Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

'Rock Phish' blamed for surge in phishing

Whether a group or person, it's the Keyser Söze of phishing, say experts


The first thing you need to know about Rock Phish is that nobody knows exactly who, or what, they are.

Wikipedia defines the Rock Phish Kit as "a popular tool designed to help nontechnical people create and carry out phishing attacks," but according to security experts, that definition is not correct. They say that Rock Phish is actually a person, or perhaps a group of people, who are behind as much as one-half of the phishing attacks being carried out these days.

No one can say for sure where Rock Phish is based, or if the group operates out of a single country.

"They are sort of the Keyser Söze of phishing," said Zulfikar Ramzan, senior principal researcher with Symantec's Security Response group, referring to the secretive criminal kingpin in the 1995 film, "The Usual Suspects."

"They're doing some pretty scary things out there," he added.

This criminal organization first appeared in late 2004 and was given the name "Rock Phish" because the URLs (Uniform Resource Locators) on the group's fake sites included a distinctive subdirectory named "rock," a technique the group abandoned once phishing filters began looking for the word.

Since then, it has grown to be one of the most prominent phishing groups in operation. It has developed a variety of new attack techniques that have earned the group a kind of grudging respect among security professionals, several of whom declined to be interviewed on the record for this story for fear of being physically harmed. They estimated that the criminal organization's phishing schemes have cost banks more than US$100 million to date.

Rock Phish is not known for targeting the two most popular phishing targets -- eBay and PayPal. Instead, it specializes in European and U.S. financial institutions. At last count, the group had spoofed 44 brands from businesses in nine countries, sending out e-mails that try to trick victims into visiting phony Web sites and entering information such as credit card numbers and passwords. Rock Phish sites have spoofed CitiBank, E*Trade, Barclays, and Deutsche Bank, among others.

Security experts estimated that Rock Phish is responsible for between one-third and one-half of all phishing messages being sent out on any given day. "They are probably the most active group of phishers in the world," said Dan Hubbard, senior director, security and technology research with Websense Inc.

What causes particular concern among security experts such as Hubbard is Rock Phish's ability to stay one step ahead of both security products and law enforcement.

For example, Rock Phish pioneered image spam: the technique of sending e-mail messages in graphic files in order to bypass spam filters, according to security experts.

And just as browser makers have been building phishing filters into their products, the group has begun creating unique URLs for its phishing messages to get around blacklists of known phishing addresses.

These single-use URLS make it extremely difficult for antiphishing researchers to identify and block phishing pages, Symantec's Ramzan said.

This is bad news for products such as the Firefox browser, which uses a blacklist. "Ultimately, technologies that rely heavily on blacklists are going to be useless," Ramzan said.

Rock Phish has contributed to a surge in the number of phishing Web sites over the past few months, according the Anti-Phishing Working Group. In August, the group counted 19,000 phishing URLs. By October, the most recent month for which data is available, that number had nearly doubled to 35,000.

Continued
1 | 2 | NEXT PAGE » 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





BRINGING PERFORMANCE VALIDATION "INTO THE LIFECYCLE"
Today's enterprise apps are complex and ever-changing, which makes delivering high performance difficult. By virtualizing the behavior of application services and data in a VSE, teams can answer this challenge with validation best practices and test tools to ensure solid performance throughout the lifecycle. Register now to attend this webcast! Sponsor: ITKO

»  Click here to view this Webcast
  The Data Protection You've Been Looking For
Enterprise data is of supreme importance. If you can't find it quickly, it's worthless. If you lose it, it's a crisis. This IT Strategy Guide explores how to keep your data safe.

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 
  • Protect Your Data with SSL - Discover how to increase customer confidence in your site with the latest solution in SSL, Extended Validation (EV) SSL ...
  • Need simple, low cost server virtualization? - Do more with less. Support fewer servers. Simplify disaster recovery. Implement proven, easy-to-use server virtualization...
  • Virtually Limitless Virtual Storage - Do you need virtualization space savings of 50% or more with virtually no performance impact? You might be able to get storage...
  • Invisible IT? - The goal of IT is to become an invisible entity within a larger organization. Eliminating visibility and road blocks IT ...
  • It Really Is Easy to be Green - "Green IT" is a popular concept. And IT organizations are learning the influence that IT purchase decisions have on data...
  • Key Strategies For SOA Testing - SOA requires a unique approach to testing. Unless you're willing to reorient your testing procedures and technology now,...

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS  IT EXEC-CONNECT   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist