Social Networks Pose Security Risks to SMBs

Fewer than half of small and midsize businesses actively enforce social network security policies, finds Panda Security.

By Mathew J. Schwartz
Information Week

One-third of all small and midsize businesses (SMBs) have been infected by malware or viruses that spread via social networks — most often via Facebook, followed by YouTube and Twitter. As a result, 35% experienced a financial loss.

Those findings come from a survey, conducted by Panda Security, of 315 IT personnel who have responsibility for setting or enforcing network policies at companies with between 15 and 1,000 employees. None of the surveyed organizations used Panda’s products.

According to Sean-Paul Correll, a threat researcher at Panda Security, “social media is now ubiquitous among SMBs because of its many obvious business benefits, yet these tools don’t come without serious risks.”

For example, the survey found that social networks are responsible for a sizeable number of “human error” privacy violations. In fact, 23% of organizations reported losing sensitive data via social networks thanks to their employees. Facebook was the most typical social networking channel for privacy violations, followed by Twitter, YouTube, and LinkedIn.

Still, in this day and age, it’s nearly impossible for a business to not have a social networking presence. Indeed, the study found that 78% of businesses surveyed use social media tools, with businesses having active accounts most often with Facebook (70%), followed by Twitter (44%), YouTube (32%), and LinkedIn (23%). The social networks were most often used for personal use, but even so, roughly half of firms also used them for research, competitive intelligence, customer service, and marketing. About one-third also use them for sales purposes.

Furthermore, from a security standpoint, the news from the survey is far from bleak. “While a relatively high number of SMBs have been infected by malware from social sites, we were pleased to see that the majority of companies already have formal governance and education programs in place,” said Correll.

A majority — 64% — of SMBs have security education programs covering social networks. However, only 57% of SMBs currently have a security policy governing the use of social networking, and 81% of that group employs personnel to actively enforce those policies. This means that only 46% of organizations actively enforce social networking security policies.

Interestingly, 25% of SMBs simply block all social media during working hours through a gateway appliance (65%) and/or through a hosted web security service (45%). But during non-work hours, 69% of SMBs allow employees to use social networking tools on corporate computers.

Computer Clarity

Weekly Report on Viruses and Intruders – 01/08/10

This week’s PandaLabs report looks at two fake antiviruses: PcLiveGuard and GreatDefender.

This type of malware passes itself off as legitimate software applications in order to steal users’ money by tricking them into believing that they will eliminate threats on their computers.  Panda Security has published a report on fake antiviruses, available at:

http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf

Similarly, the PandaLabs Annual Report also provides information about the situation of this malware at:http://www.pandasecurity.com/img/enc/Annual_Report_PandaLabs_2009.pdf

PcLiveGuard’s icon resembles a legitimate antivirus icon. When run, a typical screen is displayed, asking users if they want to scan their PCs. See pic at: http://www.flickr.com/photos/panda_security/4255539533/

Regardless of whether users accept or not, it will indicate their computer is infected. Here is the image that will be displayed if users scan their PC (http://www.flickr.com/photos/panda_security/4256301498/).

If users do not scan their PC with the fake antivirus, infection warnings are displayed to scare them into purchasing the product.

GreatDefender is a fake antivirus which informs about potentially dangerous software on the computer, due to it not being correctly protected. It tries to get users to pay with their credit cards in order to install the solution.  The objective of the antivirus is to collect personal and bank details provided by users on purchasing it. As this type of malware cannot reproduce itself, it requires user interaction to infect the PC. To do so, it uses its own websites on which it is advertised as one of the best anti-spyware solutions in the market.

Picture available at: http://www.flickr.com/photos/panda_security/4256301526/

When users access the website, they are given the option to download the antivirus, but when they try, the trial version is unavailable and they are redirected to the pay version.  The installation process is similar to that of any antivirus, allowing users to select the language and location of the files. Once the installation ends, the fake antivirus carries out a full system scan.  It then falsely ensures users that their computers are free from any infections.  To make users believe they are protected, an icon is displayed in the Windows desktop, the quick taskbar and the Windows start menu, to make it look as authentic as possible.

Computer Clarity

A New Category of Malware Has Emerged

According to Panda Security and PandaLabs, the global leaders in computer security, “Rogueware consists of any kind of fake software solution that attempts to steal money from PC users by luring them into paying to remove nonexistent threats.”  They also point out the following facts:

  • Rogueware attacks generate approximately $34 million per month for cybercriminals
  • Each month rogueware infects approximately 35 million computers
  • Twitter, Facebook, MySpace, and Digg, are used to spread rogueware
  • Eastern Europe is the source of the majority of cybercriminals
  • Rogueware is difficult to detect because it changes quickly

Because of these facts, your computer will encounter rogueware and your antivirus might not catch it.  So, what does a rogueware attack look like?  A window appears on your computer screen announcing the presence of viruses on your computer and offering to remove them if you pay them $40-$90.  If you don’t, the program starts hiding different windows controls and continues to warn you with popup windows until you do pay.  Then they will wait a random period of time before they do it again.  Once the rogueware is installed, it can be very difficult to remove, so it is best to catch and stop the installation attempt.  Fortunately this is very easy.  Rogueware tries to look like an antivirus.  You must know who your antivirus company is and don’t trust any other antivirus warning.  When you see a warning, identify what program is issuing the warning.  If it is not your antivirus software, then it is a rogue security officer trying to gain entry into your computer.

When this occurs on your computer you must close the window without following any of its instructions and without touching the window.   You must use the taskbar button below that represents the window, right click it, then hit close.  This should close the window, but if it does not, press and hold your power button on your computer.  You may lose any unsaved work, but it is better than removing the rogueware after the infection.

Rogueware and other types of malware threats are extremely prolific on the internet.  Antivirus companies are trying franticly to keep up with the threat, but only one is on top of it.  Panda Security makes and distributes the best computer security solutions and PandaLabs discovers the threats and writes the antivirus updates before the rest of the antivirus companies even know about it.  Several teams, each specialized in a specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc), work 24/7 to provide global coverage. To achieve this, they also have the support of TruPrevent® Technologies, which act as a global early-warning system made up of strategically distributed sensors to neutralize new threats and send them to PandaLabs for in-depth analysis. According to Av.Test.org, PandaLabs is currently the fastest laboratory in the industry in providing complete updates to users. According to my own test, Panda Security Solutions are the best available.

Computer Clarity