Feeds

Seeing ads on Wikipedia? Then you're infected

Click fraudsters are milking you for cash

High performance access to file storage

Surfers who see ads when they visit Wikipedia are likely infected with malware, the online encyclopedia warns.

Wikipedia relies on donations to fund its work, resisting the temptation to put ads on its pages. So internet users who see commercial ads when they visit the encyclopedia are been served content via cybercrime affiliates, a blog post by Wikipedia explains.

We never run ads on Wikipedia. Wikipedia is funded by more than a million donors, who give an average donation of less than 30 dollars. We run fundraising appeals, usually at the end of the year.

If you're seeing advertisements for a for-profit industry (see screenshot for an example) or anything but our fundraiser, then your web browser has likely been infected with malware.

Wikipedia doesn't warn over any specific malware but rather about the symptoms of click fraud, one of they more common ways that virus writers turn an illicit profit. The approach was used as the business model behind the infamous Flashback Trojan, which notoriously created a huge botnet on Mac machines until Apple belatedly patched the Java vulnerability that the malware had exploited. Cupertino released a clean-up tool earlier this week.

An updated analysis by Symantec, published on Wednesday, reveals that over a three-week period in April, the botnet displayed over 10 million ads on compromised computers. "Approximately 400,000 of those ads were clicked on, which would have netted the attackers $14,000 if they were able to collect it," an anonymous Symantec researcher explains. "Many PPC providers employ anti-fraud measures and affiliate-verification processes before paying. Fortunately, the attackers in this instance appear to have been unable to complete the necessary steps to be paid.

"It is estimated the actual ad-clicking component of Flashback was only installed on about 10,000 of the more than 600,000 infected machines. In other words, utilising less than 2 per cent of the entire botnet the attackers were able to generate $14,000 in three weeks, meaning that if the attackers were able to use the entire botnet, they could potentially have earned millions of dollars a year," Symantec adds. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.