Google Says Infected Spam Is Getting Worse

The company's Postini corporate e-mail security service reported that the volume of e-mail virus attacks peaked at almost 10 million on a single day.

Thomas Claburn, Editor at Large, Enterprise Mobility

August 12, 2008

2 Min Read
Dark Reading logo in a gray background | Dark Reading

On its enterprise blog on Tuesday, Google plans to report that it saw more infectious spam messages in July than any month so far this year.

According to data gathered by Google's Postini corporate e-mail security service, the volume of e-mail virus attacks peaked at almost 10 million on a single day, July 24.

That kind of volume, six to seven times what's typical, means spam messages are getting through someone's defenses and turning recipients' machines into zombies, said Sundar Raghavan, a product marketing manager with the Google Apps Security & Compliance team.

"The summer of spam has caught up with us this time," said Raghavan.

Raghavan suggests that in contrast to the message protection Google delivers from the Internet cloud, anti-spam hardware appliances that don't update fast enough may allow malicious e-mail attacks to succeed.

Much of the spam that Google is seeing aims to exploit not browser or operating system vulnerabilities but user curiosity. Thus, explained Raghavan, spam now takes the form of spoofed CNN newsletters with link descriptions designed to bait the user, such as "Microsoft Bribes Chinese Officials." Clicking such links in spam messages, however, generally leads to malware.

Raghavan also said that Google has seen an increase in e-mail messages with viruses concealed as encrypted .RAR attachments, despite an overall decrease in malicious attachments.

Marshal, an e-mail security company, on Tuesday issued its security report covering the first half of 2008. In the first six months of 2008, the company says spam volume doubled.

Marshal said that because of unpatched browsers, 45% of Internet users are at risk when they visit legitimate Web sites hosting malicious code. And there are many such sites. In May, the company identified 1.5 million Web sites infected with malware as a result of a botnet attack.

It may not come as a shock that Marshal, as a maker of e-mail security hardware, has more faith in e-mail security hardware than Google.

"We are now in the situation where spam accounts for almost 90% of all e-mail and increasingly contains links to infected sites," VP of products Bradley Anstis said in a statement. "Companies really need to employ a combination of e-mail security gateways that have anti-spam protection using multiple techniques to block malicious content and secure Web gateway products that do not just rely on URL filtering but also scan the content that end users are downloading and uploading in real time."

E-mail users may also want to consider in-brain message filtering (no purchase required). Just as one might be skeptical of offers of wealth from a mysterious Nigerian benefactor, one might also refrain from clicking on links to suspect news stories along the lines of "Steve Jobs Uses Windows Vista At Home" or "Google Provides NSA With Real-Time Search Data."

Read more about:

2008

About the Author

Thomas Claburn

Editor at Large, Enterprise Mobility

Thomas Claburn has been writing about business and technology since 1996, for publications such as New Architect, PC Computing, InformationWeek, Salon, Wired, and Ziff Davis Smart Business. Before that, he worked in film and television, having earned a not particularly useful master's degree in film production. He wrote the original treatment for 3DO's Killing Time, a short story that appeared in On Spec, and the screenplay for an independent film called The Hanged Man, which he would later direct. He's the author of a science fiction novel, Reflecting Fires, and a sadly neglected blog, Lot 49. His iPhone game, Blocfall, is available through the iTunes App Store. His wife is a talented jazz singer; he does not sing, which is for the best.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights