Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Fake Windows XP Activation Trojan Wants Your CVV2 Code
October 7, 2008 00:01

    
In a self-contradicting social engineering attempt, a malware author is offering to sale a (updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "We will ask for your billing details, but your credit card will NOT be charged", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.

Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders.

Moreover, according to recently reseased survey results, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008? The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services?

The increase of rogue security software domains is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.

All news for November 19, 2008
  19:33  Schneier on Security: RIAA Lawsuits May Be Unconstitutional
  16:00  Dancho Danchev: The DDoS Attack Against Bobbear.co.uk
  12:14  Schneier on Security: Skein and SHA-3 News
  10:15  Dancho Danchev: New Web Malware Exploitation Kit in the Wild
  04:19  Martin McKeay: Network Security Podcast, Episode 128

All news for November 18, 2008
  19:57  Dancho Danchev: Will Code Malware for Financial Incentives
  19:46  Schneier on Security: Schneier for TSA Administrator
  16:34  Jeff Jones Security Blog: SIRV5 Vulnerability Trends Webcast - 2 of 2 - Microsoft Trends
  12:32  Schneier on Security: The Neuroscience of Cons

All news for November 17, 2008
  11:11  Schneier on Security: Most Spam Came from a Single Web Hosting Firm

All news for November 16, 2008
  03:00  Martin McKeay: Congratulations to April and Jason
Keywords: fake, windows, xp, activation, trojan, wants, your, cvv2, code

All news for November, 2008


All news for 2008