Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

March 20th, 2013, 09:05 GMT · By

Chameleon Click Fraud Botnet Costs Advertisers over $6M / €4.6M per Month

SHARE:

Adjust text size:

Distribution of Chameleon bots
Enlarge picture
Security firm Spider.io has identified a botnet, dubbed Chameleon, which helps cybercriminals earn more than $6 million (4.6 million EUR) a month from advertisers by emulating human visitors on certain websites.

Chameleon, which has been monitored by the company since December 2012, is similar to the recently disrupted Bamital botnet. However, unlike Bamital, Chameleon impacts display advertisers, not text-link advertisers.

So far, more than 120,000 host machines have been identified, most of which are in the US IP space.

According to Spider.io, the botnet targets at least 202 websites with great impact. Of the total 14 billion ad impressions recorded across these sites each month, at least 9 billion are generated by the botnet.

This means that 65% of the traffic on these websites is botnet traffic. On average, advertisers pay $0.69 CPM for ad impressions served to Chameleon.

Host machines are subjected to heavy loads because each of the bots masquerades as several concurrent site visitors. This causes the bots to crash and restart regularly.

Every time a bot restarts, it requests a new set of cookies. The experts note that at least 7 million distinct ad-exchange cookies are associated with the botnet each month.

“Chameleon is a sophisticated botnet. Individual bots run Flash and execute JavaScript. Bots generate click traces indicative of normal users. Bots also generate client-side events indicative of normal user engagement,” the security firm noted.

“They click on ad impressions with an average click-through rate of 0.02%; and they surprisingly generate mouse traces across 11% of ad impressions.”

Another clever thing about Chameleon is that the bots generate uniform random click coordinates across ad impression. In addition, randomized mouse traces are generated to make it appear as if a real user is visiting the website.


1,007 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


German and Swiss User Warned About Fake Swisscom and T-Mobile Emails

Andromeda Botnet Reemerges, Australia, Turkey and Germany Most Impacted

Cybercriminals Are Testing AlbaBotnet, a Threat Designed to Target Latin America

Trend Micro Publishes Research Paper on Asprox Spam Botnet

New RemoteIt RAT Advertised on Hacker Forums

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM