Feeds

Dodgy affiliates use malware to flog Symantec and Check Point

Malvertisement break

Protecting users from Firesheep and other Sidejacking attacks with SSL

Unscrupulous affiliates are using malware to advertise security software from legitimate firms. The practice is the brainchild of people who make a commission for every sale they generate - and not security vendors themselves. The practice raises serious concerns about the integrity and policing of affiliate programs from big names in security including Symantec and Check Point.

Instances of the dodgy practice, compiled by security firm Sunbelt Software, include PC Tools being "malvertised" last month in manipulated search results created on machines infected with the DNSChanger Trojan (video here). Separately, popups generated by the C2 (AKA Lop) adware package maliciously punted Symantec and Check Point products last week.

Sunbelt is seeking to throw a spotlight on dodgy practices by affiliates rather than make marketing capital out of the development. "Affiliate programs are a great way to spread the word on your product, but they need to be monitored carefully for abuse," notes Alex Eckelberry, president and chief exec of Sunbelt.

The US-based anti-spyware firm is not the only security watcher to pick up on instances of malvertisement. Independent security researcher Ben Edelman, an assistant professor at the Harvard Business School, has spotted examples of popups for Symantec's online store generated by the SurfSideKick adware package that's described as potentially unwanted by Symantec and other security vendors. ®

The next step in data security

More from The Register

next story
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.