RSA Expert Says Online Security Is Missing the Mark
Phishing schemes continue to evolve and grow, and they’re increasingly targeting new channels, such as mobile, says Daniel Cohen, a researcher for security firm RSA.
Cohen says the online world is no closer than it was seven years ago to solving the phishing problem.
“We have to remember that phishing is the easiest attack to launch against end-users and we’re going to see that continue through 2013 and 2014,” says Cohen, who specializes in online fraud threats and cyber-intelligence, during an interview with Information Security Media Group [transcript below].
The latest phishing trends include the privatization of banking Trojans, attacks tailored toward mobile devices and cybercriminals turning to other industries to target, Cohen says. “In terms of the bad guys, they’re opportunistic,” he explains.
The Phishing Struggles
When it comes to defending against phishing attacks, most organizations struggle to keep up, Cohen says. Online security initiatives such as DMARC – the Domain-based Message Authentication, Reporting and Conformance initiative – are a step in the right direction, he adds. But until this protocol, which aims to standardize how e-mail receivers perform e-mail authentication, is widely adopted and becomes a uniform practice, it won’t be effective (see DMARC: Taking a Bite Out of Phishing).
“Until that happens, we still have to continue with the user awareness, [and] be aware of the phishing threats out there,” Cohen says. “We, as an industry, have to continue to protect and mitigate that threat.”
During this interview, Cohen discusses:
- How malware privatization is making Trojans more sophisticated and difficult to detect;
- How phishing schemes are growing in certain global markets;
- Why the financial industry is the most-often targeted by phishing attacks.
At RSA, Cohen serves as the head of business development for the Online Threats Managed Services division, where he researches emerging malware attacks as well as other online risks.
Phishing Trends
TRACY KITTEN: How are the phishing trends that RSA is seeing, as well as some of the mobile threats you’re tracking, evolving?
DANIEL COHEN: In terms of phishing, 2012 was a landmark year, when phishing volumes were sky-high. Looking at 2013, the year has seen a slight decline in phishing. But comparing month-over-month – 2013 to 2012 – we do still see high numbers of phishing. In terms of the crime, phishing is going to continue. We have to remember that phishing is the easiest attack to launch against end-users, and we’re going to see that continue through 2013 and 2014.
In terms of the mobile channel, we have to look at mobile as a device that basically keeps us connected 24/7. As such, we’re more prone to attacks, because once we get that SMS, once we get that Facebook update or e-mail, we’re immediately there following the link and hitting the phishing site. But we have to remember, at the end of the day, phishing is phishing is phishing, even when it hits the mobile device. And we’re obviously working to detect that and mitigate that, too.
Trojan Evolution
KITTEN: What kind of evolution are you seeing in Trojans affiliated with some of these phishing attacks?
COHEN: Trojans are continuing to develop, and we have seen a move to what we’re calling the privatization of Trojans. We’re no longer seeing commercial Trojans available out there, such as the Citadel, Ice IX or SpyEye. That means, as a botmaster or a Trojan operator today, it’s not easy for you to find a Trojan that’s constantly developed and the bugs are fixed. There’s no active RD [research and development] behind these public Trojans.
Today, we’re seeing Trojans becoming privatized in that the development, support and maintenance are done in very, very closed and controlled groups. Today, the bad guys have to rely on older Trojans, such as Zeus, which was made public back in 2011. But we’re still seeing constant development, even in those private groups. Trojans are still slipping out and we’re still detecting them.
