Tuesday, December 4, 2007

Google Purges Malware Sites Targeting Searchers

InformationWeek
Website: http://www.informationweek.com

In response to a concerted effort by cybercriminals to infect the computers of Google users with malware and make them unwitting partners in crime, Google apparently has purged tens of thousands of malicious Web pages from its index.

In a blog post on Monday, Alex Eckelberry, CEO of Sunbelt Software, noted that many search results on Google led to malicious Web pages that expose visitors to exploits that can compromise vulnerable systems.

"We're seeing a large amount of seeded search results which lead to malware sites," said Eckelberry. "These are using common, innocent terms -- one researcher landed on a malware site through searching for alternate firmware for a router."

Sunbelt published a list of search terms that returned malicious pages, the result of search engine optimization campaigns by cybercriminals to get their pages prominently ranked in Google -- Sunbelt refers to this as "SEO poisoning." The list includes hundreds of search strings containing the words "Microsoft Excel," along with a number of other popular technology-oriented terms, products, and companies.

On Tuesday, the SANS Institute said that the number of vulnerabilities in Microsoft Office had grown by 300% from 2006 to 2007, particularly in Excel.

A Microsoft spokesperson wasn't immediately available.

Sunbelt researcher Adam Thomas in a blog post attributes the thousands of pages to a bot net designed "to post spam links and relevant keywords into online forms (typically comment forms and bulletin board forums)," in order to place prominently in Google searches for those terms.

Those duped into visiting malicious Web pages from Google search results could, if their systems are vulnerable, acquire malware known as Scam.Iwin, which is designed to use the victim's computer to defraud Google and its advertisers. "With Scam.Iwin, the victim's computer is used to generate income for the attacker in a pay-per-click affiliate program by transmitting false clicks to the attacker's URLs without the user's knowledge," explained Thomas in a blog post. "The infected Scam.Iwin files are not ordinarily visible to the user. The files are executed and run silently in the background when the user starts the computer and/or connects to the Internet."

Google didn't respond to a request for comment.

But it appears Google has deleted the malicious pages from its index. "Google took action on these domains and you won't find them anymore in Google," said Eckelberry.

According to Trend Micro, cybercriminals have been planning for the holiday online shopping season for months.

"Since September, cybercriminals have been boosting their search engine rankings using a variety of methods such as 'comment spam' and 'blog spam' in preparation for the Christmas period," said Raimund Genes, CTO of Trend Micro, in an e-mailed statement. "With shoppers visiting these sites likely to purchase goods online after infection, their credit card details become a main target for cybercriminals looking for financial gains this season."

Eckelberry credits the cybercriminals responsible with being particularly crafty because they attempt to conceal their malicious Web pages from certain types of searches favored by malware researchers.

See original article on InformationWeek.com


7 comments:

Bonobo said...

My Antivirus Solutions
Rolls Royce can be hacked or Skype has shut down its video features due to fear of virus attack- these are not exactly the news making events you will get to read on any of the technology media portal. And this is exactly why this blog stands different from any other technology news portal.

IE AntiVirus

Swadesh said...

Mobile Phone Accessories
MyMemory offer a variety of mobile phone accessories, including SIM card readers, mobile phone holders, dangly's, and USB adaptors.Mobile Phone Accessories

prismsurfaceltd said...

The post was nice by Revathi

Gaurav Joshi said...



Bookmarking Demon is one of first automated solutions for link building to be launched to the world. The simple fact that Bookmarking Demon is still going strong and it is still very popular almost 5 years after being launched.


Bookmarking Demon Discount

Alina Smith said...

There are different types of Antivirus programs that will allow you to clean your computer from any errors that it may have, and will also allow you to make sure your computer is working properly. Discover here to know more about download antivirus.

Limtex Infotech said...

Nice Information...great work... avecto antivirus

Maps said...

Thank you for sharing the ultimate guide about to find about antivirus. Amazing and resourceful article. Really enjoyed this post. Please keep update us like this.

kaspersky free