Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

SecureWorks: Anti-spyware solution scam steals personal financial information

  • Email a Friend
  • Print Page
SecureWorks: Anti-spyware solution scam steals personal financial information
By Jim Carr
Nov 8, 2007 10:12 AM
Tags: SecureWorks: | Anti-spyware | solution | scam | steals | personal | financial | information
Hackers in Russia and other Eastern European countries are using the Russian Business Network (RBN) internet service provider (ISP) and other hosting outlets to lure victims into clicking on malicious ads on high-traffic websites, the Atlanta-based company reported this week.

Clicking on a malicious advertisement opens a pop-up warning about a suspicious problem on the victim's computer, initiating a "sales process" for a bogus anti-spyware solution that costs US$19.95 to US$79.95. The rogue websites collect credit card numbers, names and other personal information in the process, according to the SecureWorks.

Finally, the "anti-spyware solution" downloads a trojan, such as Zlob, which retrieves other personal information from the victim's PC over time, or a rootkit, which gives the attacker remote control of the victim's computer.

The names of the bogus anti-spyware found in this offer include Spy-shredder, AntiVirGear, MalwareAlarm and about 40 others.

The scammers make money not only from the sale of the "solution," but also from the sale of credit card numbers and access to the trojan- and rootkit-infected computers.

According to SecureWorks, the scam thrives on collaboration among a number of internet criminals who randomly inject the ads with the malicious code, making it difficult for the website owner to predict which ads are malicious, Jon Ramsey, SecureWorks chief technology officer, told SCMagazineUS.com.

"This type of scam will be around for a while because it's showing success,” he said.

The RBN has been blamed for a number of high-profile cyberattacks in the past year, including the hijacking of the Bank of India's website in late August and June's “Italian Job” trojan attack.

Avivah Litan, vice president and distinguished analyst at Gartner, told SCMagazineUS.com on Tuesday that scammers “are getting more clever day by day in their ability to plant trojans on user PCs and avoid security programs put in place by enterprises and financial institutions.”

"In this case, the crooks are linking their malware to legitimate advertising services -- an increasingly popular tactic -- and tricking consumers into downloading a malicious program on their PC,” she said.

“The crooks are then able to use the user's PC to launch more attacks or intercept user communications between the consumer and financial services and e-commerce websites. Then they are able to steal credentials, bank account, debit card account data and other sensitive personal information."

Litan added that most of the security measures deployed by banks, brokerages and e-commerce sites will not stop fraud perpetrated by these techniques.

"It's only a matter of time before websites servicing users will need to beef up their security measures, using, for example, out-of-band user authentication and transaction-verification techniques," she said.

"Consumers also will have to start using stronger desktop security products that warn them, for example, when they are about to visit a spoof site or download a trojan."

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Breaches & Exposures Whitepapers