Image spam makes a comeback

Seems like it's 2007 again.

Spammers have turned back the clock and are recycling a years-old tactic by planting their messages in images, according to a security researcher.

Image spam, which hit a peak in late 2006 and early 2007, has made a comeback, said Holly Stewart, the threat response manager of IBM Internet Security System's X-Force team. After barely registering during most of 2008, image-based spam accounted for about 25 percent of all spam by the end of last month.

"They're doing the same kind of image-based spam as in 2006 and 2007," said Stewart. "It's very surprising."

It's surprising because spammers that rely on technological trickery rarely return to an older tactic once anti-spam vendors have figured out how to detect the junk mail. "But what they're doing now is exactly what they were doing before," added Stewart.

When spammers first started using images rather than text, they were successful at slipping their pitches through filters, which were designed only to parse text and look for such things as links. Their success led to an explosion in image-based spam, with spammers and security firms playing a cat-and-mouse game for months.

The only real difference this time around, Stewart said, is the sales pitch. "Most image spam was stock 'pump-and-dump,' but now the focus is on drugs and pills, something to make you feel better in hard times," said Stewart, who credited the change to the recession and the poor performance - and even harsher perception - of Wall Street.

Also odd, she continued, is that few of the messages included ready-to-click links. Instead, the images contain a URL that the user must laboriously type in manually.

Spammers conducted an image spam test run in March, according to X-Force's data, which showed a spike in the tactic from about 19 March to 9 April. The test was obviously successful, Stewart said, because after a short period when the tactic disappeared entirely, it roared back with a vengeance on 21 April.

"Actually, it's pretty incredible that this could be successful again," Stewart said, noting that most anti-spam filters should block the mail, unless the vendor, perhaps for performance reasons, had ditched them when image-based spam vanished last year.

The return of image spam could be the first resurrection of other once-popular tactics, she warned. "We may see others come back," Stewart said, and ticked off MP3 spam - mail that replaced text with an audio clip - and PDF-based spam. Both were popular in 2006 and 2007 for junk stock pushers.

Of the discarded tactics, Stewart selected PDF spam as the one most likely to reappear. "It was short-lived [before], but if I had to pick, I would point to the PDF vector," she said, noting that rigged PDFs exploiting Adobe bugs have been on a tear of late.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

PayPal users close accounts after Cryptome attack

Online money service loses business, restores whistleblower's account

Zeus botnet malware is improving for hackers

For $10,000, criminals can take control of infected PCs

Fake antivirus software is most costly security scam of 2010

McAfee reports 400% increase in reported incidents

Adobe Reader most attacked application, says F-Secure

Hackers target PDF bugs more than Microsoft Word



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Download Whitepaper

Strategic mobile deployments

Deploying mobile applications? Supporting multiple devices? See why mobile platforms should be part of your IT strategy.

Download Whitepaper

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Download Whitepaper

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

Download E-Book
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *