::Trend Micro Threat Resource Center::
23 November 2010
Korean cross-border attacks exploited to spread malware
Scareware and malware pushers have been very prompt at poisoning related search results.
Search combinations such as "north korea bombs/attacks south korea", "kim jong il", "korean war", "world war 3", "yeonpyeong island" and "korean news" have been producing results that take users to pages where warnings about infection on their computers are shown and the users are offered to download rogue antivirus solutions, to pages that attempt to hijack their browser through JavaScript or pages that offer Trojans disguised as codecs and bogus updates for Mozilla's Firefox.
The Tech Herald reports that all of the offending compromised domains are using open source CMS software which was not updated and, consequently, vulnerable to attack. They also noted that topics related to Black Friday, Bristol Palin, Dancing with the Stars, and others have been targeted by the same black hat SEO campaign.
29 October 2010
Increase in Halloween malware attacks
Furthermore, three of the top 10 threat detections from last year’s Halloween season are still on the list, highlighting the lasting impact of this type of malware long after the holiday is over.
Consumers should be on the lookout for new iterations of the following common types of attack:
- Halloween Tweets, “likes” and posts on various social media sites that can be used to lure users to malicious websites.
- Search engine optimization (SEO) poisoning, in which links to malicious Web sites show up in search engine results for holiday items.
- Halloween-themed attachments posing as invitations, greeting cards or documents. Clicking on these creates a significant risk of downloading rogue security products or other malware.
- “Typo attacks” which take advantage of the increased Holiday traffic to commonly misspelled URLs. Malware writers set up spoofed infected sites and download locations to trap unsuspecting web users who misspell URLs and end up in the wrong place.
- Sites that offer contests attempting to get visitors to subscribe to questionable subscription services that are billed to their cell phone monthly.
26 May 2010
BitDefender impersonated by rogue antivirus
Unlike average rogue AV products, the ByteDefender sibling does not rely on the classic drive-by method used by most products of its kind, but rather piggybacks on the popularity of the BitDefender products and their distinct visual identity to lure users into voluntarily downloading it.
The website distributing it is located at hxxp://www.bytedefender.in (URL specifically invalidated to avoid accidental infection) and abusively built using the BitDefender layout. The domain name has been registered in Ukraine. Even the boxshots have been crafted in such a manner to trick the user into thinking that they are installing the genuine security product.
The infection scenario is simple, yet efficient: the user looking for a BitDefender product may typo-squat the genuine address and gets redirected to the malicious webpage. Because of the similar webpage structure, the user may download and install the rogue AV.
Read here for a more detailed report with screenshots.
11 March 2010
Most costly security scam of 2010 - Scareware
Wonder what is scareware? Here's what it is and how they look like.
Fake antivirus programs that encourage web users to part with their hard-earned cash and download hoax security software is likely to be the most costly scam of 2010, says McAfee.
According to the security firm, cybercriminals make upwards of $300m from conning web users worldwide into downloading scareware.
The security firm also said it had seen a 660 percent rise in scareware over the past two years, and a 400 percent increase in reported incidents in the last 12 months.
"Even the savviest of computer users fall victim to online threats because cybercriminals have become so sophisticated," said Jeff Green, senior vice president of McAfee Labs.
The scareware scam starts with a pop-up that claims the web user's PC is infected with malware and then prompts the user to purchase the fake 'security software' which is actually malware in disguise. Cybercriminals also obtain the user's computer and bank details.
"It's an incredibly lucrative business for cybercriminals," added Francois Paget from McAfee Labs.
With this in mind, McAfee has launched the Consumer Threat Alerts program that is designed to warn web users about the latest and most dangerous online threats
McAfee said subscribers can expect to receive periodic email alerts about how to recognise the latest online dangers and tips on how to stay safe.
"We're giving consumers the 'street smarts' they need to live their online lives safely," said Green.
"With education and the right technology, we can all play a part in the fight against cybercrime."