Welcome | Sign In
TechNewsWorld.com
Security

Scammers Target Googlers with Trojan Attack

Print Version
E-Mail Article
Reprints
Scammers Target Googlers with Trojan Attack

"This is a continuation of a trend of increasing spyware infection in the industry," Ed Moyle, president of SecurityCurve, told TechNewsWorld. "Spyware vendors ... are seeking ever-more invasive and aggressive ways of distributing their software.


Crystal Reports - Discover the Latest Innovations.
Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.

Prone to typos? Beware. Hackers have revived a once common scam in which they use a URL that contains a misspelled real site to spread malware. The latest targets Google (Nasdaq: GOOG) users with the misspelled "www.googkle.com."

Users can't check it out, even out of curiosity, anymore because it has already been taken down, Mikko Hypponen, director of anti-virus research, F-Secure, told TechNewsWorld.

In the past, users of MSN.com and CNN.com have also been targeted by scams like this. F-Secure, a security firm in Finland, first broke the news of the Trojan this week.

Wide Range of Malware

Hypponen said going to the site was quite dangerous because of the range of malware that resulted and the fact that it would be automatically downloaded to the PC of anyone who visited the malicious site.

"Your PC would completely automatically end up taken over by a wide variety of keyloggers and spyware," he said.

That malware includes Trojan droppers, program that drops Trojan horses or back door Trojans onto computers; Trojan downloaders, which secretly download more malware; backdoors, a proxy Trojan, an application that allows remote hackers to access the Internet through an infected computer; and a spying Trojan, which allows a hacker to monitor user's activities -- including keystrokes -- on an infected computer.

The scammers also included a few adware-related files. The site also blocked access to anti-virus updating.

Don't Fall Prey

Aside from double-checking all typing, Hypponen recommended using bookmarks or avoiding Internet Explorer to prevent accidental exposure to sites such at this one.

"This Web site, as well as a few related Web sites are owned by people with Russian names. Also several malicious files that are downloaded from these Web sites have Russian texts," F-Secure said on its site, adding that it had reported the scam to authorities.

The scam is a sign of the ever more invasive attempts by scammers to find a way into PCs, one analyst said.

"This is a continuation of a trend of increasing spyware infection in the industry," Ed Moyle, president of SecurityCurve, told TechNewsWorld.

"Spyware vendors, to keep pace with both users' increased awareness of spyware and the availability of software to protect against it, are seeking ever-more invasive and aggressive ways of distributing their software," he said. "I think it is only a matter of time before they ratchet the intrusiveness up to the next level."


Print Version E-Mail Article Reprints More by Susan B. Shor


Talkback: Join the Discussion.
Re: Scammers Target Googlers with Trojan Attack
cidViscous
Posted 2005-05-02
dear ms. ...
Re: Scammers Target Googlers with Trojan Attack
clayton
Posted 2005-05-03
Recently the idea of DNS poisoning and googkle.com type hacks are on the forefront of online ...

More by Susan B. Shor

Salesnet President Jonathan Tang Ready to Take On Salesforce.com
February 07, 2006
"We think it's Salesnet's time now. We've been around since the beginning, we've been lying low, but you're going to start to see more of us. We've done it through organic growth and happy customers. We continue to focus on customers."
Comcast Follows Time Warner in Offering 'Family' Programming Tier
December 23, 2005
"The demand for this type of tier is coming from the FCC and Christian conservatives. It has nothing to do with legitimate consumer demand," Todd Chanko, senior analyst at Jupiter Media, told the E-Commerce Times.
High-Risk Flaw Found in Symantec's Software
December 22, 2005
"Part of the significance of this vulnerability announcement is that your machine can be exploited without you needing to do anything at all. You don't even have to open an e-mail or attachment, and this happens with the default configuration of the product," said Forrester Research senior analyst Michael Gavin.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network