With the U.S. and China representing nearly two-thirds of such threats, the top ten countries hosting web-based malware during 2006 were:
- United States — 34.2%C
- China — 31.0%
- Russian Federation — 9.5%
- Netherlands — 4.7%
- Ukraine — 3.2%
- France — 1.8%
- Taiwan — 1.7%
- Germany — 1.5%
- Hong Kong — 1.0%
- Korea — 0.9%
- Others — 10.5%
In addition to hosting the largest number of malicious websites, the U.S. continues to top the list of worst spam-relaying nations. While the U.S. has made progress in its efforts to reduce spam-relaying statistics, there was still more spam sent from U.S. computers in 2006 than any other single nation.
The top twelve spam-relaying countries during 2006 were:
- United States — 22.0%
- China (including Hong Kong) — 15.9%
- South Korea — 7.4%
- France — 5.4%
- Spain — 5.1%
- Poland — 4.5%
- Brazil — 3.5%
- Italy — 3.2%
- Germany — 3.0%
- United Kingdom — 1.9%
- Russia — 1.8%
- Taiwan — 1.8%
- Others — 24.4%
Email will continue to be an important vector for malware authors, though the increasing adoption of email gateway security is making hackers turn to other means for infection.
During 2006, Sophos saw a decline in the use of traditional spyware, in favor of multiple Trojan downloaders. The hacker sends a 'special offer' (or similar) email in an attempt to trick recipients into visiting a website containing a malicious downloader. The executable file will attempt to download additional Trojans, a process that may be repeated multiple times to try and disable all security defenses, before it downloads a spyware component - which will then have a better chance of success.
Sophos notes that 30% of all malware is now written in China, most of it taking the form of Trojans used for gaining a backdoor into users' computers. Surprisingly, 17% of malware written in China is designed for the specific purpose of stealing passwords from online gamers. In contrast, malware authors based in Brazil are responsible for 14.2% of all malware, the majority of which is designed to steal information from online bankers.
Sophos detected 41,536 new pieces of malware in 2006, bringing the total protected against to 207,684. Of these threats, Trojans now outnumber Windows viruses and worms by 4:1. The proportion of infected emails decreased from 1 in 44 during 2005 to just 1 in 337 during 2006.
