Table of Contents
Information Security1
Internet1
Information Security Tools and Processes2
| Application security | 2 |
| Cloud security | 3 |
| Cryptography | 4 |
| Infrastructure security | 4 |
| Incident response | 4 |
| Vulnerability management | 5 |
Security Concepts5
| Confidentiality | 5 |
| Integrity | 6 |
| Availability | 6 |
People Accessing Information6
| Authentication | 7 |
| Authorization | 7 |
| Nonrepudiation | 8 |
Malware Definition9
| Viruses and Worms | 10 |
| Virus | 10 |
| Worm | 10 |
| Trojans | 11 |
| Backdoor / Remote Access Trojan (RAT) | 11 |
| Botnets | 12 |
| Adware | 15 |
| Information stealers | 15 |
| Ransomware | 15 |
| Rootkits | 16 |
| Downloaders or droppers | 16 |
| File Wipers | 17 |
| Spyware | 17 |
| Malware Summary | 18 |
Phishing18
| Spear Phishing | 20 |
| Clone Phishing | 21 |
| Whale Phishing | 21 |
| Social Media Phishing | 21 |
| Phishing Evolution | 21 |
| Phishing Opportunities | 22 |
| Criminals are Learning and Evolving | 22 |
Phishing Tools23
| Bots/Botnets | 23 |
| Phishing Kits | 23 |
| URL Obfuscation | 23 |
| Simple HTML redirection | 24 |
| Use of JPEG images | 24 |
| Use of alternate IP addresses | 24 |
| Registration of similar domain names | 25 |
| Web Browser Vulnerabilities used for Phishing | 25 |
| Session Hijacking | 25 |
| Domain Name Resolving Attacks | 26 |
| Global DNS Hijacking Campaign | 27 |
| Cross-Site Scripting Attacks | 27 |
| Domain Name Typos | 28 |
| Man-in-the-Middle Attacks | 28 |
| Phishing | 28 |
| Bancos | 28 |
| Bankash | 28 |
| W32/Grams | 29 |
| CoreFloo | 29 |
| Dyre Banking Malware | 29 |
Phishing Mitigations30
Phishing Solutions30
Prevent Phishing Attacks30
Identity Theft32
| Identity Theft Methods | 32 |
| Trash Sifting/Dumpster Diving | 32 |
| Mail Theft | 33 |
| Address Manipulation: | 34 |
| Skimming | 34 |
| Scanning | 35 |
| Straightforward Theft: | 36 |
| Conning | 36 |
| Identity Theft Crimes | 36 |
| Yahoo Data Breach | 36 |
| Equifax breach | 37 |
| Target Data Breach | 37 |
Malware Trends38
| 2014 Malware Trends | 38 |
| Increases in Researcher Evasion | 38 |
| Malware Source Code Leaks | 39 |
| Changes in Account Takeover Fraud Execution | 40 |
| Mobile SMS Malware Rose in Popularity | 41 |
| Obsolete Malware Infection Techniques Started Making a Comeback | 41 |
| 2015 Malware Trends | 43 |
| Mobile Banking Trojans on the Rise | 43 |
| Overlay of Malware on Top of Legitimate Applications | 43 |
| Increases in Mobile Ransomware | 45 |
| First Ransomware for Linux Detected | 45 |
| Encryption-Based Ransomware is on the Rise | 46 |
| 2016 Malware Trends | 47 |
| Ransomware Solidified Itself as a Serious Threat | 47 |
| Underground Cybercriminal Marketplaces are Becoming More Common | 49 |
| $100 Million was Stolen from Banks in SWIFT-Enabled Transfers | 49 |
| BlackEnergy Wreaked Havok on Vulnerable Critical Ukrainian Infrastructure | 50 |
| Mirai Botnet Attack Shows the Vulnerability of Internet of Things (IoT) Devices | 50 |
| Mobile Adware Infections Increase Dramatically | 51 |
| 2017 Malware Trends | 52 |
| Despite the Plateauing of new Ransomware Families, WannaCry and NotPetya take the Ransomware Landscape by storm | 52 |
| Mobile "Evasive" Malware is Extremely Popular and More Dangerous Than It's Ever Been | 54 |
| Losses from Business Email Compromise and CEO Fraud Reach $5 Billion | 55 |
| 2018 Malware Trends | 55 |
| Botnets Are Now Used to Attack Both Organizations and Users of Infected Computers | 56 |
