fake anti-malware; fake software

Halloween: There’s Something Scary In Your Search Engine

We told you to watch out, didn’t we? (see Randy’s blog at http://www.eset.com/threat-center/blog/2009/10/23/this-is-the-funniest-video-ever). But it’s not just Michael Myers, zombies and vampires you need to watch out for. It’s also Funny Halloween Costumes, Harvey Milk, Pumpkin Carving Stencils, candy, Pokemon, and McDonalds Monopoly online. Yes, the fake/rogue AV gang have started on their Halloween special,

9/11 – Nothing Is Sacred to Scammers

Here in the UK we’ve seen quite a lot of media attention (TV movies and documentaries and so on) relating to the 9/11 attacks, so I’m sure there’s a lot more happening in the US, today of all days. Sky News (http://news.sky.com/skynews/Home/World-News/September-11-Terror-Attacks-New-Video-Of-Plane-Crashing-Into-South-Tower-9-11-Memorial-And-Museum/Article/200909215379149) has published an article that includes a link to a video clip of the

Fake Antimalware – Old Dogs, New Tricks

(1) Websense, our neighbour in San Diego, has reported a fake anti-malware scam centred on Labor Day social engineering. The scam uses malicious SEO (Search Engine Optimization) techniques, sometimes referred to as index hijacking or SEO poisoning, to misdirect potential victims. When the victim uses Google to search for Labor Day sales (apparently these are very

Rogue Anti‑Malware Exploiting Athens Fire

Cristian Borghello, Technical and Education Manager at ESET Latin America, tells us that they’ve noted quite a few sites that pretend to provide information on the fire crisis in Athens, Greece, but actually download malware onto the user’s PC. (Mistakes in translation are down to DH!) The criminals are using Black Hat SEO (Search Engine

Lies, Damned Lies, and SPYzooka

Update. August 5th 1:30 PM PDT.  I received an email from Mr. Carl Haugen, the president of BluePenguin Software who develop SPYzooka. According to Mr. Haugen the offending post was made by a former employee and has now been removed. I have verified that the post was removed. This is an encouraging sign. I will

Xrupter – Scareware meets Ransomware

There are quite a few reports currently about particularly ugly development son the fake AV front. The Register’s John Leyden has referred to a “double dipping” attack, in which the notorious Antivirus 2009 is implicated in an attack that goes beyond offering useless rogue anti-malware to inflicting actual damage on user data files, in order to force the victim

Fake AV Spam and Selling Free Software

[Updated after further investigation.] For the past few days, I’ve been seeing spam to one of my accounts offering me various bits of software. Nothing unusual about that, of course, but this one was better constructed than usual, and consistent, and I made a mental note to look more closely when I’m a little less