Attacks/Breaches
5/28/2010
03:23 PM
Connect Directly
RSS
E-Mail
50%
50%

Feds Bust 'Scareware' Ring

Three men allegedly used fake antivirus warnings and advertisements to sell $100 million worth of bogus software.

Users -- inadvertent or otherwise -- of Malware Alarm, Antivirus 2008, VirusRemover 2008, or similar non-products may soon have their day in court.

On Thursday, a federal grand jury in Chicago indicted three men -- one living near Cincinnati, Ohio, and two believed to be abroad -- on charges of using fake advertisements to deceive consumers into thinking their PCs had suffered a virus, malware, or performance hit.

According to the indictment, this so-called “scareware” racket allegedly helped their company, Belize-registered Innovative Marketing, to sell over one million bogus products, priced at $30 to $70, to victims in 60 countries, generating over $100 million in revenue.

A subsidiary, Innovative Marketing Ukraine, located in Kiev, apparently closed up shop last year, after the Federal Trade Commission filed a federal lawsuit against it in Maryland.

The indictment also charges the men, Bjorn Daniel Sundin, Shaileshkumar P. Jain and James Reno, with operating a Belize-registered company called Innovative Marketing, which provided software which either didn’t do anything, or which would only partially fix the defects it had identified, which didn’t even exist in the first place.

The indictment further alleges that the men used deceptive shopping cart screens and hidden checkboxes to trick victims into purchasing multiple products, and that they also instructed representatives at the company’s Byte Hosting Internet Services call centers to lie to consumers, encourage them to remove legitimate antivirus software, or offer refunds to discourage them from notifying their credit card companies or authorities.

According to the indictment, the accused also created fake advertising agencies -- with names such as BurnAds, UniqAds, and ForceUp -- to place malicious banner advertisements on legitimate sites. These banners ads would surreptitiously hijack browsing sessions, redirecting users to websites allegedly run by Sudin and Jain. Displaying multiple error messages, the sites warned consumers that they should purchase various products distributed by Innovative Marketing.

Unfortunately, this type of scareware is a fast-growing scam. “The alleged scheme is widely regarded as one of the fastest-growing and most prevalent types of Internet fraud,” according to the Department of Justice.

Sudin and Jain have each been charged with 26 counts of wire fraud, Reno with 12 counts, and all with computer fraud. Each wire fraud count carries a maximum penalty of 20 years in prison, a $250,000 fine and mandatory restitution.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-6651
Published: 2014-07-31
Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

CVE-2014-2970
Published: 2014-07-31
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5139. Reason: This candidate is a duplicate of CVE-2014-5139, and has also been used to refer to an unrelated topic that is currently outside the scope of CVE. This unrelated topic is a LibreSSL code change adding functionality ...

CVE-2014-3488
Published: 2014-07-31
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

CVE-2014-3554
Published: 2014-07-31
Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

CVE-2014-5171
Published: 2014-07-31
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.

Best of the Web
Dark Reading Radio