On GameSpot: 54.2% of Xbox 360s fail - Report
BNET Business Network:
BNET
TechRepublic
ZDNet

January 14th, 2010

Haiti earthquake themed blackhat SEO campaigns serving scareware

Posted by Dancho Danchev @ 3:53 pm

Categories: Anti Virus, Browsers, Data theft, Hackers, Malware, Passwords, Web 2.0

Tags: Search Engine Optimization, Search, Marketing Research, Marketing, Dancho Danchev

Cybercriminals quickly mobilized following the news of a massive earthquake that hit Haiti on Tuesday, by introducing several hundred compromised domains embedded with bogus blackhat seo (search engine optimization) content related to Red Cross donations and general Haiti earthquake relief information.

The sites are already appearing within the first 10 search results on Google, and upon clicking on them the user is redirected to one of the most profitable monetization tactic (FBI: Scareware distributors stole $150M) that scammers use these days - scareware also known as rogueware.

Naturally, the blackhat SEO campaigns are only the tip of the iceberg. Here’s what else to look for, and how to make sure you’re donating money to the right organization.

What’s particularly interesting about the blackhat SEO campaign serving scareware (Setup_2022.exe; install.exe), is that a huge percentage of the sites are hosted within the network of Heart Shared hosting (heartinternet.co.uk), indicating some some of automatic exploitation of its customers.

The same practice of relying on compromised legitimate domains within a particular ISP was also evident in blackhat SEO campaigns that were analyzed over the last couple of months.

For instance, not only was the same practice used to affect over a million web sites (Thousands of web sites compromised, redirect to scareware) in November, 2009, but also the campaign itself was traced back to the Koobface gang, which is clearly involved in fraudulent activities going beyond the Koobface botnet.

Different fraudulent groups either multitask, or cover a specific fraud segment exclusively. According to Symantec, spam campaigns impersonating the British Red Cross are already in circulation, requesting Western Union payments to support the victims of the earthquake. Anticipating the upcoming flood of earthquake relief scams, the FBI has released the following tips in order to raise more awareness:

  • Do not respond to any unsolicited (spam) incoming e-mails, including clicking links contained within those messages.
  • Be skeptical of individuals representing themselves as surviving victims or officials asking for donations via e-mail or social networking sites.
  • Verify the legitimacy of nonprofit organizations by utilizing various Internet-based resources that may assist in confirming the group’s existence and its nonprofit status rather than following a purported link to the site.
  • Be cautious of e-mails that claim to show pictures of the disaster areas in attached files because the files may contain viruses. Only open attachments from known senders.
  • Make contributions directly to known organizations rather than relying on others to make the donation on your behalf to ensure contributions are received and used for intended purposes.
  • Do not give your personal or financial information to anyone who solicits contributions: Providing such information may compromise your identity and make you vulnerable to identity theft.

If you want to donate money to the real organizations, consider going through Google’s Support Disaster Relief in Haiti campaign page.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 35 Talkback(s)
DHL & UPS Scams
I have been getting multiple scam emails purporting to be from DHL and/or UPS.

They state:
"Dear customer!
The courier company was not able to deliver your parcel by your address.
C
... (Read the rest)
Posted by: lehnerus2000 Posted on: 01/20/10  (Edited: 01/20/10 @ 05:44) You are currently: a Guest | | Terms of Use
Could you please clarify..  AzuMao | 01/15/10
If you notice in the article, that it refers to  JM1981 | 01/15/10
So it's Windows' fault?  rfnajera | 01/15/10
Nonsense!  AzuMao | 01/15/10
Ignorance and brainwashing  Crestview | 01/15/10
Thanks for demonstrating your ignorance.  AzuMao | 01/15/10
Hey Apu, clarify whatever it is you are trying to contribute.  *Gman* | 01/16/10
Hey *Gwoman*..  AzuMao | 01/16/10
re:So it's Windows' fault?  schmandel@... | 01/15/10
Yes and no  Federico Churca | 01/15/10
Okay. Thanks for clarifying.  AzuMao | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  ekimnnud@... | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  POSTALET | 01/15/10
"Blackhat SEO Campaign"  dippleydokus | 01/15/10
Blackhat  phleroy | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  EdM727 | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  Gretsch001@... | 01/15/10
Re: FBI  kidtree | 01/15/10
And what's Google doing about it?  jpdemers@... | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  wrcresto03@... | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  TechInsider | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  majikthorne@... | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  oicur12ok | 01/15/10
Don't forget..  AzuMao | 01/16/10
Actually IIRC  lehnerus2000 | 01/18/10
That can't be it.  AzuMao | 01/19/10
I didn't say...  lehnerus2000 | 01/20/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  Prefect23 | 01/15/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  mark16_15@... | 01/16/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  JakeZ | 01/16/10
RE: Haiti earthquake themed blackhat SEO campaigns serving scareware  jamespd57 | 01/18/10
Crooked information  IslandBoy_77 | 01/20/10
So why..  AzuMao | 01/20/10
If you have the power...  lehnerus2000 | 01/20/10
DHL & UPS Scams  lehnerus2000 | 01/20/10

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads