NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Virus alerts

Virus alerts


Cyber-Criminals Take Advantage of Gmail Downtime

By poisoning search results with pages serving malware

By Lucian Constantin, Web News Editor

26th of February 2009, 10:50 GMT

Adjust text size:


Gmail downtime used by cyber-criminals to distribute malware
Enlarge picture
Security researchers from antivirus vendor Trend Micro maintain that during the few hours of Gmail downtime, cyber-crooks have moved fast to instrument a malware distribution attack, which employs black-hat SEO and social engineering techniques.

The fact that cyber-criminals capitalize on important events in order to get the most out of their schemes and malicious campaigns is nothing new. However, in the online world, the definition of "important events" exceeds the scope of holidays and significant developments that affect our lives, such as armed conflicts or natural disasters.

In these days of social networking climax, problems or changes that affect popular services, which bring together millions of users, are just as important. Such has been the case with the recent outage suffered by Google's e-mail service, Gmail.

Naturally, a large number of users were curious to find out why they could not access their accounts, and therefore many of them resorted to searching on Google, but as Trend Micro researcher Loucif Kharouni has discovered, the cyber-crooks were fast to react.

"During the downtime, searches for the string 'gmail down' yielded a Google Group page also named 'Gmail down' as the top result," JM Hipolito, responsible with technical communications at Trend, explains.

Amongst various adult materials, this page promoted three external links. The first one, entitled "Really young good looking teenager," pointed to a computer trojan identified by Trend as TROJ_PROXY.AEI. Its playload involves poisoning the search result pages from Google on the victim computer by forcing the browser to connect though a proxy server under the attackers' control.

Visiting the second link prompts the download of yet another computer trojan installer identified as TROJ_AGENT.FAKZ. This malicious application is served as a Browser Helper Object (BHO) and, when executed, opens a website inside an Internet Explorer window. The site masquerades as an embedded video file, which when clicked triggers the download of a rogue security software detected as TROJ_FAKEAV.ANI.

The third link leads to a file called "The Dark Knight torrent.zip." When unpacked, it contains a .BAT file (BAT_DELWIN.AA) with a destructive playload. More specifically, when executed, the .BAT script deletes several critical system files such as autoexec.bat, boot.ini, ntldr and win.ini. It then proceeds to display two alerts that read "Virus Activated" and "Computer Over. Virus=Very Yes," respectively. They are followed by a system shutdown and the computer is left unbootable.

According to the Trend Micro analysts, the said Google group has only been online for approximately 25 minutes, so hopefully it has not affected too many users. However, as Mr. Hipolito notes, "This incident serves proof of how keen cybercriminals’ instincts can get in seeing opportunities to distribute their malicious files."

TAGS:

Trend Micro | Gmail downtime | computer trojan | malware distribution | black-hat SEO
Read by 1,203 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Malware Exploiting Recent IE7 Vulnerability

Researchers Warn of Increase in 'Lovely' Spam

Storm's Successor Loves Valentine's Day

Spam Distribution Reaches Almost pre-McColo Levels

Barack Obama's Website Used to Push Malware

The Embassy of India in Spain Pushes Malware via Website

Government Websites and Microsoft Help Push Scareware

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM