Digg.com Spreads Malware Trough Comments on Christian Bale, Megan Fox or Jessica SimpsonBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Our Partners
Downloads
Adware - Spyware : Digg.com Spreads Malware Trough Comments on Christian Bale, Megan Fox or Jessica Simpson
Posted by Max on 2009/2/16 11:06:48 (1175 reads)
Adware - Spyware

Cyber-criminals are using accounts that are likely stolen to post comments with links supposedly pointing to videos of celebrities such as Christian Bale, Megan Fox or Jessica Simpson. Users that try to watch these videos will be asked to download a codec. This codec, however, is just a copy of VideoPlay adware.

PandaLabs, Panda Security's malware analysis and detection laboratory, has just released research with evidence proving that Digg.com (www.digg.com), the popular news aggregation service, is being used by cyber-criminals to distribute VideoPlay adware. Criminals execute their attacks by leaving comments on news items related to celebrity videos. On a first analysis, PandaLabs has detected more than 50 profiles leaving these types of comments on Digg.com.

Examples of such comments include:

    * "Christian Bale freak out dubbed with video!"
    * "Jessica Simpson Hotel Sex Tape"
    * "Megan Fox naked NEW SEX TAPE"

These comments include a link claiming to redirect users to the video. Users that click the link are redirected to a page where they are asked to download a codec in order to see the video. If they do so, the adware VideoPlay will be downloaded onto their computers.

VideoPlay adware is in the same category of fake antivirus products. As with all such malware, VideoPlay is designed to run a fake scan of the computer as if it were an antivirus, convincing users that the system is infected with malware. To make its claims more believable, it prevents the system from operating correctly, furthering the impression that it is infected with several strains of malware. It then offers users the option to eliminate the malware using a pay version of the fake antivirus. The aim is obviously to profit from sales of this spoof security solution.

"The profiles used have probably been stolen from their owners, by stealing account passwords. This is another example of how cyber-crooks are using trusted Web 2.0 services to distribute malware", explains Luis Corrons, Technical Director of PandaLabs.

More information is available in the PandaLabs blog: http://bit.ly/zPuk. Images on Flickr are available here: http://bit.ly/LoOe

About PandaLabs
Since 1990, its mission has been to detect and eliminate new threats as rapidly as possible to offer our clients maximum security. To do so, PandaLabs has an innovative automated system that analyzes and classifies thousands of new samples a day and returns automatic verdicts (malware or goodware). This system is the basis of collective intelligence, Panda Security's new security model which can even detect malware that has evaded other security solutions.

Currently, 94 percent of malware detected by PandaLabs is analyzed through this system of collective intelligence. This is complemented through the work of several teams, each specialized in a specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc), work 24/7 to provide global coverage. This translates into more secure, simpler and more resource-friendly solutions for clients. More information is available in the PandaLabs blog: http://www.pandalabs.com and the Panda Security website: www.pandasecurity.com/usa




Other articles
2010/2/3 7:32:43 - PC Login Now (Full version) Available Now For Free.
2010/2/3 7:11:57 - Mitto Named One of 20 Top Web Applications
2010/1/19 15:53:17 - OpenVAS, the New Open Source Vulnerability Scanner
2010/1/7 5:40:00 - Beware of Rogue Antispyware Named Eco AntiVirus. It's a FAKE
2010/1/7 5:30:00 - Blue Coat's K9 FREE Web Filtering Product Expands to Windows 7
2010/1/6 5:40:00 - NEW Ares P2P Windows 7 Release. Official Release of The Popular P2P Program, Ares.
2010/1/6 5:20:56 - Top 10 Malware Threats for December Presented By Sunbelt Software
2010/1/6 4:53:11 - New Service Shows WHO Installed Spyware on Your PC
2010/1/6 4:45:28 - Overweight Adults Respond More To Weight Loss Spam E-mails
2009/12/30 12:34:17 - Novosoft Provides 20% Discounts and Holidays Gifts on Handy Backup. FREE LICENSES INSIDE !

The comments are owned by the poster. We aren't responsible for their content.