Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, 3 September 2013

Organisations lack visibility on malware attacks, survey confirms


Many organisations affacted by malware in the last year either had no idea how it had bypassed their security or simply suspected their expensively-assembled antivirus defences had failed to detect it, a survey by reputation vendor Bit9 has found.

Reading between the lines of the firm’s 2013 Cyber Security Survey, an unexpected fatalism starts to emerge from the numbers.

It was not a huge surprise that seven out of ten of the 250 US, UK IT managers who responded identified the PC (i.e. not tablets or smartphones) as the soft underbelly. That much has been known for some time; security staff understand that Windows is seen by cybercriminals as the most easily-prised door into any organisation.

What was more disquieting was that of the 47 percent that had experienced at least one cyberattack, a susprising number seemed unable to work out how malware might have been used in such events. Forty percent believed it had bypassed antivirus, 27 percent that it bypassed network-level security, 25 percent that it had arrived on a USB device, 17 percent while a mobile device (i.e. a laptop) was travelling, while 31 percent admitted they had no idea.

Just over half rated their organisation’s ability to detect suspicious activity before damage was done as being either average, deficient, or in 2 percent of cases, “non-existent.” The problem is visibility. Only forty-two percent of respondents believed their organisation’s ability to monitor files in real-time was good or excellent.

Similarly, many admitted they might struggle to work out which endpoints had been affected in an outbreak, whether in real time or when conducting a retrospective forensic investigation.

“The 2013 Cyber Security Survey shows proof that traditional, signature-based security defences cannot keep up with today’s advanced threats and malware,” said Bit9 CSO, Nick Levay.

“These statistics are in line with what we hear from our customers: security teams have limited to no visibility into what is happening on their endpoints and servers. If malware is suspected, there is no way of knowing which machine it’s running on, if it executed or what it is doing,” he said.

“There are often no historical details to determine when a threat arrived and executed, leading to slow remediation.”

According to Levay, the most astonishing statistic was that 13 percent of those surveyed didn’t even know whether they had experienced a cyberattack or not. Many IT departments were simply struggling to defend themselves using a first-generation security model based on antivirus.

Bit9’s answer is whitelisting technology. It would be an omission in story on the firm not to mention that it had its own security embarrassment earlier this year when an attacker was able to hack one of its digital certificates to install malware at three customers.

“The fact that this happened - even to us - shows that the threat from malicious actors is very real, extremely sophisticated, and that all of us must be vigilant.  We are confident that the steps we have taken will address this incident while preventing a similar issue from occurring again,” Bit9 said at the time.

Tuesday, 27 August 2013

Android mobile malware rebounds in Q2, reports McAfee


Android-based malware has grown by 35% in the second quarter, according to the latest threat report from security firm McAfee.

This represents a rebound, as this growth rate has not been seen since early 2012.


mobile_malware_290x230_thinkstock.jpg
McAfee said the rebound is marked by the continued proliferation of SMS text-stealing banking malware, fraudulent dating and entertainment apps, weaponised legitimate apps and malicious apps posing as useful tools.

McAfee CanadaMcAfee Labs registered twice as many new ransomware samples in the second quarter as in the first quarter, raising the 2013 ransomware count higher than the total found in all previous periods combined.

The second quarter also saw a 16% increase in suspicious URLs, a 50% increase in digitally-signed malware samples, and notable events in the cyber attack and espionage areas.

These include multiple attacks on the global Bitcoin infrastructure and revelations around the Operation Troy network targeting US and South Korean military assets.

“The mobile cyber crime landscape is becoming more defined as cyber gangs determine which tactics are most effective and profitable,” said Vincent Weafer, senior vice-president at McAfee Labs.

“As in other mature areas of cyber crime, the profit motive of hacking bank accounts has eclipsed the technical challenges of bypassing digital trust,” he said.

According to Weafer, tactics such as the dating and entertainment app scams benefit from the lack of attention paid to such schemes.

Others, he said, simply target the mobile paradigm’s most popular currency: personal user information.

Wednesday, 14 August 2013

More Android malware distributed through mobile ad networks

Mobile ad networks can provide a loophole to serve malware to Android devices, according to researchers from security firm Palo Alto Networks who have found new Android threats being distributed in this manner.

Most mobile developers embed advertising frameworks into their applications in order to generate revenue. Unlike ads displayed inside Web browsers, ads displayed within mobile apps are served by code that's actually part of those applications.

The embedding of code for the advertising network into a mobile application itself ensures that ads get tracked and the developers get paid, but at the same time this third-party code represents a backdoor into the device, said Wade Williamson, senior security analyst at Palo Alto Networks, in a Monday blog post.

"If the mobile ad network turns malicious, then a completely benign application could begin bringing down malicious content to the device," Williamson said. "What you have at that point is a ready-made botnet."

There are precedents for this type of attack. In April, mobile security firm Lookout identified 32 apps hosted on Google Play that were using a rogue ad network later dubbed BadNews. The apps were benign, but the malicious ad network was designed to push toll fraud malware targeting Russian-speaking users through those apps. The malware masqueraded as updates for other popular applications.

According to Williamson, researchers from Palo Alto Networks recently came across a similar attack in Asia that involved using a rogue ad network to push malicious code through other apps without being detected by mobile antivirus vendors.

The malicious payload pushed by the ad network runs quietly in the device memory and waits for users to initiate the installation of any other application, Williamson said. At that point, it prompts users to also install and grant permissions to the malware, appearing as if it's part of the new application's installation process, he said.

"This is a very elegant approach that doesn't really require the end-user to do anything 'wrong'," the researcher said.

Once installed, the malware has the ability to intercept and hide received text messages, as well as to send text messages in order to sign up users for premium-rate mobile services, Palo Alto Networks said in a description of the attack sent via email.

Such attacks are probably specific to certain geographic regions, said Bogdan Botezatu, a senior e-threat analyst at antivirus vendor Bitdefender, Tuesday via email.

Botezatu expects the distribution of malware through mobile ad networks to become more common, especially in countries where mobile devices can't access the official Google Play store or where users have difficulties in purchasing applications in a legitimate manner, causing most Android devices to be configured to accept APKs (Android application packages) from unknown sources.

That doesn't mean that apps that deliver malware through ad networks can't make it into Google Play, as the BadNews incident has shown.

Google Play checks APKs for malware before approving them, so getting an infected APK uploaded there can be very hard, Botezatu said. However, a malicious ad server could lay dormant until after the application is approved and then start delivering malware, he said.

Botezatu believes that users are more likely to fall victim to "malvertising" -- malicious advertising -- attacks launched through mobile apps than Web browsers. That's because there have been many incidents of ad-based malware infections on computers and users are probably more careful about what they click on inside their browsers, he said.

Android users should make sure that their devices are not configured to allow the installation of apps from unknown sources and should run a mobile antivirus product, which might be able to detect malicious apps delivered through ad networks, he said.

Tuesday, 6 August 2013

Attackers reported seeding cloud services with malware

LAS VEGAS -- Malware writers are ramping up their use of commercial file hosting sites and cloud services to distribute malware programs, security researchers said at this week's Black Hat conference here.

Traditionally, malware writers had distributed their malicious code from their own sites.

But as security vendors get better at detecting and blacklisting those sites, hackers are increasingly distributing their malware products from legitimate host sites. The technique has been used a bit for more than two years, but now appears be gaining steam, researchers said. (See also "When malware strikes: How to clean an infected PC."

Often, the owners of legitimate sites fail to properly scan the content they are hosting, which allows attackers to furtively post malicious code with relative ease, said Michael Sutton, vice president of research at ZScaler, a provider of cloud-based security services for enterprises.

Malicious content distributed from a legitimate site is more likely to make it past corporate defenses. Vendors are also unlikely to blacklist a legitimate hosted service, allowing malicious content hosted on one to stay up longer, he said.



defcon
Zscaler said he's heard reports of malicious files hosted on Dropbox, but the they appear to have been removed, the blog noted.

