The return of "old school" spam

Thu Jul 2, 2009 12:46PM EDT

See Comments (4)

Every quarter Google and Postini take a joint look at the state of the spam industry, its undulations and upheavals. And the results for the most recent quarter, ended June 30, are in.

In many ways, the results are unsurprising: Spam is up again, with levels 53 percent higher than the first quarter of the year, but just 6 percent higher than the second quarter of 2008. (Spam levels were uncommonly low last quarter following the shut-down of the ISP McColo, a notorious haven for spammers. Those spammers have largely found other services to host their activities, and spam levels have since rebounded.)

But rising spam levels are not exactly a surprise. The big news in the latest figures is the return of spammers to traditional, almost "old school" methods.

One of the big ones is the sudden reemergence of image spam, a very simple form of spam in which the advertisement or message is embedded into an image inside an email. Image spam became common in 2007 because spam filters at the time where focused on filtering certain keywords, so spammers responded by recreating those words as graphics, which would sail through the filters. Spam filters have since adapted to this technique, but now it's coming back. Why? Hard to say, but my hunch is that so many email messages contain images now -- both commercial and personal -- that unilaterally filtering out image content is no longer an effective strategy. I know when I receive an email that contains mostly hidden images, I almost always choose to "show images" in my email client; there's just no other way to figure out whether it's something useful or not.

The Google/Postini report also offers some other possible explanations, including the likelihood that spammers are "testing" spam filters, or trying out their replacement ISPs with older techniques before advancing on to something more sophisticated.

Another old-school spam technique on the rise: Viruses sent as email attachments. Again, this is an attack that has fallen out of favor in recent years because so many attachments are blocked at the server. Spammers of late have instead sought to direct victims to malicious web links, which are tougher to filter out.

But now virus attachments are making a comeback, another return to the methods that worked in the past. (Though I think these virus attachments will have considerably less success than revisiting image spam techniques.)

All of which just goes to show: Never get complacent when it comes to PC security, because you never know what they're going to try to hit you with.

Comments on The return of "old school" spam

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 1 Posted by rogueist on Thu Jul 2, 2009 3:11PM EDT Report Abuse

    The "image spam" as you call it is just another virus infection vector. People using older, unpatched versions of Windows and Outlook will be immediately infected upon "viewing" the "images".

  • 2 Posted by scrappymichaelseese on Thu Jul 2, 2009 5:49PM EDT Report Abuse

    Well, if the 70s can come back, why not image spam? When I teach "InfoSec 101," one of the things I do is show my students how to view email as plain text in Outlook and Outlook Express. Sure, the messages are not as "pretty." But the image spam emails sure stand out. - Michael Seese, author of "Scrappy Information Security"

  • 3 Posted by alexgannis on Fri Jul 3, 2009 12:41AM EDT Report Abuse

    I agree with post #1 Outklook is way out dated with Window Mail have come and gone and now Window Live Mail is being use. With Window Outlook not being patch and soon Window XP you're going get spam and virus.

More Posts: 1

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.