Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.

Tuesday, May 26, 2009

Cybercriminals Imitating Social Networks To Spread Malware

It should be no surprise to any IT administrator who manages a secure web gateway proxy that cybercriminals have been imitating and referencing the domain names of popular social networking sites for the purpose of spreading malware.

From a report on The Journal:

The results of research conducted by Websense, which makes security software, reveals a growing domain-name cloning trend that includes brands like Facebook, MySpace, and Twitter. These sites have no connection to the real sites but are trying to trick unsuspecting users to visit fake Web sites and enter sensitive information or download malicious code.

The Websense Security Labs found more than 150,000 phony copycat sites using the term Facebook and 50,000 using some variation of either MySpace or Twitter in their URLs.

Researchers said hackers appear to be taking steps to create these cloned domains to circumvent security measures put in place by organizations to filter the original domain in a business setting. Many of the domains are proxy avoidance sites that are used to try to evade traditional Web filtering technology.


We've talked on this blog in the past about the importance of keeping your web filtering database up to date, having some way to rate web sites in real time, and having some malware detection on the secure web gateway proxy device. All three of these are necessary components to keep web surfing safe in this Web 2.0 world.

No comments: