December 3, 2004 12:00 PM PST

This week in phishing

As online shopping gets into full swing, phishers are setting up fraudulent e-commerce Web sites and simply waiting for victims using Google and other search engines to find them.

Traditionally, phishing scammers have lured their victims to fraudulent Web sites by sending official-looking e-mails that are ostensibly from well-known companies asking people to "verify" their usernames and passwords. Now many are setting up legitimate-looking e-commerce sites that disguise links to malicious software as pictures of goods on sale.

Instead of linking to pictures of the advertised product, the links point to a self-extracting Zip file that installs a Trojan horse on the victim's computer. The program could then steal personal and financial information.

In response to the emerging threat, a browser promises to detect phishing sites and nail an increasingly prevalent type of floating Web ad. Deepnet Explorer, a browser shell that uses Microsoft's Internet Explorer to render Web pages, analyzes Web addresses and combs through its own list of suspect sites to determine whether a site might be part of a phishing scam, in which fraudsters attempt to get personal and payment information from unsuspecting visitors.

Version 1.3 of the browser, previously available in a test, or beta, version, also takes aim at a new kind of Web advertisement that has been evading pop-up-blocking software. The ads, called "floating" or "overlay" ads, move around on the screen and are immune to the pop-up controls increasingly common in browsers and browser toolbars.

But monetary losses from phishing fraud may not be as high as some analysts had estimated. Financial consultant TowerGroup said phishing attacks this year will account for less than $150 million in consumer losses worldwide. The finding puts TowerGroup at odds with other researchers, who have put damages as high as $500 million.

Businesses, and not consumers, stand to lose the most from phishing. Phishing attacks lead online users to be more wary of e-commerce sites and e-mail communications, TowerGroup said. That could crimp business during the most lucrative quarter for online retailers, and companies whose brands are co-opted by scammers may have to deal with increased support calls and lost confidence in their brand.

2 comments

Join the conversation!
Add your comment (Log in or register)
PhishFraud.com checks for phishing attempts
A handy tool is a <a class="jive-link-external" href="http://www.phishfraud.com" target="_newWindow">http://www.phishfraud.com</a>. You just forward the email to them and receive an automated response back that confirms or denies whether or not the email was a phishing attempt.
Posted by (3 comments )
Reply Link Flag
confirms or denies
<a class="jive-link-external" href="http://www.analogstereo.com/nakamichi/nakamichi_bx300_service_manual.htm" target="_newWindow">http://www.analogstereo.com/nakamichi/nakamichi_bx300_service_manual.htm</a>
Posted by Ubber geek (325 comments )
Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.57%) 72.81 12,874.04
S&P 500 (0.68%) 9.13 1,351.77
NASDAQ (0.95%) 27.51 2,931.39
CNET TECH (0.84%) 17.13 2,049.14
  Symbol Lookup