ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Search poisoning, again

highMalwareimportance 42
Full article242 words · extracted from securelist.com · click to collapse

Incidents

Incidents

15 Jan 2010

minute read

Another day, another disaster, this time a big earthquake on Haiti, and once again, the bad guys are exploiting this subject to poison search results so that those looking for some news get lead to a page offering a rogue AV solution. We’re detecting this rogue software, and all its variants, as UDS:DangerousObject.Multi.Generic.

Our colleagues at Sunbelt Software have identified more than 50 search items used on search engines to lead the user to a malicious page. This isn’t exclusive to Google – Yahoo! results also are affected by the same trick:

Another interesting fact is you only get redirected to the malicious page offering the rogue AV if the referral link originated in a search engine page. If you try to directly access the URL, you’ll see a clean page:

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/search-poisoning-again/30608/