iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Rogueware Racks Up $11,000 Daily For Affiliates
Search:
[ insider_reports_insider ]

Rogueware Racks Up $11,000 Daily For Affiliates



SecurityProNews
Staff Writer
2009-03-23

SecurityProNews: Insider Reports Insider Reports RSS Feed


Obviously, cyber crooks wouldn't do what they do if there wasn't any money in it. Thanks to some black-hat search engine optimization and a little rogueware (a.k.a. scareware), some are making almost $11,000 a day, according to FinJan's first Cybercrime Intelligence Report for 2009.

Rogueware Racks Up $11,000 Daily For Affiliates
Rogueware Racks Up $11,000 Daily For Affiliates

Rogueware/scareware describe the technique of scaring web surfers into downloading a fake anti-virus program by telling them their machine is infected with a virus. When users pay to download the program all they really get is taken and phished.

How effective is this malware technique? FinJan's Malicious Code Research Center, which tracked on rogueware affiliate network, says the installation rate was between 7 and 12 percent, though just shy of two percent actually paid $50 for it. Most of what is collected gets fed back to affiliates, earning on average 9.6 cents per referral.

While that seems like low rent, FinJan counted the number of referrals over a 16 day period at 1.8 million unique users, all of them duped by affliates' SEO savvy.

"Cybercriminals keep on looking for improved methods to distribute their malware and rogueware. Since they make money by trading stolen data or selling rogue software, they are looking for new and innovative techniques all time. To increase the distribution reach of their rogueware, they successfully turned to SEO," said FinJan CTO Yuval Ben-Itzhak.

This crew targets especially typos and misspelled popular or trendy keywords (obbama, liscense, Gogle, mobile fone) and compromise well known, search engine trusted sites by injecting those keywords on them and adding links. The search engines ranks sites from that site highly, and users don't hesitate to click through to them.

But along with the keywords is often a script that redirects unsuspecting users to a different doorway page, where they are told their machine is infected and prompted to scan and download. These PHP scripts also dynamically generate keywords and the doorway pages for them.

FinJan said this technique has driven as much as half a million Google searches to a compromised site.



About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds