Attacks/Breaches
5/28/2010
03:23 PM
50%
50%

Feds Bust 'Scareware' Ring

Three men allegedly used fake antivirus warnings and advertisements to sell $100 million worth of bogus software.

Users -- inadvertent or otherwise -- of Malware Alarm, Antivirus 2008, VirusRemover 2008, or similar non-products may soon have their day in court.

On Thursday, a federal grand jury in Chicago indicted three men -- one living near Cincinnati, Ohio, and two believed to be abroad -- on charges of using fake advertisements to deceive consumers into thinking their PCs had suffered a virus, malware, or performance hit.

According to the indictment, this so-called “scareware” racket allegedly helped their company, Belize-registered Innovative Marketing, to sell over one million bogus products, priced at $30 to $70, to victims in 60 countries, generating over $100 million in revenue.

A subsidiary, Innovative Marketing Ukraine, located in Kiev, apparently closed up shop last year, after the Federal Trade Commission filed a federal lawsuit against it in Maryland.

The indictment also charges the men, Bjorn Daniel Sundin, Shaileshkumar P. Jain and James Reno, with operating a Belize-registered company called Innovative Marketing, which provided software which either didn’t do anything, or which would only partially fix the defects it had identified, which didn’t even exist in the first place.

The indictment further alleges that the men used deceptive shopping cart screens and hidden checkboxes to trick victims into purchasing multiple products, and that they also instructed representatives at the company’s Byte Hosting Internet Services call centers to lie to consumers, encourage them to remove legitimate antivirus software, or offer refunds to discourage them from notifying their credit card companies or authorities.

According to the indictment, the accused also created fake advertising agencies -- with names such as BurnAds, UniqAds, and ForceUp -- to place malicious banner advertisements on legitimate sites. These banners ads would surreptitiously hijack browsing sessions, redirecting users to websites allegedly run by Sudin and Jain. Displaying multiple error messages, the sites warned consumers that they should purchase various products distributed by Innovative Marketing.

Unfortunately, this type of scareware is a fast-growing scam. “The alleged scheme is widely regarded as one of the fastest-growing and most prevalent types of Internet fraud,” according to the Department of Justice.

Sudin and Jain have each been charged with 26 counts of wire fraud, Reno with 12 counts, and all with computer fraud. Each wire fraud count carries a maximum penalty of 20 years in prison, a $250,000 fine and mandatory restitution.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
8 Key Building Blocks for Enterprise Network Defense
Networks are changing rapidly -- and so are strategies for protecting them. This Tech Digest looks at the fundamentals for the next-gen environment.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In this episode of Dark Reading Radio, veteran CISOs will share their experience and insight into how organizations can get the best bang for their security buck.