Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Anti-spyware demo revealed as malware in disguise

Marcus Browne ZDNet Australia

Published: 09 Nov 2007 09:09 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A strain of malware disguised as anti-spyware has become the latest double-agent in multi-step "convergence" crime online.

The scam, which prompts users to download malware by posing as an anti-spyware demo, has proliferated dramatically. Reported incidences of its distribution have increased by 1,000 percent in the last month, according to Don Jackson, senior analyst at SecureWorks.

Jackson believes the scam is being hosted by hackers using Russian Business Network services (RBN), an illegal ISP responsible for hosting a significant amount of malicious and criminal content on the web.

The scam reportedly lures users browsing "a legitimate, high-traffic website where a legitimate-appearing ad is hosted," claims Jackson.

A spokesperson for MessageLabs said the scam is similar to any other involving adware: "These things are coming off legitimate websites with material linked back to a disreputable source," the spokesperson said.

The malicious link from the advertisement then initiates a pop-up warning to users about a false security threat and prompts them to download a demo anti-spyware package, which they can then purchase; giving hackers immediate credit card details and a delivery method for a trojan such as Zlob, said SecureWorks' Jackson.

He suggested that the benefits of these types of scams for the hacker come through the on-selling opportunities for credit card information and selling access to infected computers.

Homebrew Challenge

Homebrew challenge
Win a Toyota Prius

Tell us about your home tech project and you could win a hybrid car

Enter now+

Jackson also pointed out that while these scams present multiple benefits for hackers, they also rely on "a high degree of collaboration among a number of internet criminals for the full 'supply chain' to benefit to the greatest possible extent from the scam."

"What we're seeing a lot of is the convergence of attacks and groups of cybercriminals working closely together, there's a network of bad guys out there," said MessageLabs' spokesperson.

"Everyone's using each others technology, so the spyware guys will use spam tech to get out the spyware, which collects info for the spammers."

SecureWorks' Jackson claimed that these attacks are operating in a "grey area" of the law, as providing demos of anti-spyware software isn't regarded as a criminal offence.

Despite the threats posed by such attacks, some experts believe that these increasingly complex scams present evidence that the security industry is winning the battle against malware writers: "The fact that it sounds complicated can be taken as a sign that we're beginning to do very well," said Paul Ducklin, head of technology at security firm Sophos.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
41 out of 46 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment

Nokia Siemens denies Iran web snoop

Nokia Siemens has denied providing deep packet inspection capabilities to the Iranian authorities, following an article in the Wall Street Journal on Monday. The WSJ published the... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters