Fake Black Friday websites are a top source of rogueware

According to Steven Sundermeier, the director of ThirtySeven4, a specialist IT security vendor, as a search term, 'Black Friday' has soared in popularity this week, with most search engines reporting it as the number one keyword.

Because of this, he is strongly recommending that internet users avoid using the search term in their online search routines, unless they want to stand a high probability of inadvertently installing a piece of scareware.

"We've posted a web page dedicated to information on the more popular versions of Scareware", he said, adding that it appears that retail chains aren't simply competing against each other for a shoppers business but cybercriminals have entered the competition too.

To  counter the problem, Sundermeier says that his research team has developed an online malware scanner to detect the presence of any security issues on a users’ PC.

The trial license of Thirtyseven4 anti-virus, meanwhile, he adds, is fully functional and can completely remove such an infection if a user has already inadvertently downloaded and installed a piece of Scareware.

The scareware problem stems from the fact that internet users searching the term 'Best Buy Black Friday 2010 Deals' within Google may have inadvertently visited a poisoned link that downloaded the fake security product,

"Around this time of year, electronics are always hot ticket items so it's no surprise that Best Buy was among the first retail chain names used to trick a consumer into downloading malicious software", he said. "As the days draw closer to Black Friday, we will certainly see an increase in activity involving these tactics", he added.

As a result of the problems, Sundermeier and his team are recommending five simple steps to avoid falling victim to such attacks:

  1. When searching for online sales, go to the retail store website by typing in the web address directly in to the browser.
  2. When visiting a less trusted website for the first time, enable the secure browsing feature of the browser.
  3. Never click 'Ok', 'Yes', or similar if a message box should appear seeking or giving permission to install some component, object or feature, when visiting unknown websites.
  4. Make sure that antivirus software is installed and that its virus database files are up-to-date.
  5. Maintain regular operating system updates.

What’s hot on Infosecurity Magazine?