Comprehensive Protection: Secure your business from known and unknown threats.
Symantec.com > Business > Security Response

Security Response

Our security research centers around the world provide unparalleled analysis of and protection from IT security threats that include malware, security risks, vulnerabilities, and spam.
Help us improve this website: Take our Security Response User Experience Survey.
90 Day Global Threats, Risks, and Vulnerabilities Timeline
90 Day Global Threats, Risks, and Vulnerabilities Timeline
90 day view of discovered Threats, Security Risks and announced Vulnerabilities brought to you by the DeepSight Threat Management System
RiskThreatVulnerability
Most Active New Threats
Most Active New Threats
Newly discovered threats that Symantec has blocked from customer machines.
Subscribe
NameTypeProtected*Discovered
Infostealer.Shiz!genTrojan09/02/201209/02/2012
W32.Pilleuz!gen31Worm07/02/201208/02/2012
Backdoor.Cycbot!gen10Trojan08/02/201208/02/2012
Trojan.Zbot!gen30Trojan Virus07/02/201206/02/2012
Infostealer.OffsuploadTrojan07/02/201206/02/2012
W32.BegmianWorm07/02/201205/02/2012
Android.BmasterTrojan03/02/201203/02/2012
Trojan.Zeroaccess!gen8Trojan02/02/201202/02/2012
W32.Pilleuz!gen30Worm01/02/201201/02/2012
Trojan.Zatvex!gen4Trojan01/02/201201/02/2012
*For continued protection, make sure that your Symantec subscription and/or license are up to date.
Threat Spotlight: Trojan.Downbot

Trojan.Downbot is a Trojan that is implicated in a widely reported series of targeted information stealing attacks against a wide range of organizations worldwide.
These attacks were initially reported in the media on August 2nd, 2011 when a report was published naming the attack as "Operation Shady RAT". The report described a series of attacks which had been occurring for over five years against over seventy organizations.

The targets ranged from private companies to government agencies located worldwide. In the report, it speculated that these attacks were aimed at stealing highly sensitive and proprietary information belonging to specifically targeted organizations and due to this, may potentially point to a state sponsor being behind these attacks.

More information on Trojan.Downbot is available in the threat family writeup.

Best Practices
IT Security Threats With the rapid rise in the number of malware attacks it’s harder than ever to prevent machines from getting infected. But have you done everything you can do? Have you done the things you must do to stay protected? Following some simple best practices can make a tremendous difference in improving your protection. Symantec has assembled a set of best practices for today’s threat landscape.

Use these recommendations to know what you must, should and can do to protect your endpoints from malware.

Want to go further and really beef up protection on your endpoint machines? Symantec Endpoint Protection has a feature called Application and Device Control that gives you additional tools to protect your endpoints. Find out about Application and Device Control and download rulesets especially created by Symantec to increase your protection. Information available here.
White Paper Spotlight
W32.Qakbot is a worm that has been seen spreading through network shares, removable drives, and infected webpages, and infecting computers since mid-2009. Its primary purpose is to steal online banking account information from compromised computers. The malware controllers use the stolen information to access client accounts within various financial service websites with the intent of moving currency to accounts from which they can withdraw funds. There are several information stealing Trojans found in cyberspace today. What makes Qakbot stand apart from most of the others is sophistication and continuous evolution. The purpose of this white paper is to provide an insight into the worm's capabilities.

Download the full 'W32.Qakbot in Detail' white paper.

View the full set of Symantec Security Response white papers.


Stay Secure



Be Informed about IT Threats



Contact Security Response

ThreatCon

Level 1: Normal

Level 1: Normal

Learn more about threat levels

Threat Intelligence

Subscribe
Revamped Fake #Android Market for SMS Fraud  http://t.co/mlrosRUH #malware
Friday
Is Waledac spam dirtying the Russian 2012 elections?  http://t.co/6gWaIyq6
Friday
Trojan.Activehijack found in the wild using a known #Office #vulnerability.  http://t.co/7L8Xszwr
02-09-2012 12:22 PM
Infostealer.Offsupload uploads 20000+ archives of stolen data to file sharing site  http://t.co/5BBG51Go #Trojan
02-09-2012 1:47 AM
#Android.Bmaster - Botmaster's profits exposed  http://t.co/P8jOQP37 #malware
02-08-2012 9:29 PM
 
STAR Antimalware Protection Technologies
The Stuxnet Worm
Prevent Information Loss and Theft: Let Symantec help protect your business.  Shop Now