Sutton pointed to recent incidents were attackers posted and distributed malicious code on Google Code and Dropbox as an example of the trend. A blog on Zscaler's website lists nearly three dozen malicious files hosted on the Google Code site, which contains tools for software developers.

The message for IT managers: Don't blindly trust domains that seem to be secure, Sutton said.

"Attackers are starting to leverage hosting services" to stage malicious code, he said. "It used to be that [attackers] would set up their own servers," to host malware. "Then we saw them infecting legitimate third-parties. Now they are using hosting services. They are no longer paying for hosting [malware] and are less likely to get blacklisted."

Meanwhile, Firehost, a provider of cloud-hosting services for enterprises, has seen an increase in Web application attacks originating from the networks of legitimate Web hosting services, said CEO Chris Drake.

In its latest quarterly security review, Firehost observed a noticeable increase in the number of SQL injection attacks, directory traversal attacks and other Web application attacks launched from within cloud service provider networks, Drake said.

Cloud providers often have weak validation procedures when signing up new customers, allowing attackers to create accounts with fake information. The accounts are then used to deploy and administer powerful botnets that run in the cloud infrastructure, he said.

In the second quarter of 2013, the IP filtering system that Firehost uses to protect its customers against malicious attacks blocked about 1.3 million unique attacks. Of the total, a noticeable number of attacks originated from IP addresses belonging cloud services companies, Drake said.

Wednesday, 17 July 2013

New digitally signed Mac malware confuses users with right-to-left file name tricks

A new piece of digitally signed spyware for Mac OS X uses a special Unicode character in its file name to hide its real file extension from users and trick them into installing it.

The malware, which has been dubbed Janicab.A, is written in Python and is packaged as a stand-alone Mac application using the py2app utility, researchers from security firm F-Secure said Monday in a blog post.
It is distributed as a file called “RecentNews.?fdp.app” where the “?” is actually the right-to-left override (RLO) character known as U+202E in the Unicode encoding standard.

Unicode supports characters from most languages, including those written from right to left like Arabic and Hebrew. The special RLO character tells software that the text following it should be displayed from right to left.

Apple displays double extensions for security reasons in the Mac OS X file manager, said Sean Sullivan, a security advisor at F-Secure, Tuesday via email. “Here, the RLO trick is being used to counter that and to make the .app appear to be a .pdf.”

The trick itself is not new and has been used by Windows malware in the past, including by the Bredolab email spam malware and the Mahdi cyberespionage Trojan program that targeted computers in the Middle East.

Opening the Janicab .app file will trigger a standard Mac OS X pop-up dialog warning the user that the file was downloaded from the Internet. However, because of the RLO character in the file name, the entire warning text will be written right to left making it confusing and hard to read.

If users agree to open the file, the malware will install itself in a hidden folder in the user’s home directory and will open a decoy PDF document containing what appears to be a news article in Russian.

Janicab continuously takes screenshots and records audio and uploads the collected data to command and control (C&C) servers that it finds by parsing the description of specific YouTube videos. It also queries the C&C servers for commands to execute, the F-Secure researchers said in the blog post.

Based on statistics for the YouTube videos whose descriptions are parsed by the malware, the malware’s functionality and the contents of the decoy document, F-Secure researchers believe the malware is being used in targeted attacks, Sullivan said. However, the company doesn’t have any information about the identity of the targets, he said.

Janicab samples were uploaded to the VirusTotal malware scanning service from five countries, but that information might reflect the locations of different security researchers, not victims, Sullivan said.
The malware’s installer is digitally signed with a code-signing certificate—an Apple Developer ID—issued by Apple to a person named “Gladys Brady.”

In May, security researchers found several samples of a Mac OS X backdoor-type program called KitM or HackBack, that were digitally signed with a valid Apple Developer ID issued to “Rajinder Kumar.” One of those samples was collected from the Mac laptop of an Angolan activist attending the Oslo Freedom Forum, a human rights conference in Norway.

Researchers linked the KitM samples to a larger cyberespionage campaign of Indian origin dubbed Operation Hangover.

F-Secure reported the new certificate being abused by the Janicab malware to Apple, but has yet to receive confirmation of any action taken by the company, Sullivan said. “They quickly revoked the certificate in the previous KitM case,” he said. “I have no doubt they’ll also revoke this developer [ID] soon if they haven’t already.”

The F-Secure researchers believe that Apple is likely to create a removal tool for Janicab as it did for the “Pintsized” Mac OS X malware discovered in February.


“As the popularity of OS X continues to grow, Apple users have to get used to the fact that they will become targets for malware authors,” said Gavin Millard, EMEA technical director at security firm Tripwire, via email. “Although the RLO (Right Left Override) approach of obfuscating the true extension of a file is simple to spot, users will still click, especially as they are not used to being targeted.” 

Monday, 15 July 2013

Unusual file-infecting malware steals FTP credentials

A new version of a file-infecting malware program that’s being distributed through drive-by download attacks is also capable of stealing FTP (File Transfer Protocol) credentials, according to security researchers from antivirus firm Trend Micro.

The newly discovered variant is part of the PE_EXPIRO family of file infectors that was identified in 2010, the Trend Micro researchers said Monday in a blog post. However, this version’s information theft routine is unusual for this type of malware.

The new threat is distributed by luring users to malicious websites that host Java and PDF exploits as part of an exploit toolkit. If visitors’ browser plug-ins are not up to date, the malware will be installed on their computers.

The Java exploits are for the CVE-2012-1723 and CVE-2013-1493 remote code execution vulnerabilities that were patched by Oracle in June 2012 and March 2013 respectively.


Based on information shared by Trend Micro via email, a spike in infections with this new EXPIRO variant was recorded on July 11. “About 70 percent of total infections are within the United States,” the researchers said in the blog post.

Once the new EXPIRO variant runs on a system, it searches for .EXE files on all local, removable and networked drives, and adds its malicious code to them. In addition, it collects information about the system and its users, including Windows log-in credentials, and steals FTP credentials from a popular open-source FTP client called FileZilla.

The stolen information is stored in a file with a .DLL extension and is uploaded to the malware’s command and control servers.

“The combination of threats used is highly unusual and suggests that this attack was not an off-the-shelf attack that used readily available cybercrime tools,” the Trend Micro researchers said.

The theft of FTP credentials suggests that the attackers are either trying to compromise websites or are trying to steal information from organizations that is stored on FTP servers. However, it doesn’t appear that this threat is targeting any industry in particular, the Trend Micro researchers said via email.

Hackers use Dropbox, WordPress to spread malware

The Chinese cyberspies behind the widely publicized espionage campaign against The New York Times have added Dropbox and WordPress to their bag of spear-phishing tricks.

The gang, known in security circles as the DNSCalc gang, has been using the Dropbox file-sharing service for roughly the last 12 months as a mechanism for spreading malware, said Rich Barger, chief intelligence officer for Cyber Squared. While the tactic is not unique, it remains under the radar of most companies.

"I wouldn't say it's new," Barger said on Thursday. "It's just something that folks aren't really looking at or paying attention to."

The gang is among 20 Chinese groups identified this year by security firm Mandiant that launch cyberattacks against specific targets to steal information. In this case, the DNSCalc gang was going after intelligence on individuals or governments connected to the Association of Southeast Asian Nations. ASEAN is a non-governmental group that represents the economic interests of ten Southeast Asian countries.

The attackers did not exploit any vulnerabilities in Dropbox or WordPress. Instead, they opened up accounts and used the services as their infrastructure.

The gang uploaded on Dropbox a .ZIP file disguised as belonging to the U.S.-ASEAN Business Council. Messages were then sent to people or agencies that would be interested in the draft of a Council policy paper. The paper, contained in the file, was legitimate, Barger said.

When a recipient unzipped the file, they saw another one that read, "2013 US-ASEAN Business Council Statement of Priorities in the US-ASEAN Commercial Relationship Policy Paper.scr." Clicking on the file would launch a PDF of the document, while the malware opened a backdoor to the host computer in the background.

Once the door was open, the malware would reach out to a WordPress blog created by the attackers. The blog contained the IP address and port number of a command and control server that the malware would contact to download additional software.

Dropbox is a desirable launchpad for attacks because employees of many companies use the service. "People trust Dropbox," Barger said.

For companies that have the service on its whitelist, malware moving from Dropbox won't be detected by a company's intrusion prevention systems. Also, communications to a WordPress blog would likely go undetected, since it would not be unusual behavior for any employee with access to the Internet.

In general, no single technology can prevent such an attack. "There's no silver bullet here," Barger said.

The best prevention is for security pros to share information when their companies are targeted, so others can draw up their own defense, he said.

In The New York Times attack, the hackers penetrated the newspaper's systems in September 2012 and worked undercover for four months before they were detected.

The attack coincided with an investigative piece the newspaper published on business dealings that reaped several billion dollars for the relatives of Wen Jiabao, China's prime minister.

Monday, 8 July 2013

Gadgetwise Blog: Q&A: Avoiding Mobile Malware

Why is Android such a big target for malware, and how can I tell if an app may be suspect before I install it?

Android has become the dominant mobile operating system around the world, and like Windows before it, malware writers typically target the most commonly used platform in hopes of snaring the most victims. Not all phones can run the latest, more secure versions of the Android system, which can make them more vulnerable to malicious apps. Third-party app sites help spread malicious software as well.

Common sense and a discerning eye can help keep your device safe. If you want to avoid malicious apps, get new software from trusted sources like the Google Play store or Amazon’s Android app store — and avoid installing any apps from random third-party sites.

Although it does not make developers go through a formal approval process when submitting new apps, Google does automatically scan apps that are added to its Google Play store for malware. The company has also withdrawn bad apps that have wormed their way into the store.

Sticking with apps from well-known developers or apps that have been professionally reviewed can help keep you away from the junk and scam programs that may have made it into the store. (Badly written or spammy apps are a universal problem and Apple’s App Store has plenty of those, too.)

Even when shopping in the Google Play store, you should thoroughly check out an app before installing it. Be wary of apps that seem to have a lot of downloads and high ratings — but a minimal amount of written reviews — since a scammer may be trying to get attention. You can also check the app’s Permissions tab on the Google Play page to see what parts of your Android phone or tablet it wants to use, and then avoid apps that look too invasive.

If you like to visit third-party app sites, you may want to consider installing mobile security software from a reliable company. Some apps, like Lookout or F-Secure, also help track lost phones and remotely wipe data — because a missing or stolen device may be more of a security problem than malware for many people anyway.

Follow me on Twitter @sajilpl

Saturday, 29 June 2013

New disk wiper malware linked to attacks in South Korea

A new piece of malware designed to delete files from hard disk drives and render computers unable to boot targets South Korean users, according to researchers from security firm Symantec.

 

The malware is similar to the Jokra Trojan program that was used in March to wipe the hard drives of computers belonging to several banks and TV broadcasters in South Korea, leading to significant disruptions of their operations.

 

The attack in March was attributed by security experts to a hacker gang called "DarkSeoul" that's also believed to be responsible for the distributed denial-of-service attacks from Tuesday against South Korean websites, including that of South Korean President Park Guen-hye.

 

The new hard-drive wiper malware is called Trojan.Korhigh and was found by Symantec researchers during their investigations into cyberattacks in South Korea. "Trojan.Korhigh has the functionality to systematically delete files and overwrite the Master Boot Record (MBR) on the compromised computer, rendering it unusable," the Symantec researchers said Thursday in a blog post.

 

The Master Boot Record (MBR) resides at the beginning of a storage drive and contains information about how that drive is partitioned. It also includes boot code that runs before the operating system starts. If the MBR is missing, a computer will no longer be able to load the operating system.

 

In addition to overwriting the MBR on compromised computers, the Korhigh Trojan program can also wipe files with specific extensions, including executable files, libraries, Web pages, videos and images.

 

The malware can also be instructed to change the user passwords on the infected computers to highanon2013 and to replace the desktop wallpaper with an image that mentions a group called High Anonymous.

 

Korhigh gathers information such as the operating system version, the computer's name and the current date from infected computers and uploads the data to remote servers, the Symantec researchers said.

 

South Korean officials frequently blame North Korean hackers for cyberattacks against local organizations and websites. However, there is also technical evidence linking some computer attacks in South Korea to Chinese-speaking hacker groups.

 

Earlier this week, researchers from Israeli security firm Seculert reported that a piece of malware called PinkStats has been used by Chinese hackers to compromise over 1,000 computers belonging to dozens of organizations in South Korea, including many educational institutions.

 

The identities of the attackers behind the Korhigh Trojan program cannot be confirmed, the Symantec researchers said, noting that their investigation of the threat continues.

 

 

Thursday, 27 June 2013

Citadel malware variant uses content localization to target brands and users in different countries

A new variant of the Citadel financial malware uses in-browser injection techniques combined with extensive content localization to steal log-in credentials and credit card information from users in different countries, according to researchers from security vendor Trusteer.

 

Citadel has the ability to modify or replace websites opened by users on infected computers. This is known as a man-in-the-browser attack and is frequently used by financial Trojan programs to trick users into exposing their log-in details and other sensitive information.

 

The new Citadel variant targets users of social networks, banks and major e-commerce sites, including Amazon and its local versions in France, Spain, Italy and Germany, the Trusteer researchers said in a blog post.

 

International as well as local brands are targeted, said Etay Maor, fraud prevention manager at Trusteer, Thursday via email.

 

When the targeted websites are accessed from computers infected with the new Citadel variant, the malware replaces them with rogue versions that claim users' accounts were blocked because of suspicious activity. The victims are then asked to input their personal and credit card information in order to confirm that they are the legitimate owners of the accounts and proceed to unlock them.

 

This particular social engineering technique has been used for years in phishing attacks. However, unlike in traditional phishing, when websites are modified locally by Citadel or similar malware, the URLs displayed in the browser's address bar are those of the legitimate websites.

 

The use of localized HTML injections by financial malware is not new, but the extra effort put into this new Citadel variant to make the rogue content believable makes it stand out, Maor said.

 

The particular variant uses some interesting technical tricks to create the injection screens, Maor said. For example, it includes customized drop down menus and requests for information generated in local languages, he said.

 

These implementation aspects, the operating team's behavior and the botnet's command-and-control structure point to a detail-oriented and professional operation, Maor said.

 

Based on data collected and analyzed by Trusteer, the company's researchers estimate that several thousands of computers have been infected with this new Citadel variant so far.

 

Earlier this month Microsoft said that it worked with the FBI and other technology industry partners to disrupt more than 1,400 botnets based on the Citadel malware. The company estimated at the time that those botnets were responsible for more than US$500,000 million in losses to people and businesses around the world.

 

Microsoft's effort disrupted the operation of many Citadel botnets, but anyone with a Citadel builder -- an application used to build customized versions of the Trojan program -- can create a new variant and start a new operation of his own, Maor said. "We actually see new Citadel botnets in play."

 

Follow me on Twitter @sajilpl

Wednesday, 26 June 2013

Chinese malware attack affected dozens of South Korean organizations, researchers say

A recent targeted attack that used Chinese malware compromised over 1,000 computers belonging to dozens of South Korea organizations, according to researchers from Israeli security firm Seculert.

The main malware tool used in the attack is called PinkStats and has been used by several Chinese-language groups to target different organizations and nation states from around the world during the past four years, the Seculert researchers said Tuesday in a blog post.

PinkStats is designed to download and install additional malicious components after it infects a computer and then report successful installations to its command and control server.

In the South Korean attacks, the malware installed a common Chinese attack tool called "zxarps" that acts as a worm on the local network, the Seculert researchers said.

The "zxarps" tool uses a technique called ARP poisoning to intercept Web sessions from other computers on the network and inject a malicious ActiveX component into them. If executed, the ActiveX control installs the PinkStats malware.

The malicious component was signed with a valid digital certificate issued by certificate authority Thawte to what is likely a fake company with a South Korean name, the researchers said.

A second component installed by PinkStats is a malware tool used to launch DDoS (distributed denial-of-service) attacks. The component masquerades as software developed by South Korean antivirus vendor AhnLab.

The attackers don't seem to have sent any specific instructions to the DDoS malware yet, the Seculert researchers said. However, it is reasonable to assume that this could change at any time, they said.

Data obtained by Seculert researchers from a PinkStats administration panel suggests that over 1,000 computers in South Korea were infected in the recent attack. Many of those machines belong to universities and other educational institutions.

Earlier this year, attackers used malware to cripple the computer networks of several South Korean banks and TV broadcasters. While many in South Korea blamed North Korean hackers for the attack, some security researchers said the malware's code is distinctly Chinese.

Even though there has been speculation that Chinese-speaking hackers have attacked South Korean organizations before, PinkStats seems to be the first proof of such an attack, the Seculert researchers said.

Google adds malware, phishing numbers to its transparency report to make the Web 'safer'

Google is revealing some new numbers around malware and phishing attempts in an effort to get more people thinking about online security and to make the Web safer.

 

The data is being incorporated into the company’s biannual transparency reports, which are meant to provide clarity on the numbers for user data requests Google receives from government agencies and courts, as well as figures on removal requests received from copyright owners and governments and traffic reports for Google services worldwide.

 

Phishing and malware sites detected by Google

 

The malware and phishing data stems from Google’s Safe Browsing technology, which was established in 2006 to examine billions of URLs each day to find unsafe websites. These unsafe sites, Google said, generally fall into two categories: malware sites, which use code to install malicious software on users’ computers; and phishing sites, which fake their legitimacy while trying to trick people into giving their user names and passwords or other private information online.

 

As of June 16, for instance, the company’s Safe Browsing program had detected nearly 42,000 malware sites per week, according to data Google released Tuesday. For phishing sites, the rate clocked in at roughly 26,000.

 

Concerns over online security have been heightened in recent months following a spate of cyberattacks carried out against major companies such as The New York Times and the Jeep car company on sites like Twitter.

 

Google’s thinking is that by providing details about these sorts of threats, “we hope to shine some light on the state of web security and encourage safer web security practices,” the company said in its report.

 

Google Safe Browsing is currently used by some 1 billion people, the company said. The service shows warnings when users navigate to unsafe websites while using the Google Chrome, Mozilla Firefox and Apple Safari browsers.

 

With the new figures, people can see how many Safe Browsing warnings are delivered to users each week (more than 88 million as of June 16); where malicious sites are hosted around the world (Europe is a bit of a hotbed); how quickly websites become reinfected after malware is removed (the rate “rises dramatically,” due to periodic rescanning of infected sites, Google said); and other tidbits like webmaster response time.

 

“We’re always looking for new ways to protect users’ security,” said Google software engineer Lucas Ballard in a blog post announcing the data.

 

Users can report websites suspected of hosting or distributing malware here, or a suspected phishing site here, Google notes.

 

The report also includes a section on “notable events,” which details some specific security incidents that are responsible for the larger trends contained in the report. Earlier this month, for instance, a campaign targeting vulnerabilities in Java and Acrobat Reader infected more than 7,500 sites, resulting in more than 75 million Safe Browsing users to receive malware warnings.

 

As part of its larger transparency report, Google last released numbers on data removal requests in April, when they spiked to over 2000.