Search poisoning, again
Full article242 words · extracted from securelist.com · click to collapse
Another day, another disaster, this time a big earthquake on Haiti, and once again, the bad guys are exploiting this subject to poison search results so that those looking for some news get lead to a page offering a rogue AV solution. We’re detecting this rogue software, and all its variants, as UDS:DangerousObject.Multi.Generic.
Our colleagues at Sunbelt Software have identified more than 50 search items used on search engines to lead the user to a malicious page. This isn’t exclusive to Google – Yahoo! results also are affected by the same trick:
Another interesting fact is you only get redirected to the malicious page offering the rogue AV if the referral link originated in a search engine page. If you try to directly access the URL, you’ll see a clean page:
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/search-poisoning-again/30608/