Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

'Scareware' scammers abuse Google Trends to poison search results

They're riding the coattails of hot news, including Gmail's outage, to game Google

February 26, 2009 12:00 PM ET

Computerworld - Cybercrooks are using one of Google Inc.'s own tools to poison search results with links that spread fake security software, a researcher said today.

"Malware distributors have abused Google Trends before," said Craig Schmugar, a senior threat researcher at McAfee Inc. "But I've never seen them use it as aggressively as they are now."

Google Trends, a tool the search giant rolled out last June, highlights the most popular searches of the past hour. At midday Thursday, for instance, the No. 1 search phrase, according to Trends, was "Obama budget."

Scammers and malware makers are closely monitoring Google Trends to guide them in selecting search phrases and legitimate news content, which they then integrate into their own fly-by-night sites, said Schmugar. The idea is to "game" Google into ranking their malware-hosting sites near the top on scores of high-profile, current events-related search results.

"I'm not talking about just a few sites," Schmugar said. "I've collected a lot of them, with poisoned links [in Google search results] that are pretty high up, almost always in the top 10."

News accounts recently abused by hackers have ranged from this weekend's stories about a worm spreading on Facebook to the attack last week by a chimpanzee that left a Connecticut woman in critical condition, said Schmugar. "They're grabbing content from pages that are already popular," he said. "They grab content from those pages and put it on their own site."

More recently, Schmugar has monitored poisoned links ranked high on searches for "Gmail down," a reference to the two-and-a-half hour outage at Google's Web-based e-mail service on Tuesday.

Because the malicious sites share the same content as legitimate pages that are currently of great interest -- and because the scammers also name those pages with the popular search phrases it pulls from Trends -- Google's ranking algorithms push those sites toward the top when people search for that news item or use those search strings.

"It looks like they're following Trends, which refreshes every hour, and then reacting very quickly to produce their own sites," said Schmugar. The only common element he's found so far among those sites is that they are all hosted on free site-hosting services. "Some portion of this must be automated," he added, to account for the quick reaction time to the hot searches and content touted by Trends.

All the poisoned links lead to sites that hit users with phony security warnings; those alerts then try to trick users into downloading a free antivirus program. The download, however, is actually a Trojan horse that continues to dun the user with fake warnings. The only way that users can stop the messages, and to supposedly clean their PCs of infection, is to pay for the worthless software.

Distributing "scareware," as the category is sometimes called, can be very lucrative. Last year, Joe Stewart, director of malware research at SecureWorks Inc., said he had found evidence that some hackers were making as much as $5 million a year from the practice.

Schmugar's advice? "Look carefully before you click," he said.

Read more about cybercrime and hacking in Computerworld's Cybercrime and Hacking Knowledge Center.



Jump to comments

Google

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Gene Kim's Practical Steps to Achieve and Maintain NERC Compliance
Learn seven steps operators can take to meet IT configuration requirements set forth in the NERC-CIP standards.  

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.


IT Jobs