Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

Guest Blog // Selected Security Content Provided By Sophos
What's This?
4/9/2009
08:28 AM
Graham Cluley
Graham Cluley
Security Insights
50%
50%

Hackers Launch Fake Conficker Antivirus Attacks

With all the focus on the Conficker worm in recent weeks, it should come as no surprise at all to find that cybercriminals are taking advantage of the headline-grabbing worm for their own ends.

With all the focus on the Conficker worm in recent weeks, it should come as no surprise at all to find that cybercriminals are taking advantage of the headline-grabbing worm for their own ends.Evidence of this can be seen in a malicious spam campaign, intercepted by experts at SophosLabs, which poses as a security warning from Microsoft's security department.

The email messages tell the unsuspecting user that "Microsoft has been alerted by your Internet company that your system is showing signs of infection," and advising that a security check is run on the computer:

Of course, clicking on the link contained inside the email is a very bad idea, especially for anyone who can't resist acting on the following message:

Yes, you've guessed it. This is another example of a fake antivirus or scareware attack, designed to frighten users into parting with their hard-earned cash by displaying bogus security warnings. The free scan will claim to find malware on your computer, and then scare you into purchasing a "remedy" from the hackers.

The irony is that the more we teach computer users about the importance of information security and raise their awareness of Internet threats, the greater the temptation for the hackers to take advantage of their heightened awareness by scaring people into spending money unnecessarily.

And if the hackers are prepared to use dishonorable means to display their bogus warnings in the first place, then how can you feel confident they won't do something illegal with your credit card if you do buy their "clean-up" software?

Graham Cluley is senior technology consultant at Sophos, and has been working in the computer security field since the early 1990s. When he's not updating his other blog on the Sophos website you can find him on Twitter at @gcluley. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19767
PUBLISHED: 2019-12-12
The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19768
PUBLISHED: 2019-12-12
In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).
CVE-2019-19769
PUBLISHED: 2019-12-12
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).
CVE-2019-19770
PUBLISHED: 2019-12-12
In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file).
CVE-2019-19771
PUBLISHED: 2019-12-12
The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.