in. Your company probably fits at least one of these profiles, so read on to learn
how Malcovery is battling phishing attacks in unique ways.
The Anti-Phishing Working Group reports that there are some 700 or so organizations whose brands are repeatedly abused in phishing campaigns. Such schemes
are designed to trick end users out of their critical information, such as user ID and password, credit card number, CVV and
card expiration date. You know the companies they spoof because you’ve received the phishes: eBay, FedEx, practically every
leading bank, the IRS, and so on.
For these victim companies, Malcovery provides an in-depth Phishing Intelligence Report that delivers specific information
such as who is running the phishing campaigns against the brand, precisely what their messages look like, and where the purloined
credentials are going.
Warner explains his company’s fundamentally different approach to stopping phishing attacks: “Let’s say you operate a major
bank, which I’ll call Acme Bank. Acme Bank may have a thousand phishing sites created against it this month. These are fake
websites where individual victims are tricked into entering their account information because they think they are on Acme’s
real website.” Warner says thousands of people fall for these tactics every week, making it lucrative for phishers to run
their campaigns.
Malcovery’s tools help to identify those serial offenders who create the most phishing sites against a brand. They recommend
applying a disproportional number of resources against the biggest identified source of fraud. “If you are Acme Bank, we think
it is more important to identify who has created the greatest number of phishing sites against you and treat them differently
than everyone else. If we can identify the guy who is making the most phishing sites and then give you the explicit information
you can use to take him down, that would have long-term benefit to you. If he made 30% of all the phishing sites against your
brand this month, getting rid of him is a different approach than just trying to take down the sites he creates.”
Linda Musthaler is a principal analyst with Essential Solutions Corporation.
