You are here

Malware Peaks, China Targeted on Fortinet's April'09 Threatscape Report

Highest Malware Volumes Recorded This Year, Online Gaming Makes Asia Activity Swell

SUNNYVALE, Calif., May. 6, 2009 - Fortinet®- a market-leading network security provider and worldwide leader of unified threat management (UTM) solutions - today announced findings from its April 2009 Threatscape eport, which shows new and persistent malware faces contributing to the highest malware volumes detected this year online gaming and adware threats largely among them. China received the brunt of this months malware attack, doubling its share from the last report. Fortinets FortiGuard® Global Security esearch team made the following observations in April:

  • Game-on for New Faces: Four new variants landed in Aprils Top 10 malware list, three of which were online gaming Trojans. The fourth narrowly missed the list at the eleventh position. But W32/Virut.A is still king of the hill, claiming first position for two consecutive months and building on a year-long run within the Top 10 list. Collectively, these threats formed a significant portion of Aprils detected activity. The lucrative marketplace created by online gaming has attracted cyber crime with haste, predominantly in China. China leap-frogged over Japan and the U.S. with a 44.86 percent global malware share, nearly doubling its 24.17 percent share from the last report.
  • Waledacs esilience: One of the most active malware families, Waledac launched a fifth campaign since the beginning of this year, serving up malicious variants disguised as SMS spying software. Waledac, like many blended threats, is multi-functional with the ability to receive and spew custom spam templates, launch denial of service attacks, and download further components. It was also spotted on Confickers network which, in concert with its own various campaigns, has further helped this family gain momentum.
  • Conficker.C Peers: As we anticipated, no significant activity occurred with Conficker.C on the much hyped April 1st date; however, soon after, Conficker.Cs newly established peer-to-peer network became active. Exploit activity with MS.DCEPC.NETAPI32.Buffer.Overflow (MS08-067) picked up once again during the first week of April, returning to February levels after a significant drop in March. The drop was due to Conficker.C variants ceasing exploit activity, while the subsequent increase can be linked to several factors outside of Conficker. Over 31 percent of new vulnerabilities this period (96 in total) were reported to be actively exploited: 36 of the new vulnerabilities were rated as critical, marking a year high, up from 30 in last months report.
  • ÏApril was a busy month for cyber criminals who unleashed the most aggressive malware attacks thus far this year, said Derek Manky, project manager, cyber security and threat research, Fortinet. ÏWe believe this upward trend will endure with online gaming attacks continuing to dominate, especially with eal Money Trading becoming a big business now an estimated $2 billion annual market.

    The FortiGuard research team compiled threat statistics and trends for April based on data collected from FortiGate network security appliances and intelligence systems in production worldwide. Customers who use Fortinets FortiGuard Subscription Services should already be protected against the threats outlined in this report.

    To read the full April Threatscape report which includes the top threat rankings in each category, please visit: http://www.fortiguardcenter.com/reports/roundup_apr_2009.html. For ongoing threat research, bookmark the FortiGuard Center (http://www.fortiguardcenter.com/) or add it to your SS feed by going to http://www.fortinet.com/FortiGuardCenter/rss/index.html. Additional discussion on security technologies and threat analysis can be found at the FortiGuard Blog at http://blog.fortinet.com. To learn more about FortiGuard Subscription Services, visit http://www.fortinet.com/products/fortiguard.html.

    FortiGuard Subscription Services offer broad security solutions including antivirus, intrusion prevention, Web content filtering and anti-spam capabilities. These services help enable protection against threats on both application and network layers. FortiGuard Services are updated by the FortiGuard Global Security esearch Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and zero-day protection from new and emerging threats. For customers with a subscription to FortiGuard, these updates are delivered to all FortiGate, FortiMailÌ¢åãå¢ and FortiClient™ products.

About Fortinet (www.fortinet.com)

Fortinet is a leading provider of network security appliances and the market leader in Unified Threat Management or UTM. Fortinet solutions were built from the ground up to integrate multiple levels of security protection -- including firewall, VPN, antivirus, intrusion prevention, Web content filtering, spyware prevention and antispam -- designed to help customers protect against network and content level threats. Leveraging a custom ASIC and unified interface, Fortinet solutions offer advanced security functionality that scales from remote office to chassis-based solutions with integrated management and reporting. Fortinet solutions have won multiple awards around the world and are the only security products that are certified in five programs by ICSA Labs: Firewall, Antivirus, IPSec VPN, Network IPS and Antispam. Fortinet is based in Sunnyvale, California.

Copyright © 2009 Fortinet, Inc. All rights reserved. The symbols ® and ™ denote respectively federally registered trademarks and unregistered trademarks of Fortinet, Inc., its subsidiaries and affiliates, including, but not limited to, the following trademarks: Fortinet, FortiGate, FortiGuard, FortiManager, FortiMail, FortiClient, FortiCare, FortiAnalyzer, FortiReporter, FortiOS, FortiASIC, FortiWiFi, FortiSwitch, FortiVoIP, FortiBIOS, FortiLog, FortiResponse, and FortiDB. Other trademarks belong to their respective owners. Fortinet has not independently verified statements above attributed to other parties, and Fortinet does not endorse any such statements.

How to Buy

Purchase Fortinet Products


Security virtualization rapidly became the answer to our needs and only Fortinet could offer to virtualize all the essential security functions on a single platform that would scale to thousands of users. On top of the strong performance and flexibility of Fortinet's appliances, we were impressed with Fortinet's management and reporting tools, which will allow us to provide a unique Web interface to our customers so that they have easy control and visibility over their security service.

Hendrik Van De Velde
Vice President, Product and Solution Management
Belgacom