Share

Related Links

Related Stories

  • Financial hackers attacking Visa/MasterCard users with fake 3-D Secure logins
    Criminal hackers are using more advanced methods of trying to extract users card credentials, the latest attack vector being malware that launches a fake Visa/MasterCard 3-DSecure screen.
  • Fake Adobe Flash updates lure the unwary
    Barracuda Networks has warned internet surfers to be wary of fake Adobe flash updates, after it uncovered a number of compromised sites in the wild which present unwary visitors with an official-looking Adobe Flash update page.
  • Hike in trojan activity in May
    The latest monthly statistics on security threats from Sunbelt Software claim there has been a significant increase in Trojan activity, as well as malware designed to channel fake anti-virus products onto a user's machine.
  • Fake anti-virus apps generate $180 million a year for one crimeware gang
    Fake anti-virus applications have been around for a few years now, but there are signs that hackers are deploying the scareware apps more and more and, according to Rik Ferguson, Trend Micro's solutions architect, the economics of fear are what drives this type of malware
  • Final episode of 'Lost' tapped by hackers to spread fake anti-virus software
    There's nothing like the final episode in a TV series to bring out people on the Net looking for early copies of the cliffhanger, and 'Lost' looks to be no exception. Unfortunately, PandaLabs reports users' searches are being hijacked to get them to install fake anti-virus software.

Top 5 Stories

News

Computer users warned as fake AV attack spreads

26 August 2010

Sophos urges users not to click on suspicious email attachments from unknown sources

IT security and data protection firm Sophos is warning computer users to be cautious in the wake of a widespread spam campaign designed to infect users with fake anti-virus products. If recipients open HTML files attached to the spam emails, their web browser will be directed to a hacked website containing a malicious iFrame that allows the fake anti-virus attack to be launched.

The emails that have been intercepted have a variety of different themes ranging from credit card charges to free-to-view holiday photographs.

The emails have subject lines such as:

  • Parking Permit and/or Benefit Card Order Receipt - <random number>
  • You're invited to view my photos!
  • Appointment Confirmation
  • Your Bell e-bill is ready
  • Your Vistaprint Order Is Confirmed
  • Vistaprint Canadian Tax Invoice (<random number>)

"A scam like this can be extremely successful at passing revenue directly and quickly into the hands of hackers - so we all have to be on our guard", said Graham Cluley, senior technology consultant at Sophos.

"The attacks are designed to trick people into paying to remove threats from their computer that never really existed in the first place. Once a user's computer is infected with fake anti-virus, the software will continue to bombard the user with bogus warning messages to encourage them to pay for threats to be removed or install more malicious code onto their PC. If computer users are concerned about the security of their machine, they should go directly to a legitimate IT security site, rather than put their trust in a criminal hacking gang."

Sophos detects the malicious email attachments as Troj/JSRedir-CH, and the fake anti-virus attack as Mal/FakeAV-EI.

Fake anti-virus scams are usually very successful as hackers prey on human gullibility, poorly protected websites, and the tried-and-trusted trick of scaring users into believing that they have security problems on their PC. This can lead users into downloading dangerous software onto their computers and handing over their credit card details.

 

This article is featured in:
Internet and Network Security • Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.