Feeds

Thousands snared by malware warning from big-name websites

Attack of the tainted banner ads

Protecting against web application threats using SSL

Thousands of PC users have been duped into surrendering sensitive information and installing malicious software after falling victim to a complex scam that continues to plague well-known websites, a researcher warns.

The scam is the latest to piggyback on banner ads that are fed to high-traffic destinations. Malicious code hardwired into the ads prompts a pop-up that warns of a bogus security threat on the visitor's machine. It offers to fix the problem in exchange for a fee and for credit card information. The ad then attempts to install a back door on the victim's machine.

"These are pretty well-respected, high-traffic websites," said Don Jackson, a researcher with security provider SecureWorks. "The point is to compromise [the user's machine] and basically have it on demand."

Jackson estimates the rogue ads have appeared on anywhere from "several hundred to 1,000" sites, which tend to be related to television and entertainment. Based on unique signatures of the javascript used in the attack, which researchers have seen passing over the net, he estimates thousands of people have fallen for the ruse.

Jackson has managed to shut down at least two servers serving the bad ads, but warns at least two more are still operational. He declined to identify the servers or the websites by name.

Those behind the scam make some money from the sale of the bogus software, but the real profit comes from selling the victim's credit card information and access to the infected computer.

The tainted ads are being sold by outfits posing as small online advertising agencies. They then purchase ad space from the large websites. It's hard to spot anything fishy about the ads. They look legitimate are are programmed to only occasionally serve up malicious code, thwarting attempts by security personnel to filter out harmful ads.

As is so frequently the case, those using the NoScript extension for the Firefox browser are afforded some level of protection against the ads, but not always. The ads are frequently served up by the same server hosting the trusted content. Users who allow the site to run javascript so, for example, it can provide local weather forecasts, will not be protected, Jackson said.

When a person views a page that contains a malicious ad, a threat warning will appear if the victim clicks anywhere on the page or take most other actions. The bogus anti-spyware programs bear names including Spy-shredder, AntiVirGear and MalwareAlarm. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.