You are here: silicon.com > Software > Malware

Malware

Microsoft virus 'bounty hunter' warns of never-ending battle

"There will be new threats as long as there are people out there with criminal intent"

Tags: microsoft, zombies

By Andy McCue

Published: 1 March 2006 13:15 GMT

IT security will always remain a never-ending battle, according to the head of Microsoft's European cyber-crime-fighting unit.

Former police officer Paul Thomas, head of Microsoft's European internet safety and IP investigations team, heads up a unit made up of ex-Interpol and ex-US secret service agents, prosecutors and IT forensics experts responsible for tracking down virus and malware writers, spammers, hackers and phishing gangs.

One of the areas people should pay more attention to is opening jokes and images. Education and awareness is important.

He told silicon.com: "There will be new threats as long as there are people out there with criminal intent. Most new technology is going to be looked at by the criminals to use to their advantage. As people's use of technology increases then criminals are still looking for opportunities."

One of the biggest security threats today are the armies of 'zombie' PCs that have been hijacked by criminals using backdoor Trojans to gain remote control of a user's computer. A botnet - a network of zombie PCs - can then be used to send spam or launch a distributed denial of service (DDoS) attack against a target organisation.

Thomas said: "You don't have to be amazingly technically gifted to set up a botnet. At the lower end of the scale you have people doing it for personal gain where you could use a botnet for click through revenue on a website. At the other end of the spectrum you have serious and organised crime using those compromised computers for DDoS attacks to extort money for people."

The main locations Microsoft's security unit has tracked these to turn out to be the usual suspects: central and eastern Europe and China, although there is also significant activity in some Asia-Pacific countries and Brazil.

Thomas claims that worldwide co-operation between governments, law enforcement agencies and technology companies - such as the Botnet Taskforce - is proving successful in combating these security threats.

He said: "The tide is turning towards law enforcement."

Indeed Microsoft's cyber-crime unit has had some notable successes to date, having taken action against 150 spammers, tracked down the Sasser virus author, caught the two people in Morocco alleged to be behind the Zotob virus that hit some major US corporations including American Express, and nabbed a Bulgarian phishing gang.

But Thomas readily admits that it will be an on-going battle to try and stay one step ahead of the high-tech criminals and said one of the weak links is people who are still unable to resist opening dodgy email attachments that subsequently infect their machine.

He said: "It still often comes down to social engineering. People have to be aware of what it is they are looking at and what they are opening. One of the areas people should pay more attention to is opening jokes and images. Education and awareness is important."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Cyber, Security & Risk Analyst, Berkshire, c27-32k

Due to expansion our client is now seeking a Cyber, Security & Risk Analyst to join their team responsible for assessing the level of residual ...

Field Sales Executive

With an off the keyboard anti cyber bullying piece of software my client possess a unique door-opening tool. Field Sales Executive IT Services ...

Software Packaging and Windows XP Build technician

Ensuring All Desktops conform to the Bank's Security policy and have anti-virus and sufficient user lockdown policies applied as required. Updating ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: