Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Feds Bust 'Scareware' Ring

Three men allegedly used fake antivirus warnings and advertisements to sell $100 million worth of bogus software.

Users -- inadvertent or otherwise -- of Malware Alarm, Antivirus 2008, VirusRemover 2008, or similar non-products may soon have their day in court.

On Thursday, a federal grand jury in Chicago indicted three men -- one living near Cincinnati, Ohio, and two believed to be abroad -- on charges of using fake advertisements to deceive consumers into thinking their PCs had suffered a virus, malware, or performance hit.

According to the indictment, this so-called “scareware” racket allegedly helped their company, Belize-registered Innovative Marketing, to sell over one million bogus products, priced at $30 to $70, to victims in 60 countries, generating over $100 million in revenue.

A subsidiary, Innovative Marketing Ukraine, located in Kiev, apparently closed up shop last year, after the Federal Trade Commission filed a federal lawsuit against it in Maryland.

The indictment also charges the men, Bjorn Daniel Sundin, Shaileshkumar P. Jain and James Reno, with operating a Belize-registered company called Innovative Marketing, which provided software which either didn’t do anything, or which would only partially fix the defects it had identified, which didn’t even exist in the first place.

The indictment further alleges that the men used deceptive shopping cart screens and hidden checkboxes to trick victims into purchasing multiple products, and that they also instructed representatives at the company’s Byte Hosting Internet Services call centers to lie to consumers, encourage them to remove legitimate antivirus software, or offer refunds to discourage them from notifying their credit card companies or authorities.

According to the indictment, the accused also created fake advertising agencies -- with names such as BurnAds, UniqAds, and ForceUp -- to place malicious banner advertisements on legitimate sites. These banners ads would surreptitiously hijack browsing sessions, redirecting users to websites allegedly run by Sudin and Jain. Displaying multiple error messages, the sites warned consumers that they should purchase various products distributed by Innovative Marketing.

Unfortunately, this type of scareware is a fast-growing scam. “The alleged scheme is widely regarded as one of the fastest-growing and most prevalent types of Internet fraud,” according to the Department of Justice.

Sudin and Jain have each been charged with 26 counts of wire fraud, Reno with 12 counts, and all with computer fraud. Each wire fraud count carries a maximum penalty of 20 years in prison, a $250,000 fine and mandatory restitution.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
7 SMB Security Tips That Will Keep Your Company Safe
Steve Zurier, Contributing Writer,  10/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: The old using of sock puppets for Shoulder Surfing technique. 
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17513
PUBLISHED: 2019-10-18
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.
CVE-2019-8216
PUBLISHED: 2019-10-17
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
CVE-2019-8217
PUBLISHED: 2019-10-17
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
CVE-2019-8218
PUBLISHED: 2019-10-17
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
CVE-2019-8219
PUBLISHED: 2019-10-17
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .