Securelist / Blog
Securelist / Blog
  • The Winlock numbers, the Winlock laws

    While Eugene’s busy taking bets (wonder how much he’s going to make?), I’ve been having a think about the Winlock case.

    Russian law enforcement is estimating that the bad guys could have raked in as much as $1 billion. While it’s difficult to be certain about the exact amounts involved (obviously they spread their money across a lot of different accounts to avoid attracting attention), a little bit of simple math makes me think this figure isn’t as crazy as it might sound.


    Our statistical analysis tells us there could be around a million people who’ve been infected. 10 cybercriminals, each getting a cut of a ransom between $10 and $30 - even though they were paying out $3 per infection to the people willing to spread this malware, the numbers add up pretty quickly.

  • Understanding Current Trends in the Fake Anti-Virus/Scareware Ecosystem
    The cyber-criminal groups behind fake anti-virus (scareware/rogueware) infections have run into some significant roadblocks over the last few years, but there is much more to the overall story.


    Some groups have been arrested. Some have had their operations and entire call support centers
    shut down.

    Some groups attracted too much attention, picked off
    the low hanging fruit and eventually walked away from their botnets.

    In some cases, the groups just weren't very skilled
    at developing anti-anti-malware techniques, blackhat SEO, and malware distribution. They couldn't keep up with the changes in anti-malware technologies,
    weren't exactly dedicated
    to the effort, and simply fell off the map.


    However, some of the remaining scareware distribution gangs upped the ante and are aggressively developing difficult-to-detect polymorphic installers and difficult-to-remove support components. And the newest of these malware components include some of the first ITW 64-bit malware components to be taken seriously. But, for the most part, the scareware program itself remains the same. The development continues to change and progress, all for the purpose of evading anti-malware solutions and helping coerce the end-user to pay for the fake product, including support/rootkit components like TDSS (and its extreme complexities) or the more recent Black Internet (also known as "Trojan-Clicker.Win32.Cycler") support/rootkit components. These complex Mbr infectors and other rootkit components meant to maintain money-making scareware on the system are signs of this somewhat extreme development effort.

  • The Winlock case - I'm taking bets!

    Interesting news on Trojan SMS Blockers (Winlock etc). These programs block Windows and demand a ransom in the form of a text message which is sent to short number for a fee. It's a very popular type of racket at the moment, both in Russia and a few other countries.


    The whole affair has now reached the General Prosecutor’s office of Russia – the criminals have been identified and detained (or so it seems) and will be prosecuted in Moscow soon.

    Altogether the criminals have earned an estimated 790,000 roubles, or $25K. Moreover, they have caused other damages by blocking or crashing a yet to be determined number of personal and company PCs. Very often people have needed to re-install the OS and all software and then restore data from backups - even after paying the ransom.




    But I wanted to focus on the outcome – or the possible outcome of this incident, not on the investigation, arrests and so forth.

 
SpywareGuide Articles
Articles on Spyware, Adware, Malware and privacy in general
SpywareGuide Articles
  • DATA-THEFT WORM TARGETING GOOGLE'S ORKUT
    FaceTime Security Labs announced the discovery of a worm that steals users? banking details, usernames and passwords. The worm, known as MW.Orc, is propagating through Orkut, Google?s social networking site, as users launch an executable file disguised as a JPEG. Google has a temporary fix in place
  • The Digital Underground: Interview with RinCe
    This is Part TWO of a series of write-ups focusing on the recent threat to E-Commerce systems via potential IM (Instant Messaging) attack vectors and more besides, by way of a remotely installed administration tool and custom-built scripts, designed to find vulnerabilities in third-party payment sys
  • Property Values, Satellite Maps and Zillow
    A new service called Zillow allows you to easily access the value of your home...and your neighbors and even their neighbors. SpywareGuide articles are sponsored by FaceTime Communications, providing solutions for securing and controlling IM, P2P and Spyware Greynets.
vScan.com - Virus Scanning information, Malware Removal, Spyware Removal
Back Up Your Computer Data PDF Print E-mail
Submitted by:  Carol Smith
 
Have you backed up the data on your computer recently? Many people will answer no to this question. They don't think they need to, they think they haven't got time or they simply haven't thought about the personal or professional consequences of losing all their documents photos and emails.
Read more...
 
What is Identity Theft? PDF Print E-mail
Submitted by: Connie Barker
 
If you have been keeping up to date on current events one of the largest increases in crime can be attributed to identity theft. Identity theft is a term used for a type of crime that involves a hacker or thief stealing your personal and/or sensitive information to commit fraud or crimes. In most cases, identity theft involves stolen credit cards, stolen social security numbers and other forms of data that can be used for theft and fraud.
Read more...
 
What Are The Differences Between Adware And Spyware? PDF Print E-mail
By: Salihu Ibrahim

You may think adware and spyware are the same thing, but there are plenty of differences between the two of them. Since most people use the computer for personal access to the internet and their accounts, you need to do all you can to protect them. There are plenty of people trying to make an easy buck online by taking advantage of those accessing the internet. Don’t let them get access to your information through adware or spyware.

Advertising is everywhere you turn online these days, and that is where the issues of adware and spyware come into play. Adware is generally found in pop ups and it will track your internet use. As a result you will get redirected to sites that offer products for you to purchase. You will also get more and more pop ups until they have completely ruined the chance for you to be online without interruptions.

Read more...
 
Computer Security - Tips For Safe Public PC Use PDF Print E-mail

Submitted By: Deepesh Agarwal

In the new computer age, We don't always log on from home where our PC's are thoroughly protected. (You took care of that already, right?) Cyber cafes, libraries, airports, hotels and other places offer use of a public terminal for those on the go. But, unfortunately, those computers may not always get secured well nor checked regularly. And, since others use them, they can get infected only minutes before it's your turn.

Here are a few tips for how to protect your information while using a public computer.

Read more...
 
Free Security Programs - The Right Price For Computer Safety PDF Print E-mail


By: Darrin Johnson

While you may think that security software for your computer is expensive, a number of developers have made some of their versions available over the Internet for free. Hard to believe, but true.

Instead of purchasing expensive security software packages that have more fire power than what a typical consumer might ever use, you can find simpler versions that can be downloaded for free from certain sites.

Read more...