Attacks/Breaches
5/28/2010
03:23 PM
50%
50%

Feds Bust 'Scareware' Ring

Three men allegedly used fake antivirus warnings and advertisements to sell $100 million worth of bogus software.

Users -- inadvertent or otherwise -- of Malware Alarm, Antivirus 2008, VirusRemover 2008, or similar non-products may soon have their day in court.

On Thursday, a federal grand jury in Chicago indicted three men -- one living near Cincinnati, Ohio, and two believed to be abroad -- on charges of using fake advertisements to deceive consumers into thinking their PCs had suffered a virus, malware, or performance hit.

According to the indictment, this so-called “scareware” racket allegedly helped their company, Belize-registered Innovative Marketing, to sell over one million bogus products, priced at $30 to $70, to victims in 60 countries, generating over $100 million in revenue.

A subsidiary, Innovative Marketing Ukraine, located in Kiev, apparently closed up shop last year, after the Federal Trade Commission filed a federal lawsuit against it in Maryland.

The indictment also charges the men, Bjorn Daniel Sundin, Shaileshkumar P. Jain and James Reno, with operating a Belize-registered company called Innovative Marketing, which provided software which either didn’t do anything, or which would only partially fix the defects it had identified, which didn’t even exist in the first place.

The indictment further alleges that the men used deceptive shopping cart screens and hidden checkboxes to trick victims into purchasing multiple products, and that they also instructed representatives at the company’s Byte Hosting Internet Services call centers to lie to consumers, encourage them to remove legitimate antivirus software, or offer refunds to discourage them from notifying their credit card companies or authorities.

According to the indictment, the accused also created fake advertising agencies -- with names such as BurnAds, UniqAds, and ForceUp -- to place malicious banner advertisements on legitimate sites. These banners ads would surreptitiously hijack browsing sessions, redirecting users to websites allegedly run by Sudin and Jain. Displaying multiple error messages, the sites warned consumers that they should purchase various products distributed by Innovative Marketing.

Unfortunately, this type of scareware is a fast-growing scam. “The alleged scheme is widely regarded as one of the fastest-growing and most prevalent types of Internet fraud,” according to the Department of Justice.

Sudin and Jain have each been charged with 26 counts of wire fraud, Reno with 12 counts, and all with computer fraud. Each wire fraud count carries a maximum penalty of 20 years in prison, a $250,000 fine and mandatory restitution.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-1793
Published: 2014-12-25
rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted SVG document that leads to a "stale pointer."

CVE-2011-1794
Published: 2014-12-25
Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ...

CVE-2011-1795
Published: 2014-12-25
Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document con...

CVE-2011-1796
Published: 2014-12-25
Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaS...

CVE-2011-1798
Published: 2014-12-25
rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown othe...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.