Rogue security programs are 'ongoing threat'

By Vivian Yeo, ZDNet Asia
Tuesday, October 20, 2009 07:16 PM

Rogue security software, also dubbed scareware, is an "ongoing threat" that is impacting largely users from English-speaking markets, according to findings from a year-long study by Symantec.

Released Tuesday, Symantec's report on rogue security software noted that 250 rogue security programs launched some 43 million attempts to prompt user installation between July 2008 and June 2009.

Further analysis on the top 50 most reported scareware was carried out between July and August this year, during which Symantec found that 38 of the programs had been detected prior to Jul. 1, 2008.

"The continued prevalence of these programs emphasizes the ongoing threat they pose to potential victims, despite efforts to shut them down and raise public awareness," the security vendor said in the report.

The five most commonly reported rogue security applications during the study were SpywareGuard 2008, AntiVirus 2008, AntiVirus 2009, Spyware Secure and XP AntiVirus.

Over 90 percent of the top 50 scareware had a dedicated Web site to support the scam, Symantec said. More than 194,000 domain names associated with rogue security applications were observed during the two-month evaluation period.

Web advertising was another popular tool, used in 52 percent of the installation attempts, added the company. Scammers also employed "black hat search engine optimization" to "poison search results" in order to be ranked higher on search results. They capitalized on topical and popular news, events and celebrities, such as during the Conficker worm saga, where scam perpetrators created Web sites containing terms such as "remove virus".

Besides playing on consumer fears, scammers also attempted to trick users via social engineering techniques, Symantec reported.

A major risk associated with rogue security programs is that users are provided a "false sense of security", said the vendor. Such applications also potentially expose PCs to additional threats as they may instruct the user to adopt more lenient security settings, or block compromised machines from accessing legitimate Web sites of security companies. In addition, users' personal data including credit card details submitted during the registration process, could be used without their knowledge or sold in the underground economy.

Asia's language diversity slowing attacks
Just over 60 percent of install attempts involving the top 50 scareware applications, targeted users in North America, Symantec said in the report. Some 31 percent of these scams occurred in Europe, the Middle East and Africa (EMEA), while the Asia-Pacific, including Japan, and Latin America regions were targeted in 6 percent and 2 percent, respectively, of such attempts.

The disparity in rogue software attacks likely corresponded to the fact that the majority of malicious activity globally is also detected in the North America and EMEA regions. In addition, most of the rogue programs were developed and distributed in English, although there were exceptions such as CodeClean, which targets Korean users.

The top five countries that housed servers hosting the rogue applications were in North America and Europe. The United States had the biggest share, accounting for 53 percent of all servers, while Germany ranked second with a share of 11 percent. China was the only Asian country to be ranked among the top 10, accounting for 3 percent of the servers.

Alvin Ow, Symantec's senior director of systems engineering for Symantec in Asia Pacific and Japan, told ZDNet Asia in an e-mail that threats aimed at disabling security technology will increase going forward. They are also becoming more difficult to detect, he noted.

"Profit is the primary motivation for creators and distributors of rogue security software scams and with such a lucrative underground economy, it looks as though scareware will continue to be an ongoing threat despite efforts to [contain them]," he explained. "Scareware authors will continue to push the security boundaries and devise innovative ways to break down user' protective barriers, in order to increase their profits."

According to Ow, enterprises need to remain vigilant against sophisticated attacks by mitigate them by deploying legitimate security software and regularly updating antivirus definitions. Other safeguards that can be employed include maintaining a whitelist of trusted Web sites, upgrading all browsers to the latest, patched versions and scanning all e-mail attachments at the gateway.


WORTHWHILE?

0

0 votes
Blog

Talkback 6 comments

Advice
Hit Ctrl + Alt + Del FAST if a web page says scanning your computer or won't let you exit the page or has a a click to exit prompt, and close the browser window from task manager.

Failing this, hit the reset button FAST!!!!
Posted by Charles L on Tuesday, October 20 2009 11:05 PM

RE: Advice
The new scareware enters registry entries disabling task manager and regedit and run commands not allowing you to stop the virus so your advise is no good. the user will need to edit registry in a preboot enviroment and remove bogus policies
Posted by anonymous on Wednesday, October 21 2009 12:28 AM

RE: RE: Advice
Not true I have caught several attempts to install by doing that or hitting the stop browser and catching the websites of the installer and being able to identify the actual location of the Spyware sender to web security sites.
Posted by PZ on Wednesday, October 21 2009 03:49 PM

Rogue security programs are 'ongoing threat'
Don't get me wrong... I am not saying the report is false in any way, but it would carry more weight if the source were an independent researcher, rather than a representative from a company who also sells anti-virus software and can lose sales to these other 'rogue' software sellers. It's like the guys from Ford saying that Hyundais and Kias are bad for the consumer. Gimme a reliable source, not the competition.
Posted by anonymous on Wednesday, October 21 2009 12:03 AM

RE: Rogue security programs are 'ongoing threat'
i work in the industry of removing these virus's and the author is correct about needing a Good up to date Anti virus program. Microsoft Security Essentials is Free. I had found that almost all AV programs do not find and fix the virus quickly enough before they do thier damage. But most of my clients problems are because the OS's are not updated, i see xps with only sp1 and the never downloaded Windows Defender and vistas with no sp
Posted by anonymous on Wednesday, October 21 2009 12:37 AM

RE: RE: Rogue security programs are 'ongoing threat'
There is a very powerful program out there that is free to use. when this is coupled with a good up to date virus scanner these threats are removed completely. this program is called malwarebytes...it removes spyware and malware...malware being these programs that pose as actual antivirus programs. another good one to run alongside it that is also free is spybot search and destroy. i have run avast, malwarebytes, and spybot on my conuter for years and with regular scans i have never had any issue with infection or removing infection when an issue comes up. also running a 64 bit operating system makes you more resilient as well.
Posted by Lawrence Salefske (holytotemic) on Wednesday, October 21 2009 10:40 PM


Tech Jobs Now!

Search for your ideal tech job:

A look at the Terminal Services Manager in Windows Server 2008

Windows Server

Terminal Services Manager has been around for a while, but Microsoft made some changes to the utility in Windows Server 2008. Here's what you'll find.


Read more »



Open source blog reloaded!

Blog thumbnail

This is with great pleasure that this "little corner of the Web" is resuming activities through another member of the (now famous ;-)) Beijing Linux User Group (BLUG) doing the..... by Fred Muller

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web