Showing posts with label Fake anti-virus. Show all posts
Showing posts with label Fake anti-virus. Show all posts

Tuesday, September 20, 2011

Automated Skype calls spread fake anti-virus warning [VIDEO]

Skype and fake anti-virusAs more and more people become acquainted by the tricks used by internet scammers and cybercriminals, so they are pressed to find new social engineering tricks in their hope of tricking the unwary.
One of the schemes we have heard of involves unsolicited calls via Skype, where an automated message (what I like to call a "Digital Dorothy") warns you in a semi-robotic voice that your computer's security is not up-to-date.
A Naked Security reader has pointed us to the following YouTube video, showing just such a scam call caught on camera. Fortunately, in this case, the recipient of the bogus call about his computer's security was wise to the scam and knew not to act upon it.
Warning: Some of the language used in this video is a little fruity.



In case you couldn't make it out on the video's soundtrack, here's what the automated call was saying:
"Attention: this is an automated computer system alert. Your computer protection service is not active. To activate computer protection, and repair your computer, go to [LINK]"
If you weren't aware of fake anti-virus (also known as scareware) scams like this you might well be worried enough to visit the website referred to in the message, where it will pretend to scan your computer's security.
Computer protection not active
Surprise surprise.. the website claims that you are not properly protected - and it urges you to install its software (a steal at $19.95).
Computer protection not active
I'm not sure I would want to trust any product which uses Skype spam techniques to advertise itself, and presented itself in such an underhand manner.
They seem to be keen for you to hand over your contact details (including your email address). For test purposes, I entered an email address - but haven't received a communication yet. One thing is for sure - I am not going to trust whatever they say in that email.
Computer protection not active. Now they want your contact details
Of course, if you don't want to receive unsolicited Skype calls the best thing to do is change your privacy settings so only users listed in your contacts list are allowed to get in touch with you.
Skype privacy settings
If you want to find out more about fake anti-virus or scareware attacks download the technical paper from SophosLabs: "What is Fake AV?" [PDF]

Sunday, September 18, 2011

BitTorrent serves malware directly from website - no need for P2P!



Back in 2001, when BitTorrent was first announced, it seemed inevitable - and, at the same time, implausible - that a commercial company based around its social approach to file sharing would emerge and succeed, despite its novelty.
Inevitable, because the sheer popularity of peer-to-peer file sharing means that the potential return for any company successfully commercialising a popular P2P client is enormous.
Implausible, because the indelible association between P2P and piracy means that potential risk of burning out in lawsuits from copyright holders is vast.
But the creator of BitTorrent, Bram Cohen, did create a company out of his codebase, and BitTorrent, Inc. is effectively today's Torrent mothership.
The company is also the custodian of two popular Torrent clients: the so-called Mainline version, and its extremely popular compact cousin, uTorrent.
(The character u is commonly, if confusingly, used in Latin alphabets to represent the Greek letter μ. Short for micro, it's pronounced in English as mew, as in cat. So much for internationalisation.)
In its ten-year history, BitTorrent - the protocol, not the company - has become well known for facilitating the unregulated sharing of arbitrary material. Indeed, it's become quite the way to find all the ripped-off software, films, TV shows and porn you might need. Unsuprisingly, the cybercrooks love that sort of neo-anarchic mix, because it makes it easy for them to expose you to your fair share of malware.
Unfortunately, however, even if you are one of the several many entirely law-abiding users of BitTorrent, the folks at BitTorrent, Inc. may recently have put you in harm's way.
According to a really-ought-to-be-more-visible warning on the download pages of www.bittorrent.com and www.utorrent.com, a breach of the two servers resulted in a two-hour window in which downloading BitTorrent's software would have given you a fake anti-virus program instead.
This morning [13 Sep 2011 on the US West Coast] at approximately 4:20 a.m. PT, the uTorrent.com and BitTorrent.com Web servers were compromised. Our standard software download was replaced with a type of fake antivirus "scareware" program.
Just after 6:00 a.m. PT, we took the affected servers offline to neutralize the threat. Our servers are now back online and functioning normally
BitTorrent, Inc. identifies the malware as belonging to the Security Shieldscareware family. Program files under this "brand" of fake anti-virus should be mopped up by Sophos Anti-Virus as CXmal/FakeAV-A.
Confusingly, the BitTorrent blog has recently been updated to claim that the software available from the www.bittorrent.com URI was not affected, implying that only those who downloaded utorrent during the infection window would be at risk.
Since the two sites share the same network infrastructure - both resolve to the same IP number in Limelight Networks' cloud - you might want to ignore that blog update and assume that any recent downloads from Bittorrent, Inc. were dodgy and give yourself a thorough anti-malware checkover.
I'd also ignore the time window, since BitTorrent used the annoyingly ambiguous abbreviation "PT" to denote the timezone. I'm guessing they meant to say UTC-7, but they didn't.
Update. Allison at BitTorrent got in touch to say she's updated the official report to make it clear: Pacific Daylight Time, UTC-7. Thanks for listening, Allison!

Will Windows 8's new interface herald full-screen scareware?



Microsoft has designed a new user interface for Windows 8, with an emphasis on bright colours and friendliness.
Personally, the interface (dubbed "Metro") reminds me of a child's toy.
Windows 8 and Simon toy
One of the interesting features of the Metro user interface is that apps are designed to be full-screen, without any surrounding furniture. That means you won't see scroll bars and the like, unless you interact with the interface.
One has to wonder whether this will lead to a wave of new scareware/fake anti-virus attacks.
Currently, malicious hackers poison webpages to display what appears to be a warning about malware found on your computer - tricking users into downloading software. The initial alert pops up in your web browser.
Fake anti-virus alert on older version of Windows
These phony alerts have proven to be a very effective way for cybercriminals to fool users into installing their malicious scareware. And it's very likely we'll continue to see hackers trick your browser into displaying bogus warning messages
But, with Windows 8, these browser-based fake anti-virus warnings will be shown full-screen, without the tell-tale visible signs that you're in a browser.
That means it may be even easier to convince a victim into believing they are viewing a genuine security alert from the operating system rather than simply a webpage pretending to be one.
Some will argue, no doubt, that Window 8's Metro simplistic interface is a sign of progress, making the use of computers less threatening to those who are currently put off by complicated GUIs.
The view may be that people get confused between operating systems, apps and browsers - why not make them all look the same?
But these are the very people who are, perhaps, most likely to be tricked into believing that a fake anti-virus alert is genuine and blindly do whatever the computer screen is advising them to do.
It will certainly be interesting to see how cybercriminals evolve their social engineering attacks to take advantage of a Windows 8 Metro-interfaced world.

Blue screens, cute screens

One thing we've already seen is how Microsoft has - after many years - revamped their infamous blue screen of death. Now it's a cute screen of death instead (and a slightly different shade of blue).
Blue screen of death - is this progress?
Wow, that's real progress..
One wonders if the blue screen itself will become an attractive disguise for scammers and malicious hackers.
Will they attempt to duplicate the look of the now oh-so-friendly blue screen of death by popping it up in full screen browser sessions, tricking users into making bad decisions?
One thing we can be sure of - if the bad guys think they will make money effectively this way, they'll do it.