madison

Zero Day

Ryan Naraine and Dancho Danchev

Cybercriminals promoting malware-friendly search engines

By | May 7, 2009, 8:14am PDT

Summary: The cybercriminals behind the ongoing blackhat search engine optimization attacks hijacking swine flu related queries in order to serve scareware, have re-introduced an old social engineering tactic - the use of fake and malware friendly search engines. Researchers from PandaLabs have recently uncovered a similar malicious search engine part of the blackhat SEO campaign, where the [...]

The cybercriminals behind the ongoing blackhat search engine optimization attacks hijacking swine flu related queries in order to serve scareware, have re-introduced an old social engineering tactic - the use of fake and malware friendly search engines.

Researchers from PandaLabs have recently uncovered a similar malicious search engine part of the blackhat SEO campaign, where the majority of searches lead to malware serving sites.

Three of the legitimately looking search engines have been in operation since January, 2009, and are operated by the same group of cybercriminals whose blackhat search engine optimization practices are so successful, that according to publicly obtainable traffic data two of the sites have already passed the 250,000 unique visitors benchmark in March, 2009.

The first one has approximately 257,512 unique visitors +63.64% increase since last month, followed by the second one which has approximately 279,665 unique visitors with a +64.26% increase since last month, and the third one is apparently lacking behind with 39,175 unique visitors, a +22.63% increase since last month.

Where is all that traffic coming from? 60.08% of the traffic to the first one came from Google,  12.87% of the traffic to the second one came from Google, and 26.55% of the traffic to the third one also came from Google. Google is appearing on the top of the their (approximate) traffic referrers due to the active blackhat SEO campaigns hijacking traffic from the search engine.

Interestingly, the search engines themselves are not visible in Google’s results, an evasive practice applied by the cybercriminals who only serve malicious content to users visiting their sites upon clicking on a link from a pre-defined search engine where the blackhat SEO campaigns are active, in this case - Google, MSN, Yahoo, Comcast and AOL.

Upon following a sample link from the phony search engines, we’re redirected to domains operated by services that have been in the cybercrime-facilitating neighborhood for years, on further redirect to scareware (Trustedwebsecurity; Spyware Cease) and online casino scams. From instance, searchadv.com, which was serving WMF (Windows Metafile) exploits in 2006 to users searching through it, and 7search.com, a Pay Per Click Search Engine Advertising network :

“7Search.com has been a leading Pay Per Click Search Engine Advertising and Affiliate Network since our inception in 1999. As a Search Engine who is dedicated to value and service for online businesses, 7search.com provides thousands of Web entrepreneurs with an economical and measurable opportunity to obtain Internet traffic and generate revenue through their online presence.”

The company sued McAfee in 2008 for labeling it as a spyware and potentially dangerous site, which isn’t the first, and definitely not the last time when affiliate networks attempts a frontal attack against vendors/researchers.

The use of these fake and malware-friendly search engines demonstrates the complexities of the cybercrime ecosystem, due to the double-monetization approach applied by the cybercriminals, earning pay per click revenue from the affiliate networks, and earning more revenue from serving search results serving scareware and pharmaceuticals with their own affiliate code.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Talkback Most Recent of 10 Talkback(s)

  • RE: Cybercriminals promoting malware-friendly search engines
    Well done! Thank you very much for professional templates and community edition
    seslisohbet seslichat
    ZDNet Gravatar
    birumut
    2nd May
  • RE: Cybercriminals promoting malware-friendly search engines
    thanks for your hardwork doing this lists... replica watches
    ZDNet Gravatar
    lovedong
    13th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
    ZDNet Gravatar
    MACKENZI
    11th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
    ZDNet Gravatar
    PEARLINEI
    12th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
    ZDNet Gravatar
    RHIANNONA
    13th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
    ZDNet Gravatar
    SATURNINA
    14th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
    ZDNet Gravatar
    TOCCAR
    25th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    Thanks nice info z d n e t I really liked your current article write more..let me add you to its favorite The articles you have on zdnet s i t e are always so enjoyable to read. Good work and I bookmarked it.
    ZDNet Gravatar
    MCKNIGH
    26th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
    ZDNet Gravatar
    MEJIAHA
    30th Sep
  • RE: Cybercriminals promoting malware-friendly search engines
    Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
    ZDNet Gravatar
    FAULKNE
    13th Oct

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
Click Here

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources