On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

October 2nd, 2008

Cybercriminals syndicating Google Trends keywords to serve malware

Posted by Dancho Danchev @ 1:20 pm

Categories: Anti Virus, Botnets, Google, Hackers, Malware, Microsoft, Passwords, Web 2.0

Tags: Security, Cybercrime, Blackhat SEO, SEO, Zlob Trojan, Webroot, Google Trends, Windows Live, Dancho Danchev

Google TrendsIn an underground ecosystem that is anything but old fashioned when it comes to abusing legitimate web services, cybecriminals have started exploiting the traffic momentum, and by monitoring the peak traffic for popular search queries using Google’s Trends, are syndicating the keywords in order to acquire the traffic and direct it to malware serving blogs primarily hosted at Windows Live’s Spaces.

According to a recent advisory issued by Webroot :

“For the first time, hackers are capitalizing on the top news stories from Google Trends Labs, which lists the day’s most frequently searched topics, which can include news of the Wall St. bail out or the presidential campaign,” said Paul Piccard, director of Threat Research, Webroot. “These highly relevant news stories and videos are being posted to the hackers’ fake blogs to increase the site’s Google search rankings.

These fraudulent blogs contain several video links about the news story for which the users were originally searching. Once a user clicks on one of the video links, they are prompted to download a video codec that downloads a rogue antispyware program designed to goad the user into purchasing an illegitimate program that may put their personal information and data at even greater risk. “

Let’s take a sample, and confirm the ongoing syndication of popular keywords in order to attract traffic to the several hundred malware serving blogs.

Search keywords blackhat SEO malwareA random keyword “on fire” like gwen ifill wheelchair indicates that 55 minutes ago a malware serving blog has been successfully crawled and is now appearing within the first 10 results thanks to the high page rank of Windows Live Spaces. Upon clicking the link, the user is exposed to the typical ActiveX Object Error message that is attempting to trick them into installing TrojanDownloader:Win32/Zlob.AMV with 10 out of 36 AV scanners currently detecting it (27.78%).

Rogue blogs blackhat SEO malwareMoreover, in order to ensure that their fake blogs will get crawled in the shortest time frame possible so that they can better abuse the momentum peak of the search query, they’re naturally taking advantage of the pre-registered blogs at popular blogging platforms which Google is crawling literally in real-time. Syndicating this particular keyword in order to serve malware is not an isolated event, with several hundred currently active blogs doing exactly the same as soon as Google Trends refreshes its hourly feed.

Fake codec ZlobMalware campaigns have been taking advantage of pure SEO (search engine optimization), and mostly blackhat SEO techniques, during the entire 2008. The difference between the ongoing campaign and previous ones, is that the current approach has a higher probability of attracting generic search traffic since it’s relying on the world’s most popular search engine to tip them on what has the world been searching for during the past hour.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 15 Talkback(s)
Patch for java is successful and posted.
This patch was designed for this; Spaces@MSN access to JRE FCV_FCI. I know it should have been marked J2SE. Search Stalin Hornsby, Stalin_Hornsby. It is the deal with a zipper and buffer and is in com... (Read the rest)
Posted by: rtirman37@... Posted on: 10/07/08 You are currently: a Guest | | Terms of Use
Large networks are increasingly...  bjbrock | 10/03/08
So, What Are You Proposing?  PMC-CON | 10/05/08
should be standards for large network systems  opcom | 10/07/08
RE: Cybercriminals syndicating Google Trends keywords to serve malware  alandee4 | 10/03/08
RE: Cybercriminals syndicating Google Trends keywords to serve malware  stephke | 10/03/08
RE: Cybercriminals syndicating Google Trends keywords to serve malware  fudge2216 | 10/03/08
You need an in depth defense to fight this kind of threat..  JCitizen | 10/04/08
RE: Cybercriminals syndicating Google Trends keywords to serve malware  botchagalupe | 10/03/08
Re: OpenDNS--a Good Thing.  gypkap@... | 10/03/08
On Mozilla, NoScript also.  phatkat | 10/03/08
Open DNS not always the answer...  JCitizen | 10/04/08
RE: Cybercriminals syndicating Google Trends keywords to serve malware  Alan Balkany | 10/03/08
RE: Cybercriminals syndicating Google Trends keywords to serve malware  windowsknowitall | 10/03/08
your best posting so far, Dancho  Narr vi | 10/03/08
Patch for java is successful and posted.  rtirman37@... | 10/07/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads