Feeds

Looking for code work? Write fake anti-virus scripts

Scammer job ads move mainstream

Protecting users from Firesheep and other Sidejacking attacks with SSL

Updated A scareware purveyor has brazenly advertised for recruits on a mainstream job market website.

A job ad on Freelancer.com offers work for a coder prepared to turn his hand to the creation of fake anti-virus website redirection scripts. However, prospective applicants are warned not to expect a big payday - the budget for the whole project is between $30 and $250.

On the plus side the prospective employer, redlinecl, has 100 per cent positive feedback from previous coding lackeys. One said: "Nice buyer, hope can work for him again in the future."

Of course when the job involves tricking the unsuspecting into visiting scareware portals in order to flog software of little or no utility it's probably wise to take these glowing reviews with a pinch of salt.

The ad, posted on Monday (screenshot here), was spotted by security researcher Patrik Runald of Websense, who notes that the same chap was previously involved in fake PayPal pages, spam campaigns and other forms of malfeasance.

Runald described the ad campaign as an amateurish wannabe cyber criminal, based not least on his previous postings. "This guy seem to have no clue what he's doing," Runald told El Reg. "The Fake AV [anti-virus] business is based on affiliates which means that the company providing the software has people doing the fake AV scanning pages as well."

Adverts on Freelancer.com are largely legitimate but sometimes cross over the line into more questionable enterprises.

"Freelancer.com typically has jobs for creating websites, logos, writing help etc but there are lots of shadier once too, like making a voting bot," Runald explained.

The market for scareware is booming. Shysters involved in the business are increasingly adopting the business structures of mainstream security firms - even to the point of running call centres designed to persuade people not to try to apply for refunds, and recruitment programs.

redlinecl's project is on a much smaller scale than some of the Ukranian and Russian operations we've heard of, but it does illustrate the increased openness of those involved in the trade, who seem to feel little need to be discreet about their activities. ®

The next step in data security

More from The Register

next story
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.