MALWARE 2.0
     Shane Ochotny
TYPES OF MALWARE
 Worms                                     Exploits

                    Trojans
                                  Adware
          Spyware
                                                Keyloggers
                              Viruses

Dialers
                                                      Rootkits
                          Rogue
STATISTICS
                TREND MICRO UNIQUE THREAT GROWTH




20,000,000


15,000,000


10,000,000


 5,000,000


        0
         2005           2006              2007     2008
STATISTICS
                TREND MICRO UNIQUE THREAT GROWTH




20,000,000


15,000,000


10,000,000


 5,000,000


        0
         2005           2006              2007     2008
MALWARE 1.0
BORED KIDS
   80’s - 90’s
INFECTION VECTORS
      File Replication
MALWARE 2.0
ORGANIZED CRIME

Groups Discovering and Selling Exploits
         Developing and Selling Malware
         Hosting Exploits and Malware
         Selling the Stolen Data
         Using the Stolen Data
ORGANIZED CRIME

        Discovering and Selling Exploits
Groups Developing and Selling Malware
        Hosting Exploits and Malware
        Selling the Stolen Data
        Using the Stolen Data
ORGANIZED CRIME

        Discovering and Selling Exploits
        Developing and Selling Malware
Groups Hosting Exploits and Malware
        Selling the Stolen Data
        Using the Stolen Data
ORGANIZED CRIME

         Discovering and Selling Exploits
         Developing and Selling Malware
         Hosting Exploits and Malware
Groups Selling the Stolen Data
         Using the Stolen Data
ORGANIZED CRIME

        Discovering and Selling Exploits
        Developing and Selling Malware
        Hosting Exploits and Malware
        Selling the Stolen Data
Groups Using the Stolen Data
MONETARY GAIN
MONEY HOW?
                                        Bank Accounts
      Authentication Credentials


Credit Card Numbers        Send Spam           Emails


   DDoS                Address Book Contacts


        Social Security Numbers            Screenshots


                                       Recent Websites
  Keystrokes          DNS Redirect
INFECTION VECTORS



         Exploits


    Social Engineering
REACHING THE USERS
IFRAMES
MALVERTIZEMENTS
REDIRECTION



MySpace        IFrame        Bad Website

MySpace     Malvertizement   Bad Website
REDIRECTION



MySpace        IFrame        Bad Website

MySpace     Malvertizement   Bad Website
REDIRECTION



MySpace        IFrame        Bad Website

MySpace     Malvertizement   Bad Website
REDIRECTION



MySpace        IFrame        Bad Website

MySpace     Malvertizement   Bad Website
REDIRECTION



MySpace        IFrame        Bad Website

MySpace     Malvertizement   Bad Website
REDIRECTION



MySpace        IFrame        Bad Website

MySpace     Malvertizement   Bad Website
HIGH PROFILE WEBSITES
EXPLOITS
TAKE ADVANTAGE OF SOFTWARE VULNERABILITIES




   No User Interaction
   No Downloading Accidentally
   No User Knowledge
SOCIAL ENGINEERING
  TAKES ADVANTAGE OF USER VULNERABILITIES
SOCIAL ENGINEERING
  TAKES ADVANTAGE OF USER VULNERABILITIES
SOCIAL ENGINEERING
  TAKES ADVANTAGE OF USER VULNERABILITIES
SOCIAL ENGINEERING
  TAKES ADVANTAGE OF USER VULNERABILITIES
MALWARE SOURCES
                     THREATEXPERT.COM


Canada               United Kingdom       Russia
 0.67%                    6.17%           22.29%



     United States
         6.42%                              China
                                            32.07%

                                 Africa
                                 0.17%

            Brazil
            6.92%
WHY BARCAMP?
SOCIAL THREATS
    Facebook


    MySpace


    YouTube


    Twitter


    Instant Messaging
FACEBOOK
MYSPACE
  JULY 2006
YOUTUBE
TWITTER
INSTANT MESSAGING
Network Anti-Malware
Passive on the Network
No Client Software
MALWARE SOURCES
                     THREATEXPERT.COM


Canada               United Kingdom       Russia
 0.67%                    6.17%           22.29%



     United States
         6.42%                              China
                                            32.07%

                                 Africa
                                 0.17%

            Brazil
            6.92%
MALWARE 2.0
     Shane Ochotny

Malware 2.0