Conficker business model: Scareware and spam
The Conficker botnet has started to use its peer-to-peer communication system to update itself and download scareware (fake anti-virus programs) to millions of infected Windows machines, according to malware hunters tracking the threat.
The latest Conficker mutant comes a week after a heavily-hyped April 1st activation date and provides the first sign of the motivation behind this malware threat — financially motivated cybercrime.
[ RELATED: Honeynet Project finds way to fingerprint Conficker infections ]
Editor's Pick
According to my colleague at Kaspersky Lab Alex Gostev, Conficker now has a business model linked to scareware/fraudware, which means that millions of Conficker-infected machines will start getting pop-ups pushing a fake $49.95 security scanner.
One of the files is a rogue anti-virus app, which we detect as FraudTool.Win32.SpywareProtect2009.s. The first version of Kido (Conficker), detected back in November 2008, also downloaded fake antivirus to the infected machine. And once again, six months later, we’ve got unknown cybercriminals using the same trick.
The rogue software, SpywareProtect2009, can be found on spy-protect-2009.com., spywrprotect-2009.com, spywareprotector-2009.com.
At the moment, the rogue anti-virus comes from sites located in Ukraine, Gostev said. Mozilla Firefox is blocking access to the scareware sites.
[ RELATED: There will be no April 1st Conficker outbreak ]
Gostev also found the latest version of Conficker downloading the Waledac e-mail worm onto the infected systems. Waledac is a known botnet linked to data theft and e-mail spam campaigns.
Also see the Techmeme discussion on the latest mutant.
Commenting on this Article is closed.
Today's Most Popular
- Yahoo Includes Private Key in Source File For Axis Chrome Extension
- Researchers Unveil New Way to Trust Certificates
- DNSChanger Lingers: 330k Systems Still Infected, 77,000 In The U.S.
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Common Firewall Feature Enables TCP Hijacking Attacks
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (10)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (12)
-
Facebook Cancellation Malware Disguised As Adobe Update Making Rounds (3)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (4)
-
Iranian Students Claim to have Stolen Thousands of Researcher's Records (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



