Showing posts with label scareware. Show all posts
Showing posts with label scareware. Show all posts

Thursday, October 22, 2009

Caution! Rise in Scareware Tactics - Rough Security software

Rogue security software, also dubbed scareware, is an "ongoing threat" that is impacting largely users from English-speaking markets, according to findings from a year-long study by Symantec.

Released Tuesday, Symantec's report on rogue security software noted that 250 rogue security programs launched some 43 million attempts to prompt user installation between July 2008 and June 2009.

Read also: Fake 'Conflicker.B Infection Alert' spam campaign drops scareware

Further analysis on the top 50 most reported scareware was carried out between July and August this year, during which Symantec found that 38 of the programs had been detected prior to Jul. 1, 2008.

"The continued prevalence of these programs emphasizes the ongoing threat they pose to potential victims, despite efforts to shut them down and raise public awareness," the security vendor said in the report.

The five most commonly reported rogue security applications during the study were SpywareGuard 2008, AntiVirus 2008, AntiVirus 2009, Spyware Secure and XP AntiVirus.

For more info read ZDNet Asia Security Blog.........

Fake Conficker.B Infection Alerts Impersonate Microsoft

An ongoing spam campaign is once again attempting to impersonate Microsoft’s security team — the same campaign was first seen in April — by mass mailing Conficker.B Infection Alerts (install.zip), which upon execution drop a sample of the Antivirus Pro 2010 scareware.

Whereas the theme remains the same, the botnet masters have slightly modified the message:

“Dear Microsoft Customer,

Starting 18/10/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected. To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division”
The use of email as propagation vector for scareware campaigns (The ultimate guide to scareware protection), and in particular the use of email attachments is an uncommon practice, compared to the single most effective way of hijacking traffic through blackhat search engine optimization where the cybercriminals rely on real-time news events.

The campaign is an example of a — thankfully - badly executed one in the sense that with Microsoft’s Security Essentials recently gained momentum, even the average Internet user would notice the suspicious timing of the offered “antispyware program”.

Thursday, April 9, 2009

Microsoft Security Intelligence Report - Extracts

Here’s a look at the five most important aspects from the full Microsoft Security Intelligence Report.

1. Vulnerabilities (the response and reaction to them) vary, depending on whether the target is at work or home.

Based on data provided by its enterprise Forefront Client Security and consumer Windows Live OneCare, Microsoft found that vulnerabilities are very different. Why? A corporate user may have email and Internet limitations that reduce the attack surface. A home user has more software tools to be infected but less critical data at risk.

Simply put, a home user is more likely to get hit with a Trojan attack to extract bank and credit card details, etc. In the enterprise, the weapon of choice is the Worm attack, which is primarily destructive and disruptive.

The greatest difference between enterprise and home vulnerabilities is social engineering. Microsoft explains:

  • The Windows Live OneCare list also includes several families associated with rogue security software, such as Win32/Renos, Win32/FakeXPA, and Win32/Antivirus2008.
  • The social engineering messages used in connection with rogue security software may be less effective in an enterprise environment, where malware protection is typically the responsibility of the IT department…
  • By contrast, the Forefront Client Security list is dominated by worms, like Win32/Autorun, Win32/Hamweq, and Win32/Taterf.
  • Worms rely less on social engineering to spread than categories like trojans and downloaders do, does and more on access to unsecured file shares and removable storage volumes, both of which are often plentiful in enterprise environments.

2. Users don’t always remove unwanted software: There’s great appeal to the procrastinator in the “ignore” button.

  • Microsoft explains one nuance of the malware issue:Software cannot always be classified in binary terms as “good” or “bad.”
  • Some software inhabits a gray area wherein the combination of behaviors and value propositions presented by the software is neither universally desired nor universally reviled.
  • This gray area includes a number of programs that do things like display advertisements to the user that may appear outside the context of the Web browser or other application and which may be difficult or impossible to control.

Microsoft’s scans allow users to ignore a security alert, allow software to remain, issue a prompt, quarantine or remove it.

If software is really malicious it is removed without user input. The gray areas appear when users have a choice.

Microsoft adds:
  • These decisions are influenced by a number of factors, such as the user’s level of expertise, how certain they feel about their judgment regarding the software in question, the context in which the software was obtained, societal considerations, and the benefit (if any) being delivered by the software or by other software that is bundled with it.
  • Users make choices about what to do about a piece of potentially unwanted software for different reasons, so it’s important not to draw unwarranted conclusions about their intent.

Moderate or Low threats are often ignored by users, who think that there’s value in the software. These threats are keepers based on user behaviour:

3. Rogue security software (Scareware) gains momentum.

The concept of rogue security software is pure genius. Malicious hackers prey on the fears of users, cook up bogus security software and extract payments to keep your PC running. Microsoft notes that rogue security software is becoming a hot category.

Microsoft reports:

  • Rogue security software authors have long attempted to exploit this trust by giving their programs generic, anodyne names, like “Antivirus 2009,” and making them resemble genuine security software in many ways.
  • Recently, many threats have taken this approach a step further, posing as components of the operating system itself or as a familiar search engine.
  • One of the first families observed to exhibit this behavior was Win32/FakeSecSen, which was added to the MSRT in November 2008 and was the eighth most prevalent family in 2H08 overall.
  • Win32/FakeSecSen adds an icon to the Control Panel named Vista AV or MS AV and fraudulently uses the same four-colour shield icon as the Windows Security Center. Double-clicking the icon launches the rogue software, which claims to detect a large number of nonexistent threats and urges the user to “activate” the software by paying for it.

Win32/Renos is a longtime threat that delivers rogue security software. It was the most prevalent threat in the second half of 2008. Two new trojans–Win32/FakeXPA and Win32/FakeSecSen were the seventh and eight most prevalent family class.

4. Social networking phishing attacks represented less than 1 percent of attacks, but yielded a big chunk of phishing impressions.

Translation: Social networking sites will remain a big phishing target.

Microsoft explains:
  • A typical social network phish is likely to trick an order of magnitude more users than a typical financial phish. There are a number of explanations for this discrepancy.
  • While financial institutions targeted by phishers can number in the hundreds, just a handful of popular sites account for the bulk of the social network usage on the Internet, so phishers can effectively target many more people per site.
  • In addition, phishers often use the messaging features of the sites themselves to distribute their attacks, typically by gaining control of a user’s account and using it to send phishing messages to the victim’s friends.
  • These attacks can be much more effective than e-mail–based attacks, because they exploit the considerable level of trust users place in their friends.

Take a look at:

And.

5. Malware is dominant in the U.S. and accounted for 67 percent of all infected computers.

Trojans—the miscellaneous variety–were detected on 29.4 percent of infected computers. Among other items:

  • Five of the top 20 families detected in the United States in Q3 and Q4 of 2008 (Win32/Renos, Win32/FakeXPA, Win32/FakeSecSen, Win32/Antivirus2008, and Win32/Winfixer) download rogue security software or display misleading warning messages to convince users to purchase a program that supposedly removes spyware.

Here are the top five individual threats:

Trojan downloaders and droppers were detected on 24.4 percent of all infected computers.

I trust this was of interest to you and you will see the sense of protecting your computer(s) with known and trusted anti Virus software as well as setting up a good Firewall and Intrusion detection. The rise and rise of Malware across the globe means that you will also need to protect your system(s) from this menace.

Do your research, read the reviews and never be the first to try any new protection software.