| As Rooted Mobile Malware Declines in Popularity, Traditional Malware Infection Rates Surge | 57 |
| With the Rising Value of Cryptocurrency, Mining Malware is Rising in Popularity | 58 |
| 2019 Malware Trends | 60 |
| WannaCry Ransomware | 60 |
| Kovter Click Fraud Malware | 62 |
| Gh0st RAT | 63 |
| NanoCore RAT | 64 |
| CoinMiner Cryptocurrency Mining Malware | 66 |
| ZeuS Modular Banking Malware | 67 |
| Emotet Infostealer | 68 |
| Trickbot Banking Trojan | 71 |
| Qakbot Financial Malware | 73 |
| Dridex Banking Trojan | 75 |
Common Malware Threats of 202077
| KMS | 78 |
| Dridex Banking Trojan | 78 |
| Tech Support Scams | 79 |
| Glupteba Trojan | 79 |
| Infostealers | 80 |
| Important Mentions: Trickbot and Emotet Infostealer | 80 |
Important Malware Trends of 202181
| Ransomware Attacks Will Continue to Increase in Both Number and Sophistication in 2021 | 81 |
| Cybercriminals and Threat Actors will Continue to Exploit the COVID-19 Pandemic | 82 |
| Non-Windows Malware Attacks are Increasing | 82 |
| Vulnerabilities that Enable Malware will Likely Increase in 2021 | 83 |
Important Malware Trends of 202283
| Healthcare Sector Cyberattacks are on the Rise | 84 |
| Ransomware Attacks are Becoming more Sophisticated and Vicious | 84 |
| Security-as-a-Service and Zero Trust Networks is on the Rise | 85 |
Important Malware Trends of 202386
| Ransomware Attacks Continue to Grow, but Switch Focus to Supply Chain Companies | 86 |
| Ransomware-as-a-Service Increases in Popularity | 87 |
| Zero Trust Security Systems See Wider Implementation, but still aren't Perfect | 87 |
Important Malware Trends of 202488
| AI is at the forefront of the Cybersecurity Landscape in 2024 | 88 |
| The Evolution of Malware using AI – Polymorphic and Metamorphic Malware | 89 |
| The Rise of Loaders, Stealers, and RATs | 90 |
| IoT Devices Continue to be a Priority Target for Cybercriminals | 91 |
Glossary93
Course Details
Author: Andrew Clark, EA
Publication/Revision Date: 9/12/2025
Course Exam Questions (online): 30 (multiple-choice)
Program Delivery Method: Self-Study (NASBA QAS Self-Study)
Available Formats of Course Text: PDF or PDF plus printed copy sent in the mail
Course Level, Prerequisites, and Advance Preparation Requirements
| License | Course Level | Prerequisites | Advance Preparation Requirements |
|---|
| CPA | Intermediate | None | None |
| EA/OTRP | Intermediate | None | None |
Sponsor ID Numbers
National Registry of CPE Sponsors ID: 107615
IRS Qualified Sponsor ID: FWWKO — Course ID: FWKK0-T-00795-26-S
State CPA Board Sponsor ID Numbers (where applicable)
Florida Division of Certified Public Accounting: 0004761
Hawaii Board of Public Accountancy: 14003
New York State Board for Public Accountancy: 002146
Ohio Accountancy Board: CPE .51 PSR
Pennsylvania State Board of Accountancy: PX178025
Texas State Board of Public Accountancy: 009349
Learning Objectives
As a result of studying the course material, you should be able to meet the objectives listed below:
- Identify the importance of information security for CPAs and Tax Practitioners,
- Identify the different types of malware that can infect computer systems,
- Define the term “Phishing” and recognize how phishing occurs,
- Define the term “Identify Theft” and recognize how identify theft most commonly occurs,
- Identify the major malware events that have occurred in recent years, and
- Identify the operating processes and mitigation techniques for the most commonly seen malware programs of the current year.