ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Anti-spyware demo revealed as malware in disguise

Marcus Browne ZDNet Australia

Published: 09 Nov 2007 09:09 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A strain of malware disguised as anti-spyware has become the latest double-agent in multi-step "convergence" crime online.

The scam, which prompts users to download malware by posing as an anti-spyware demo, has proliferated dramatically. Reported incidences of its distribution have increased by 1,000 percent in the last month, according to Don Jackson, senior analyst at SecureWorks.

Jackson believes the scam is being hosted by hackers using Russian Business Network services (RBN), an illegal ISP responsible for hosting a significant amount of malicious and criminal content on the web.

The scam reportedly lures users browsing "a legitimate, high-traffic website where a legitimate-appearing ad is hosted," claims Jackson.

A spokesperson for MessageLabs said the scam is similar to any other involving adware: "These things are coming off legitimate websites with material linked back to a disreputable source," the spokesperson said.

The malicious link from the advertisement then initiates a pop-up warning to users about a false security threat and prompts them to download a demo anti-spyware package, which they can then purchase; giving hackers immediate credit card details and a delivery method for a trojan such as Zlob, said SecureWorks' Jackson.

He suggested that the benefits of these types of scams for the hacker come through the on-selling opportunities for credit card information and selling access to infected computers.

Homebrew Challenge

Homebrew challenge
Win a Toyota Prius

Tell us about your home tech project and you could win a hybrid car

Enter now+

Jackson also pointed out that while these scams present multiple benefits for hackers, they also rely on "a high degree of collaboration among a number of internet criminals for the full 'supply chain' to benefit to the greatest possible extent from the scam."

"What we're seeing a lot of is the convergence of attacks and groups of cybercriminals working closely together, there's a network of bad guys out there," said MessageLabs' spokesperson.

"Everyone's using each others technology, so the spyware guys will use spam tech to get out the spyware, which collects info for the spammers."

SecureWorks' Jackson claimed that these attacks are operating in a "grey area" of the law, as providing demos of anti-spyware software isn't regarded as a criminal offence.

Despite the threats posed by such attacks, some experts believe that these increasingly complex scams present evidence that the security industry is winning the battle against malware writers: "The fact that it sounds complicated can be taken as a sign that we're beginning to do very well," said Paul Ducklin, head of technology at security firm Sophos.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
41 out of 46 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Credit Analyst Immediately req (SAS Base/SAS Macros)London

Credit Analyst Immediately req (SAS Base/SAS Macros)London Do you have experience of SAS working in a credit risk environment? My client is a leading ...

Business Analyst - Credit Risk MI Reporting - London £500pd

Our Client, a tier 1 Investment Bank based in the City of London, is currently looking for a strong Business Analyst with Credit Risk MI Reporting ...

Credit Risk JAVA Specialist

My Tier one Investment house, requires a Lead JAVA Developer to join the Credit Risk Technology division. Credit Risk system. Credit Risk or Market ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment