Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

September 2nd, 2009, 10:37 GMT · By

California Wildfires Search Results Lead to Malware

SHARE:

Adjust text size:

Cybercrooks poison search results for the California wildfires
Enlarge picture
Security experts warn that searching for information about the bushfires currently gaining ground in California is likely to lead to malicious Web pages that attempt to infect visitors with malware. This attack seems to be part of a larger campaign that poisons search results for multiple current news topics.

Security researchers from antivirus vendor Sunbelt warn that searching for "Altadenablog," a popular news source for people living in Altadena, is returning a lot of malicious links. Altadena is one of the Californian locations currently affected by the wildfires.

"Altadena Fire Hottest Info" is also a search string that has been hijacked, with many of the pages returned distributing a trojan downloader called CodecPack.2GCash.Gen. "They use switching terminal sites as they are the urls not seen in transmissions that can remain static for days but rotating to the newer 2GCash Fake Codec sites," Patrick Jordan, senior spyware research analyst at Sunbelt, explains.

Meanwhile, researchers from CA are also reporting poisoned search results related to the southern Californian wildfires. What is interesting about their report is that the malware being distributed includes a trojan for Mac OS X, called Jahlav or MyCinema, and a rogue antivirus program called Smart Virus Eliminator.

The CA investigation was the result of a report from a user looking for maps of the Station Fire in Los Angeles. "Immediately, we searched and verified this report, and surprisingly it was the #1 hit out of millions of pages in Google’s search results, while for Yahoo, it was the 4th hit," the company's experts note.

A report from antivirus vendor Panda Security links some of these attacks to a much larger scareware distribution campaign leveraging on other hot news subjects as well. "The Rogueware campaign we blogged about last week turned into a full blown BHSEO attack targeting relevant news topics such as, the California wildfires, Ted Kennedy’s death, DJ AM’s death, Mega Millions Lottery, Hurricane Danny, UFC 102, CNN and BBC breaking news among thousands of search terms and 123,000 links," it reads.

As always, users are advised to get their news only from trusted sources and avoid clicking on search results if they do not recognize the domain names they point to. Having a solid and update antivirus solution installed is also a must when it comes to staying clear of such threats.


2,778 hits · 1 comment
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Total Solar Eclipse Exploited by Cybercrooks

Michael Jackson Death-Themed Spam Already in Circulation

Air France Flight 447 Tragedy Exploited by Cybercrooks

Swine Flu Causes Spike in Malicious Activity

Easter and Ford Search Results Poisoned

READER COMMENTS:


Comment #1 by: Timothy Rutt on 03 Sep 2009, 08:11 UTC reply to this comment

Please know that www.altadenablog.com is NOT a malware site! It's my legitmate news site -- in fact, I discovered the malware during a routine auto-Google!

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM