Kaspersky Lab Presents Its Extreme Malware Chart for June 2008

The small ones are getting bigger and the big ones smaller again—despite the start of summer, Kaspersky Lab’s June chart of extreme malware shows several changes. Only one long-familiar threat still refuses to be displaced.

Archive notice: This article was originally published on July 14, 2008. Links and embedded videos are preserved as part of the historical record.

  1. “Greediest banking malware”: The start of summer also brought a change at the top of this category. June’s leader seems somewhat sluggish in the summer heat, however: Trojan-Banker.Win32.Banker.ohq attacked customers of a total of 56 banks—almost 50 fewer than its predecessor.

  2. “Greediest malware targeting electronic-payment systems”: Trojan-Banker.Win32.Banker.olr targeted one more victim than the previous month’s winner. Customers of three payment systems fell within its reach in June.

  3. “Greediest malware targeting key cards”: In June, one modification of Trojan-PSW.Win32.Agent.apl won this category after attacking users of four payment-card systems.

  4. “Best-hidden malware”: June changes everything. Here too, a new leader emerged. Trojan-PSW.Win32.Delf.jj had been packed eight times using different compression programs.

  5. “Smallest malware”: Larger than its predecessors but still vanishingly tiny, June’s leader in this category was Trojan.BAT.KillFiles.hx. Despite measuring just 26 bytes, it was capable of destroying the entire contents of a hard drive.

  6. “Largest malware”: The largest threats appear to be settling at a lower average size in 2008 than last year. In June, Trojan-Banker.Win32.Bancos.mk was crowned the month’s “largest” at “only” 31 MB.

  7. “Most hostile malware”: This month’s winner comes from the same family as May’s leader. One modification of Backdoor.Win32.Agobot.gen removes numerous security products, including antivirus software, from the infected PC’s memory and hard drive.

  8. “Most widespread malware in email traffic”: “Never change a running system”—this month, as in previous months, Email-Worm.Win32.Netsky.q again won this category, accounting for 34.15 percent of malicious traffic.

  9. “Most widespread Trojan family”: There was a change among Trojan families, however: the Trojan-GameThief.Win32.OnlineGames family displaced the previous month’s leader, and with good reason. No fewer than 3,295 modifications of this malware were identified.

  10. “Most widespread virus and worm family”: In the first month of summer, the worm family with the most members was Worm.Win32.Autorun. With 152 previously unseen modifications, however, the family delivered a relatively modest showing.