On UrbanBaby: Nanny vs. Daycare. Discuss!
BNET Business Network:
BNET
TechRepublic
ZDNet

September 13th, 2009

The ultimate guide to scareware protection

Posted by Dancho Danchev @ 5:49 pm

Categories: Anti Virus, Botnets, Browsers, Complex Attacks, Data theft, Hackers, Malware, Passwords, Social Networking Applications, Spyware and Adware, Viruses and Worms, Web 2.0

Tags: Search Engine Optimization, Antivirus, Malware, Security Software, Search, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms, Security, Dancho Danchev

Throughout the last two years, scareware (fake security software), quickly emerged as the single most profitable monetization strategy for cybercriminals to take advantage of. Due to the aggressive advertising practices applied by the cybercrime gangs, thousands of users fall victim to the scam on a daily basis, with the gangs themselves earning hundreds of thousands of dollars in the process.

Not surprisingly, Q3 of 2009 was prone to mark the peak of the scareware business model, whose affiliate program revenue sharing scheme is not only attracting new cybercriminals due to its high pay-out rates, but also, is directly driving innovation within the cybercrime underground acting as a reliable financial incentive.

This end user-friendly guide aims to educate the Internet user on what scareware is, the risks posed by installing it, how it looks like, its delivery channels, and most importantly, how to recognize, avoid and report it to the security community taking into consideration the fact that 99% of the current releases rely on social engineering tactics.

What is scareware?

Basically, scareware, also known as rogueware or put in simple terms, fake security software, is a legitimately looking application that is delivered to the end user through illegal traffic acquisition tactics starting from compromised web sites (Sony PlayStation’s site SQL injected, redirecting to rogue security software), malvertising (MSN Norway serving Flash exploits through malvertising; Fake Antivirus XP pops-up at Cleveland.com; Scareware pops-up at FoxNews; Ukrainian “Fan Club” Features Malvertisement at NYTimes.com), or blackhat search engine optimization (9/11 related keywords hijacked to serve scareware; The most dangerous celebrities to search for in 2009; The Web’s most dangerous keywords to search for), to ultimately attempt to trick the user into believing their computer is already infected with malware, and that purchasing the application will help them get rid of it.

Upon execution, certain scareware releases will not only prevent legitimate security software from loading, but it will also prevent it from reaching its update locations in an attempt to ensure that the end user will not be able to get the latest signatures database. Moreover, it will also attempt to make its removal a time-consuming process by blocking system tools and third-party applications from executing.

There have also been cases where scareware with elements of ransomware has been encrypting an infected user’s files, demanding a purchase in order to decrypt them, as well as a single reported incident where a scareware domains was also embedded with client-side exploits.

For the time being, scareware releases are exclusively targeting Microsoft Windows users.

The characteristics of scareware - pattern recognition for a scam

Due to the fact that the scareware campaigns maintained by partners in the affiliate network use a standard template distributed to all of them, scareware sites all share a very common set of deceptive advertising practices, which can easily help you spot them before making a purchase.

For instance, the majority of scareware sites attempt to build more authenticity into their propositions by using “non-clickable” icons of reputable technology web sites and performance evaluating services, such as PC Magazine Editors’ Choice award, Microsoft Certified Partner, ICSA Labs Certified,  Westcoast Labs Certified, Certified by Softpedia, CNET Editors’ Choice, as well as ZDNet Reviews — the real ZDNet Reviews are unaware of the scareware’s existence.

Next –>

Pages: 1 2 3 4

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 50 Talkback(s)
RE: The ultimate guide to scareware protection
The ultimate guide is simple:

Do not use Windows online.

It is as simple as that. (Read the rest)
Posted by: gertruded Posted on: 11/17/09 You are currently: a Guest | | Terms of Use
Time to change advertising?  CobraA1 | 09/13/09
The bad guys are creative  mechBgon | 09/13/09
Oh, and how ironic. Hey Dancho...  mechBgon | 09/13/09
ROFLMAO!  Grayson Peddie | 09/14/09
There *is* a problem on Macs too  GrahamCluley | 09/13/09
How is this a OS X or Windows problem?  NeoGeneration | 09/14/09
os  elllroy | 09/14/09
happened to me once. make that twice.  pfyearwood | 09/14/09
WRONG!!!  dinosoft@... | 09/14/09
Time to switch to decaf Dino?  914four | 09/15/09
Really, Dino?  gary@... | 09/15/09
Oh it is not a problem for Macs  gertruded | 11/17/09
Oh how ironic - I cannot take ZDNet recommendations seriously any more.  pdalton@... | 09/13/09
There's no preventing stupid.  James T. Kirk | 09/14/09
That's easy to say...  NCWeber | 09/14/09
RE: That's easy to say  bfilipiak@... | 09/14/09
Lol  aaaa123354 | 09/14/09
Excellent article, Dancho,  mhenriday | 09/14/09
See to that you don't need it. Simple.  Mikael_z | 09/14/09
Needing that "crap"  M.R. Kennedy | 09/14/09
Why not a Mac? Because we have work to do maybe?  James T. Kirk | 09/14/09
You need it too, my friend happy  mechBgon | 09/14/09
Silly Person  FrankleeMiDeer | 09/14/09
Google is one of the worst offenders  Joe_Raby | 09/14/09
NY Times was serving scareware yesterday  markbn | 09/14/09
NY Times Scareware  AndrewBW | 09/14/09
OK, I followed a link from Google News  markbn | 09/14/09
NY Times Scareware  savio.lau | 09/14/09
fake av stuff  boomchuck1 | 09/14/09
RE: The ultimate guide to scareware protection  lna2000 | 09/14/09
Find these guys?  murphym@... | 09/16/09
RE: Find these guys?  bfilipiak@... | 10/08/09
Downside to Apple's approach  fastboxster | 09/14/09
PLEASE READ THIS  chaz15 | 09/14/09
RE: The ultimate guide to scareware protection  Ashtonian | 09/14/09
The night crew should be FIRED in that case  Lerianis10 | 11/17/09
RE: The ultimate guide to scareware protection  JOEL714 | 09/14/09
All known scareware programs?  murphym@... | 09/16/09
Re: All known scareware programs?  Altiris_Grunt | 09/23/09
RE: The ultimate guide to scareware protection  rjamison | 09/14/09
RE: The ultimate guide to scareware protection  dennyw@... | 09/14/09
The OFF button  RazorEdge | 09/14/09
Avoid bad exits  cquirke | 09/15/09
-  fcdenton666 | 09/15/09
Simple rule of thumb  Greenknight_z | 09/15/09
No, the close button will NOT be a link to malware  Lerianis10 | 11/17/09
Cybercriminals are getting more sophisticated, so must we  edchuy | 09/16/09
RE: The ultimate guide to scareware protection  Fat2000 | 09/17/09
So, How to prevent it from popping up?  dclements@... | 11/17/09
RE: The ultimate guide to scareware protection  gertruded | 11/17/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads