Who's Serving Up the Most Malware? Google

Updated CatRambo 0 Tallied Votes 677 Views Share

Security company has named Google the "king of malware," in that shows the popular search site linking to twice as many malware sites and files as its chief competitors, Bing, Twitter, and Yahoo combined.

Barracuda points to a growing need for online reputation checks as user-generated content becomes more and more popular. 88 billion searches per month appear on Google, which served up 69% percent of the malware appearing on the Internet, next to Yahoo's 18%, Bing's 12%, and Twitter's 1%. The most popular categories for malware were: spyware, entertainment, search-engines-portals, hosting-sites, peer-to-peer, business, proxies, shopping, and computing-technology while the top ten terms included the name of a NFL player, three actresses, a Playboy Playmate and a college student who faked his way into Harvard.

Malware distributors rely on tracking topics that are trending on search engines, and Google is quick to pick up trending topics, which may account for the large amount of malware appearing on it. Another possible reason may be its large market share.

Barracuda also examined Twitter in detail, looking at its "crime rate," the number of accounts being suspended. Looking at this rate provides insight into the current efforts of spammer to use the social networking service.

The company says new dangerous websites have increased by 5.6 percent since April, with 23% of company security breaches coming from employees who accessed personal web-based mail accounts.

Dani AI

Generated

As noted, a third‑party report drew attention to search engines and social feeds as common delivery channels for malware. That outcome usually reflects attacker tactics and web dynamics rather than deliberate behavior by a search provider: attackers tailor content to trending queries, compromise or spoof legitimate sites, use short‑lived domains and redirect chains, and amplify links on social platforms so they get indexed and clicked quickly.

Common techniques seen in these incidents include SEO poisoning (pages stuffed with hot keywords that redirect to malware), compromised content on otherwise reputable hosts, fast‑flux/throwaway domains to evade takedown, and social amplification via shortened links and trending tags. Large engines index enormous volumes and favor fresh content, so newly created malicious pages can surface faster there.

Recommended quick checks and mitigations:

  • Inspect the full domain before following a result; hovering reveals the actual target.
  • Favor official/known domains and avoid unexpected executable downloads from search snippets.
  • Verify suspicious URLs with a reputable URL‑scanner before opening, and open unknown binaries only in an isolated VM or sandbox.
  • Keep browsers, plugins, and endpoint anti‑malware up to date and disable automatic execution of downloaded files.
  • Use reputation‑based filtering and the search engine’s safe‑browsing features where available.

Operational defenses for organizations:

  • Enforce web‑proxy filtering with URL reputation and category blocking, and log DNS/HTTP for anomaly detection.
  • Apply least‑privilege on endpoints and consider browser isolation for untrusted web content.
  • Couple technical controls with regular phishing/malware awareness and an incident playbook for fast takedown requests.

A single report is a snapshot. Combining careful user habits, layered technical controls, and good logging/speedy response is the practical way to reduce risk from search‑surfaced malware.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.