Phishing is the next wave of outsourcing

Image
Kirtika Suneja New Delhi
Last Updated : Jan 29 2013 | 3:33 AM IST

After direct attacks on email ids, phishing attacks are being outsourced as a service.

Vincent Weafer, head, security response, Symantec, said: “There is an underground economy that guarantees the phishing attacks. In fact, there are money-back guarantees for renting and leasing out tools that can be used for spreading malware and phishing attacks. There are regionalised professional tools that can host a site from a different domain name,” said

Attackers use the local data to outsource these jobs to people without any technical background. Amuleek Bijral, country manager, India & SAARC, RSA, security division, EMC, said: “Basic tools like Mpack are available between $100 and $200 . Sophisticated tools like Zeus, Limbo, Torpig, BankSniff, Haxdoor and Metafisher are available for $600-1000 (Rs 29,000- 48,000).”

Commenting on the underground economy, Bijral said: “It is difficult to ascertain the exact amount for phishing alone, but if we were to look at the amount of money lost due to phishing, trojan and other social engineering attacks it will be in the range of $3-3.5 billion (around Rs 17,000 crore).”

Through the underground markets, a phisher can also “rent” a compromised Web server on which to host his phishing pages. He can further outsource the process by renting another compromised machine from which phishing email can be sent out.

Shantanu Ghosh, vice-president, product operations, Symantec India, said: “Automated phishing toolkits are an example of such outsourcing. A phishing toolkit is a set of scripts that allows an attacker to automatically set up phishing websites that spoof the legitimate websites of different brands, including the images and logos associated with those brands. These are developed by groups or individuals and are sold in the underground economy. These kits are difficult to obtain and expensive, and are more likely to be purchased and used by well-organised groups of phishers, rather than the average user.”

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jan 01 2009 | 12:00 AM IST

Next Story