Infected software fakes on the rise

By Victoria Ho, ZDNet Asia
Wednesday, September 24, 2008 07:10 PM

Spam e-mail that contain links to malware bearing viruses and Trojans are on the increase, particularly those disguised as legitimate software, security vendors warn.

One common ruse involves the circulation of fake copies of popular software, which infects users' systems upon installation. In a statement Wednesday, Symantec pointed to the example of a "very high profile attack" involving fake versions of Microsoft browser, Internet Explorer 7.

Adobe also recently issued a warning that fake copies of its Flash plugin had been circulated via fake news video pages that prompt users to download the malware.

Ironically, another IT security company Sophos, noted that Symantec itself fell victim to such hoaxes.

Graham Cluley, senior technology consultant at Sophos, warned users of a Trojan horse circulating as a free copy of competing Symantec's Norton AntiVirus 2008 product.

Cluley said in a blog post that users running a search for the string "free antivirus" would be directed, via Google's advertisements, to a "professional-looking Web site" claiming to offer antivirus software for download.

The software offered is infected with a Trojan horse, called Troj/FakeAV-AD, which presents false security alerts and prompts users to divulge their credit card details to purchase a "full version" of the software.

Cluley said in a video posted on his blog that the yellow-themed fake site is made to mimic Symantec's own site in appearance. "This [site] seems to be going to considerable lengths to present itself as a legitimate product," he said.

According to Symantec, there has been an overall rise in spam that points to malicious software, compared to traditional spam that carry merely promotional or marketing product information.

The security vendor said the number of e-mail directing users to malware increased by 9 percent last month, accounting for 27 percent of all spam.

Overall spam levels remained constant in August, where 80 percent of e-mail were spam messages, Symantec said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

10 open source projects worth checking out

Open Source

The open source field is pretty crowded, but certain projects stand above the rest. Here are 10 tools and solutions you don't want to overlook.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in "Racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web