At the end of last week our internal statistics showed a strong spike in description requests for several long detected spyware applications. We wondered about the cause. Their activity had been flat for some time. Something new was installing them, but what? We needed a bit more information.
You can see from the images below that the spike drops after the 22nd. Detection for Licat.C was added at that time. The detection of the IM worm (installer) then caused the spyware to fall back to its normal levels.
It seems that we may now have a new forecasting tool.