Flashback gang could be making $10K a day off infected Macs
Symantec spells out the malware's money-making mechanism: click fraud
Computerworld - The Flashback malware that's infected hundreds of thousands of Macs may be generating more than $10,000 a day for the hackers who made the Trojan horse, Symantec said Monday.
The malware steals clicks from ads that Google's search engine displays alongside search results.
In a blog entry posted today, Symantec published an analysis of Flashback's money-making capabilities, and concluded -- as others had earlier -- that the gang was turning a profit through click fraud.
Flashback.K surfaced in March and by early April had infected more than 600,000 Macs.
"Click fraud" describes campaigns where large numbers of people are silently redirected to online ads not normally served by the site the user is viewing. The criminals receive kickbacks from the sometimes-legitimate, sometimes-shady intermediaries for each ad clicked.
The clicks are "ghost clicks" in that they are not triggered by a human, but instead by the botnet.
That's exactly what Flashback.K does, said Symantec. After worming its way onto a Mac via an exploit of a since-patched Java vulnerability, Flashback.K loads an ad-clicking component into Apple's Safari, Google's Chrome and Mozilla's Firefox browsers.
"Flashback specifically targets search queries made on Google and, depending on the search query, may redirect users to another page of the attacker's choosing, where they receive revenue from the click," said Symantec. "Google never receives the intended ad click."
In one code snippet shown by Symantec, a hijacked ad based on the user searching for "toys" would generate $0.008 per click, meaning that 1,000 clicks would earn the hackers $8, 10,000 clicks $80, and so on.
The Flashback gang is still earning this fraudulent revenue, even though much of the botnet has been "sinkholed" by Symantec and other antivirus companies, said Vikram Thakur, principal security response manager at Symantec. By registering as many potential command-and-control (C&C) domains used by the malware to receive instructions, security researchers prevent orders from reaching the infected Macs. The commands fall down a metaphoric "sinkhole" instead.
But in an interview today, Thakur confirmed that Flashback-infected Macs, even those that have been sinkholed by security firms, continue to produce revenue for the hackers.
"They're still making money," said Thakur, explaining that the ad-clicking component communicates to different C&C servers whose IP addresses are hard-coded into the malware. Those servers have not been sinkholed. "In fact, they're making a lot of money.
How much wasn't clear. Symantec hasn't been able to uncover the botnet revenue, but instead compared its size and money-making abilities to the 2011 "W32.Xpaj.B" botnet, a collection of 25,000 compromised Windows PCs that returned up to $450 per day to its handlers.
If Flashback's profit-making is as efficient, and with its size hovering around 600,000 Macs, by that example it could generate up to $10,800 per day, or $75,600 per week or $3.9 million over the course of a year. All tax free.
"That's a lot of money," Thakur said.
- With faster 5G Wi-Fi coming, Wi-Fi Alliance kicks off certification program
- A detailed look at Apple's iOS 7
- Apple plays defense, Microsoft goes on offense in battle for iPhone customers
- IT will have a love-hate relationship with iOS 7, OS X Mavericks and iCloud
- New MacBook Air still stymies repairs, upgrades
- 5-year-old Macs not too old for OS X Mavericks
- The new MacBook Air gets a 45% performance boost with PCIe flash
- The world is not flat: Apple unveils 'fresh, light' iOS 7
- Forget the keynote. WWDC is still about the developers
- Why iOS is the future of Apple (and how we got here)
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security for Virtualization Learn more.
- When Malware Goes Mobile: Causes, Outcomes and Cures Cybercriminals are increasingly setting their sights on smartphones and other mobile devices. Learn about platform-specific policies and strategies you can employ to protect...
- Top Three Reasons Why Customers Deploy EMC VNX with EMC VPLEX What if you could build a cost effective, continuously available storage infrastructure? Learn the top reasons users are deploying EMC VNX with EMC...
- Clearing the Clouds for Midmarket Businesses The 10-point checklist included in this expert brief has been developed to help small and midsize businesses select the cloud model and cloud...
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Williams & Fudge on Transforming IT with EMC Watch Williams & Fudge Data Center Director Phillip Reynolds discuss why this accounts receivable management firm turned to EMC. All Malware and Vulnerabilities White Papers | Webcasts
