Fraud report reveals danger of ‘fast-flux botnets’
RSA’s Global Fraud Report has some scary predictions for the next 12 to 18 months, as criminals become more technically savvy.

The use of sophisticated fast-flux botnets' will increase in the next year, according to a new Global Online Fraud report from RSA.
Fast-flux botnets hide the content servers delivering phishing and malware websites behind a number of compromised computers, letting addresses change very quickly to avoid detection.
"The location of the attack is constantly moving and so obviously makes it much trickier to try and get it stopped, because every time you find it it moves again," Andrew Moloney, director of marketing at RSA, told IT PRO.
The report said fast-flux networks were becoming more popular as they were easy to set up. In some cases, fraudsters rent botnets and a content server for a monthly fee.
The report noted the example of the Sinowal Trojan, which RSA discovered in October 2008. The report said the trojan had an advanced and reliable communication infrastructure, which allowed it to gather and transmit data for three years.
Moloney said: "Fundamentally what we're seeing is a commercialisation of the fraud industry at a level really greater than what we've ever seen before.
"The barrier for entry, if you're a non-technical kind of person, has been significantly lowered."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
This was seen with fraud-as-a-service', which meant that people didn't need technical expertise to infect a machine with a trojan or other type of attack, as they could simply buy what they needed.
Fraud-as-a-service was also likely to evolve in the next 12 months to support the development of the fraud economy.
"I think we'll see greater levels of sophistication and targeting under new service models," Moloney said.
"Within that fraud world there is a lot of buying and selling of information and credentials, and the better quality those credentials the better value they'll have."
The report said that enterprise fraud, which was still in its infancy' as criminals were only just starting to realise the benefits of phishing businesses, would increase to create a market for information'.
Moloney said: "If I can deliver the login credentials of the management team of a Fortune 500 company, that clearly has value."
-
HSBC says get back to the office or risk bonuses – and history shows it’s a tactic that might backfire
News HSBC is the latest in a string of financial services firms hoping to tempt workers back to the office.
-
Python’s popularity shows no signs of fading – here’s why software developers love it
News Python remains highly popular among developers for a number of key reasons, experts told ITPro.
-
RSAC Conference 2025: AI and quantum complicate security
Organizations are grappling with the complications of adopting AI for security
-
RSAC Conference 2025 was a sobering reminder of the challenges facing cybersecurity professionals
Analysis Despite widespread optimism on how AI can help those in cybersecurity, it’s clear that the threat landscape is more complex than ever
-
RSAC Conference day three: using AI to do more with less and facing new attack techniques
-
"There needs to be an order of magnitude more effort": AI security experts call for focused evaluation of frontier models and agentic systems
News Evaluating the risks of dynamic, evolving AI networks is slow work for cybersecurity analysts
-
Cyber defenders need to remember their adversaries are human, says Trellix research head
There's a growing overlap between nation-state actors and cybercriminals, but these attackers are real people who make mistakes
-
RSAC Conference day two: A focus on what attackers are doing
From quantum to AI, experts discussed how new and experimental technologies could be used by hackers to access and decrypt sensitive data
-
RSAC Conference Day One: Vibe Is 'All In' on AI for Security
News Artificial intelligence took center stage as RSAC Conference looks at how the discussion has moved from generative AI to agentic AI
-
RSAC Conference 2025 live: All the latest from day three
Live blog ITPro is covering RSAC Conference 2025 live – find out all the day-three news right here