Advertisement
Promo

Security threats Toolkit

Anti-spyware demo revealed as malware in disguise

Marcus Browne ZDNet Australia

Published: 09 Nov 2007 09:09 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A strain of malware disguised as anti-spyware has become the latest double-agent in multi-step "convergence" crime online.

The scam, which prompts users to download malware by posing as an anti-spyware demo, has proliferated dramatically. Reported incidences of its distribution have increased by 1,000 percent in the last month, according to Don Jackson, senior analyst at SecureWorks.

Jackson believes the scam is being hosted by hackers using Russian Business Network services (RBN), an illegal ISP responsible for hosting a significant amount of malicious and criminal content on the web.

The scam reportedly lures users browsing "a legitimate, high-traffic website where a legitimate-appearing ad is hosted," claims Jackson.

A spokesperson for MessageLabs said the scam is similar to any other involving adware: "These things are coming off legitimate websites with material linked back to a disreputable source," the spokesperson said.

The malicious link from the advertisement then initiates a pop-up warning to users about a false security threat and prompts them to download a demo anti-spyware package, which they can then purchase; giving hackers immediate credit card details and a delivery method for a trojan such as Zlob, said SecureWorks' Jackson.

He suggested that the benefits of these types of scams for the hacker come through the on-selling opportunities for credit card information and selling access to infected computers.

Homebrew Challenge

Homebrew challenge
Win a Toyota Prius

Tell us about your home tech project and you could win a hybrid car

Enter now+

Jackson also pointed out that while these scams present multiple benefits for hackers, they also rely on "a high degree of collaboration among a number of internet criminals for the full 'supply chain' to benefit to the greatest possible extent from the scam."

"What we're seeing a lot of is the convergence of attacks and groups of cybercriminals working closely together, there's a network of bad guys out there," said MessageLabs' spokesperson.

"Everyone's using each others technology, so the spyware guys will use spam tech to get out the spyware, which collects info for the spammers."

SecureWorks' Jackson claimed that these attacks are operating in a "grey area" of the law, as providing demos of anti-spyware software isn't regarded as a criminal offence.

Despite the threats posed by such attacks, some experts believe that these increasingly complex scams present evidence that the security industry is winning the battle against malware writers: "The fact that it sounds complicated can be taken as a sign that we're beginning to do very well," said Paul Ducklin, head of technology at security firm Sophos.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
41 out of 46 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters