Rogue anti-malware, also known as rogue AV, has become the delivery vehicle of choice for the cybercriminals seeking to infect endpoints with their payloads. Those endpoints consist of both the consumer and enterprise. The ESET Global Threat Trends Report for April 2010 contains a short article called “Free but Fake.” Better yet, one of our most active researchers, Cristian Borghello from our Latin American office, wrote an excellent paper on rogue anti-malware.
If you haven't had a chance to view the convincingly crafted fake scans from our various rogue AV pages, here's one that I took off of one of my testing workstations prior to the infection. The first stage requires the user to take a particular action. In this case – and many others – it can't infect the system without human assistance.
According to a recent paper on large-scale exploits and emergent threats that Google released in late April at the Usenix Workshop, rogue AV accounts for more than 15 percent of all malware Google detects. In the report, Google outlines that from January 2009 until February 2010, more than 11,000 domains were involved in rogue AV distribution.
I have also had recent discussions with colleagues over fake/rogue anti-malware that didn't break the law by infecting endpoints. This isn't actually fake security software, just highly substandard with disproportionately strong messaging.
This aligns strongly with an article from Bruce Schneier that I recall reading entitled “A Security Market For Lemons” (Wired, April 2007). In his article Bruce states:
““Of course, it's more expensive to make an actually secure USB drive. Good security design takes time, and necessarily means limiting functionality. Good security testing takes even more time, especially if the product is any good. This means the less-secure product will be cheaper, sooner to market and have more features. In this market, the more-secure USB drive is going to lose out.”
Bruce closes the article with:
““With so many mediocre security products on the market, and the difficulty of coming up with a strong quality signal, vendors don't have strong incentives to invest in developing good products. And the vendors that do tend to die a quiet and lonely death.”
I agree that a new tactic that's not illegal, such as a deluge of confusing messages and products (more than our customers currently experience), has the potential to impact the revenue of legitimate companies and leads the end-user into having a false sense of security with a highly inert product.
So what do we do about blatantly rogue anti-malware? Below are four points to consider:
■The executable itself shouldn't be allowed to touch or run on the endpoint. While possible, this is easier said than done due to the myriad permutations of endpoint configurations.
■Rogue software, like other malware, may be detectable via behavioral analysis. Implement a highly regarded anti-malware product with excellent static and/or dynamic detection (i.e., positive user feedback and presale dialog – not marketing hype)
■The distribution of the executable is dependent on very convincing JavaScript and associated graphics. Filtering for these, while tedious, can yield big payoffs.
■If the rogue executable is discovered, send it to the security response team for your anti-malware product. This allows them to add static detection and update their dynamic detection algorithms.
Attacks are cyclical, so once there is a much more effective means for dealing with rogue AV, you can rest assured there will soon be another angle leveraged to gain a foothold in the endpoint. In the meantime, it's an arms race and there are a lot of security vendors working hard to meet the escalating threats head-on. As a security community, keeping the lines of communication open and flowing to share threat intelligence is one of our greatest strengths in this protracted fight.
Showing posts with label rogue antivirus. Show all posts
Showing posts with label rogue antivirus. Show all posts
Sunday, August 8, 2010
Wednesday, December 16, 2009
Rogue Antivirus Lurks Behind Google Doodle Searches
In Esperanto the word is "malica." It means malicious and it's the best way of describing many of the search results Google visitors got Tuesday when the clicked on Google's front-page Doodle sketch, dedicated to Esperanto's creator.
It's the latest example of just how good scammers have become at manipulating Google search results. For months now, they've followed Google's Trending Topics section and then used search engine optimization techniques to push hacked Web pages up to the top of Google's search results, security experts say.
They do this by flooding hacked pages with keywords that are then recorded by Google's search engine.
Hackers have several ways of getting their code on legitimate Web sites -- lately they've focused on stealing FTP login credentials, according to Dave Michmerhuizen, a research scientist with Barracuda Labs.
The hacked sites that pop up when one clicks on Tuesday's Google Doodle include a hair salon in New Jersey, an Texas tree company, and a science fiction group.
On Tuesday, clicking on the illustration on Google's front page commemorating the 150th anniversary of the birth of Esperanto's creator L. L. Zamenhof, generated an awful lot of malicious search results -- taking visitors to dodgy advertisements or pages that tried to trick visitors into thinking their computers were infected and paying for fake antivirus software. pcworld
It's the latest example of just how good scammers have become at manipulating Google search results. For months now, they've followed Google's Trending Topics section and then used search engine optimization techniques to push hacked Web pages up to the top of Google's search results, security experts say.
They do this by flooding hacked pages with keywords that are then recorded by Google's search engine.
Hackers have several ways of getting their code on legitimate Web sites -- lately they've focused on stealing FTP login credentials, according to Dave Michmerhuizen, a research scientist with Barracuda Labs.
The hacked sites that pop up when one clicks on Tuesday's Google Doodle include a hair salon in New Jersey, an Texas tree company, and a science fiction group.
On Tuesday, clicking on the illustration on Google's front page commemorating the 150th anniversary of the birth of Esperanto's creator L. L. Zamenhof, generated an awful lot of malicious search results -- taking visitors to dodgy advertisements or pages that tried to trick visitors into thinking their computers were infected and paying for fake antivirus software. pcworld
Saturday, October 24, 2009
Trend Micro CEO: Hackers Hitting AV Infrastructure
It's become an all-too-common scam: A legitimate Web site pops up a window that looks just like a real security warning. It says there's something wrong with the computer, and click here to fix it. A few clicks later, the victim is paying out US$40 for some bogus software, called rogue antivirus.
Rogue AV scams have become a big problem in recent months, but according to Trend Micro CEO Eva Chen, it's part of a more sinister, strategic attack on the antivirus industry in general. Criminals "can fake any other application. Why do they fake AV?" she asks.
According to her, a lot of today's security problems are designed not only to steal information from victims, but to undermine the credibility of companies like Trend Micro itself.
One way hackers have done this is by changing the way their software is put together each time they attack, forcing the AV vendors to bloat up their products with hundreds of thousands of new detection signatures.
In response, Trend was one of the first companies to push reputation-based technology into its antivirus products, developing its Smart Protection Network to identify and block not just viruses themselves, but also the malicious Web sites that are used to distribute malware.
PC World
Rogue AV scams have become a big problem in recent months, but according to Trend Micro CEO Eva Chen, it's part of a more sinister, strategic attack on the antivirus industry in general. Criminals "can fake any other application. Why do they fake AV?" she asks.
According to her, a lot of today's security problems are designed not only to steal information from victims, but to undermine the credibility of companies like Trend Micro itself.
One way hackers have done this is by changing the way their software is put together each time they attack, forcing the AV vendors to bloat up their products with hundreds of thousands of new detection signatures.
In response, Trend was one of the first companies to push reputation-based technology into its antivirus products, developing its Smart Protection Network to identify and block not just viruses themselves, but also the malicious Web sites that are used to distribute malware.
PC World
Friday, October 16, 2009
A Rogue Demands A Ransom
One strain of the rogue AV, currently called Total Security 2009, will now block access to anything on your PC until you pay for a serial number for the rogue program. Attempts to open anything will instead pop-up a message claiming that the file is infected, and that you should "activate your antivirus software." Paying $79.95 for a serial number and "activating" the program allows you to use your PC once more, according to a post from antivirus maker Panda Security, but doesn't get rid of the scamming software.
Why Small Companies Should Think Outside Box for Protecting Endpoints: Download nowRansomware that holds files hostage has been around for years, but it has been a relatively small niche in the online black market. But where previous extortion attempts were obvious, even clumsy, this new twist uses yet another layer of social engineering to disguise the ransom demand as a supposed safety measure.
If you or someone you know is unlucky enough to fall victim to this rogue, Panda has posted a batch of serial numbers that will activate the fake app and unlock your files (next step would be to run all the real AV scans you can). However, scammers constantly change their rogue apps in an attempt to stay ahead of the real security software, so these numbers may not remain useful for long. Panda also has a demonstration video in its post.
PC World
Thursday, October 1, 2009
Phishing websites, rogue antivirus skyrocket in 2009
The number of unique phishing websites reached a high of nearly 50,000 in June, the second highest on record since more than 55,000 phishing websites were recorded in April, 2007. Meanwhile, the number of people downloading and installing rogue antivirus programs is also on the rise, providing a cash cow to cybercriminal gangs. In the first quarter of 2009 alone, more new strains of rouge antivirus were created than in all of 2008, according to the APWG Phishing Trends Report.
The organization, an industry association of security vendors, individual businesses and business trade associations, started in 2003 and has monitored phishing and email spoofing with the goal of finding ways to reduce and ultimately eliminate the problem. The report includes data collected by security vendors Websense Inc. and Panda Security, as well as brand jacking information from Mark Monitor Inc.
Rogueware, phishing:
Panda reports fast-spreading rogueware antivirus fraud rakes in millions: Rogueware fake antivirus strains are increasing at a stunning rate. Panda Security reports that this cyber crime bilks users out of about $34 million every month.
Can mutual authentication beat phishing or man-in-the-middle attacks? What's the best way to prevent phishing and man-in-the-middle attacks? IAM expert David Griffeth explains the benefits of mutual authentication over one-way SSL.
Phishing, identity theft keeps law enforcement, researchers occupied: An expert on cybercrime and online scams, Derek Manky, is one of the members of the Fortiguard research team
Rogue antivirus displays fake pop-up warnings and launches messages in the task bar warning of a possible infection. Once downloaded, the program typically conducts a fake scan of a victim's system and then provides results showing fake infections.
In June, the number variants of rogue antivirus programs increased above 152,000, according to the APWG. The number of rogue antivirus variants detected was four times as many samples as in all of 2008.
Luis Corrons, technical director of PandaLabs, the research arm of Panda Security, said the lucrative business model has attracted new cybercriminal gangs that are helping fuel the increase in rogue antivirus. Panda estimates that victims are shelling out $34 million per month worldwide for rogue antivirus programs. There are currently more than 200 different gangs being tracked by researchers. Ten gangs are responsible for more than 77% of the rogue antivirus samples, he said.
"Unlike with banking Trojans, where you have to infect the user, steal the data, then hire some money mule with rogueware they only have to wait for users to pay," Corrons said. "The user is the one willing to pay in order to disinfect their computer." SearchSecurity radio:
According to security experts, the rogueware has been spreading by less sophisticated means. They rely on rouge antivirus-touting website visitors to download and install the program. But phishers have been successful in avoiding detection by legitimate antivirus programs, according to the APWG report. Each downloaded rogue antivirus program contains a slightly different binary file, which tricks signature-based antivirus. In addition, Corrons said the programs themselves don't act maliciously on computers, other than displaying false information, which helps them evade detection from antivirus engines.
Search Security
Props to my buddy Eric Cissorsky on this one too!
Subscribe to:
Posts (Atom)




