By Jennifer LeClaire TechNewsWorld Part of the ECT News Network
05/31/06 10:50 AM PT
"In many cases, adware is a legitimate revenue source for companies that offer software free to users," Ken Dunham, senior engineer at iDefense, told TechNewsWorld. "Unfortunately, it's being abused for criminal gain. It has digressed into an environment where hackers are using it on a daily basis."
Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!
A new spyware program called DigiKeyGen is luring the unwary with a claim to provide free access to online pornographic content. It's hardly a new tactic, but Panda Software has discovered yet another instance of this time-tested social engineering ploy.
DigiKeyGen is found on a Web page that allows visitors to download a password generator in order to access adult resources that users would normally have to pay for. When users run DigiKeyGen, they receive passwords that supposedly allow them access to pornographic Web sites.
At the same time -- and unknown to the victim -- a spyware program and an alleged anti-spyware application are installed on the computer. Users are then warned that their computer is infected and offered an anti-spyware program to clean the system for US$49.95.
Be Very Suspicious
Panda has discovered that DigiKeyGen can be downloaded from other Web sites offering adult content in addition to the program's official page. "You must always be suspicious of offers for something in exchange for almost nothing," warned Luis Corrons, director of Panda Software Labs.
"Cybercrime, which aims to make easy money, simply applies traditional fraud techniques to the Internet, and as a result, anybody tempted by the chance to get something for nothing is taken in, unaware of the risks of apparently harmless actions such as downloading small programs or accessing certain Web sites," Corrons noted.
Where the Money Is
Spyware is on the rise. In fact, many hackers are choosing to deploy spyware instead of installing backdoor Trojans or executing denial of service attacks, because there is so much money to be made and so little risk.
"In many cases, adware is a legitimate revenue source for companies that offer software free to users," Ken Dunham, senior engineer at iDefense, told TechNewsWorld. "Unfortunately, it's being abused for criminal gain. It has digressed into an environment where hackers are using it on a daily basis."
In the case of DigiKeyGen, the malware writers are cashing in by selling anti-spyware programs. Worldwide revenue for the anti-spyware market combined is expected to grow from $214 million in 2006, to $1.4 billion in 2010, according to the Radicati Group. The only problem is, malware writers' spyware typically doesn't work. They just take the money and run.
Proceed With Caution
The technique used in the DigiKeyGen case is not new. Other alleged anti-spyware programs detected in the past, such as RazeSpyware or SpySheriff, also used the same lure as DigiKeyGen -- offering to clean nonexistent spyware, or spyware installed with user consent, for a modest fee.
"Even users with sound IT knowledge could drop their guard with offers like this," Corrons added. "It is essential to be cautious of irresistible offers in the Internet. Users should leave the task of deciding whether or not a program is malicious to an anti-malware solution."
Hackers Target University Computer Assets May 30, 2006
Colleges identified security as the most critical issue facing their computer systems for the first time in seven years, according to a survey of about 600 colleges released this month by Educause, a nonprofit group that promotes information technology use. In a 2000 survey, security wasn't even among the top five concerns.
Related Stories
First Mac OS X Worm Shows Up February 17, 2006
The Leap-A worm itself is not a major threat, says Sophos senior technology consultant Graham Cluley. In fact, it may prove to be a welcome development if it prods more people to install and update their security software. "Mac users cannot keep thinking that they are invulnerable to these threats," he warns.
Porn Worm Set to Execute Nasty Payload on Friday January 30, 2006
There is concern surrounding the W32/Nyxem worm because of reports that have surfaced indicating that it can disable a keyboard and mouse and force a restart function immediately after infection. During this process, it creates several Windows registry key values to cause an included OCX file to be trusted.
Security Firms Warn of Looming Sober Worm Threat December 09, 2005
Overall, Sober worms are seen as the leading Web-based security threat during 2005. Security firm Sophos Inc. identified the Sober-Z variant as the most prevalent complaint during November.
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.