Free Newsletter
Register for our Free Newsletters
Access Control
Deutsche Zone (German Zone)
Education, Training and Professional Services
Government Programmes
Guarding, Equipment and Enforcement
Industrial Computing Security
IT Security
Physical Security
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor

Malicious code disguised as fake US election campaign videos

Webroot Software : 30 September, 2008  (Technical Article)
Following links to Obama or McCain videos propagated by e-mail leaves users prone to malicious code and the possibility of identity theft.
Webroot has detected malicious software being propagated as campaign videos for John McCain and Barack Obama. Hackers are taking advantage of unsuspecting users during the US Presidential election season by utilising the Gnutella file sharing network and seeding it with malware disguised as material relevant to the campaigns. This file sharing network is commonly accessed by clients such as LimeWire and FrostWire.

A search of the FrostWire network indicated that of the 34 search results for "Obama Speech" 14 contained active malware while five of the 19 results for "McCain Speech" were found to be harboring malware.

"Peer to peer networks pose some of the greatest security risks on Internet," said Paul Piccard, director, Threat Research, Webroot. "Because P2P networks lack the security measures found in enterprise networks or trusted Websites, users of these networks may put themselves or their companies at increased risk by downloading malicious content or leaking confidential data.'

The most common malware variant spreading through this method is W32/Zipwire. Users become infected with the malware after downloading a zip file with a name such as "Democratic Convention 2008 - Barack Obama Acceptance" The contents of these zip files contain executable files (such as Setup.exe). When run, these files infect the host machine with random malware, including rogue antivirus applications, which detect fake security issues on the infected machine in order to entice users to buy the rogue application for disinfection. Other malware threats such as password stealers and backdoors can be downloaded as well, which may give a hacker remote access to the infected machine or allow them to gather personal data such as usernames and passwords.

According to the Webroot Threat Research Center, this threat poses a number of different risks. For example, once infected the computer can be accessed remotely, which allows for the potential installation of new malware. These could include system monitors that spy on the user in an attempt to gather the information needed -including social security numbers, bank accounts, home addresses and more - to steal their identity.

"Webroot is focused on identifying emerging threats so that we can help consumers avoid being attacked and compromised," said Paul Lipman, Webroot's senior vice president and general manager of Consumer Business. "However, hackers are constantly evolving their attack vectors so it is essential for PC users to have best-in-class antispyware, antivirus and firewall software installed on their computers to ensure that their personal and confidential information is safe."

Webroot recommends several steps to users to prevent this type of malware attack:.

1) Always have a current version of antispyware, antivirus and firewall product.
2) Never download free product or purchase them from unknown Web sites and vendors, or peer to peer networks.
3) Never click on a link while visiting a peer to peer site.
4) Never purchase a product that is the result of an unknown alert.
5) Make sure the computer is up-to-date by always installing new Microsoft or Apple security updates.
6) Make it a point to check your credit through one of the credit bureaus.
7) Use a credit card that has sufficient fraud protection and never use a debit card online.
Bookmark and Share
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
   © 2012
Netgains Logo