---
Email this article   Print article 

'Super Bowl' Key Term In Poisoned Google Searches

By Stefanie Hoffman, CRN
February 08, 2010    3:49 PM ET

Cybercriminals are using key search terms such as "2010 Super Bowl" by placing malicious sites at the top of the Google search pages to infect visitors' computers with malware.

Thus far, more than 15 percent of the top 20 Google search sites related to the 2010 Super Bowl are actually malicious sites designed to download malware onto visitors' computers, according to researchers at SonicWall, who first detected the malicious sites.

Fake Anti-Virus Scam

The malware sites impersonate legitimate sites that appear to offer news or videos on the 2010 Super Bowl, and are ranked at the top of the search result pages in order to further convey authenticity. However, once opened, the malicious site attempts to persuade users to purchase fake antivirus software by impersonating a Windows security application. The application then offers to conduct a phony virus scan that produces fake positives.

Instead of downloading antivirus software, users are actually installing a Trojan designed to take control of their computer and incorporate their system into a larger botnet.

Poisoned Google Search Terms

"These sites are injected or poisoned with malware," said Nick Bilogorskiy, manager of antivirus research at SonicWall. "They pretend to scan your computer, and they always find some result. Then they charge you to use their antivirus software."

Bilogorskiy said that the sites appeared to come from the same criminal organization. And while the malware doesn't automatically exploit a vulnerability or instantly infect users, the same pop-up will repeatedly attempt to force the user to install the malicious software, he said.

"If you're smart, you'll close the browser," Bilogorskiy said. "If you end the program, you can get out of it and not get infected."

Meanwhile, a regular antivirus program will likely not be enough to protect users. Bilogorskiy said that the cybercriminals update malware frequently, while continually staying apprised of which AV vendors have produced signatures for the threats.

To protect themselves, users need to exercise caution, and avoid downloading unsolicited software, even if it appears legitimate. "Users need to be informed of this attack and exercise caution when browsing," he said. "In general, just use safe computing practices and just don't install programs that you're not sure of."

To continue reading this article, please download the CRN Tablet Edition app from the iPad App store.

SHARE THIS ARTICLE

More Security

Recent Articles

Bit9 Security Survey: Nobody Wants To Be A Headline

What's keeping IT security professionals awake at night? These survey results provide insight into perceived threats and vulnerabilities, the effectiveness of security practices, and opinions about disclosure practices.

Nix That Click: Six Scareware Scams To Watch Out For

SpywareRemove.com provides a list of some of the nastiest rogue antispyware programs out there -- designed to trick people into paying to remove malware from their computers.

Malicious Malware: Six Ways Cybercriminals Beat Security

Cybercriminals have become adept at going around the latest security defenses. Here's a list of some of the most innovative malware in use today.

  More Slide Shows




Related Videos
Loading...