The high price of fake software

happygeek 0 Tallied Votes 336 Views Share

As someone who works within the IT Security space, I have to say that rogueware (also known as scareware) is starting to seriously hack me off. Not that I have ever been conned into purchasing it, I hasten to add, but rather because so many others have and so many people are making rather a lot of money as a result.

Rogueware, which can be loosely defined as any 'fake software solution' which separates unsuspecting users from their cash in order to fix non-existent problems, is increasing by a factor of ten in less than a year according to the chaps at PandaLabs. They have been watching the rogueware phenomenon very closely indeed, and have now published a multi-year study into the proliferation of rogueware into the overall cybercrime economy. The research report, The Business of Rogueware, reveals that:

  • Cybercriminals are earning approximately $34 million per month through rogueware attacks
  • Approximately 35 million computers are newly infected with rogueware each month
  • Rogueware is now being distributed through Facebook, MySpace, Twitter, Digg and targeted blackhat SEO attacks
  • And finally, a confirmation of something that many of us suspected anyway: the majority of these cybercriminals are operating from Eastern Europe

"Rogueware is so popular among cybercriminals primarily because they do not need to steal users’ personal information like passwords or account numbers in order to profit from their victims" said Luis Corrons, PandaLabs Technical Director. "By taking advantage of the fear in malware attacks, they prey upon willing buyers of their fake anti-virus software, and are finding more and more ways to get to their victims, especially as popular social networking sites and tools like Facebook and Twitter have become mainstream."

There are now approximately 200 different rogueware families, and in the first quarter of 2009 alone more new strains were created than in all of 2008. The second quarter painted an even bleaker picture, with the emergence of four times as many samples as in all of 2008. In Q309, PandaLabs estimates a rogueware total greater than the previous eighteen months combined.

Dani AI

Generated

The original observation from still rings true: fake "antivirus" and scareware are social‑engineering scams that trade on fear, and they never really went away. Modern scareware still looks like an urgent system alert or an impossible scan result, but delivery and scale have changed — law enforcement actions have nailed operators, yet the tactics remain profitable for criminals. (malwarebytes.com)

How these scams appear today: infected ads (malvertising), compromised sites, shortened links on social networks, or drive‑by redirects that show a fake scan and a demand to pay or call a number. Red flags are urgent language, unexpected payment requests, or pages that block normal browser controls. If a popup or site claims your machine is "infected," do not click, do not call any phone number shown, and close the page or terminate the browser process immediately. (microsoft.com)

If a machine is already affected: disconnect it from the network, boot to Safe Mode (or use rescue media), then run up‑to‑date removal tools. Microsoft’s removal utilities (MSRT / Safety Scanner / Defender Offline) are good first steps; follow with a dedicated anti‑malware scanner for PUPs and rogue AV (for example, Malwarebytes or another reputable second opinion). If removal fails or the system shows persistent tampering, restore from a known clean backup or seek professional help. Keep copies of logs and screenshots. (support.microsoft.com)

Practical prevention and recovery: keep OS, browser and plugins patched; run a reputable, always‑on AV; enable popup and content protections; avoid pirated/cracked software and unknown downloads. If money was paid, contact the card issuer immediately to dispute the charge, and report the scam to ReportFraud.ftc.gov and IC3 — also change credentials and monitor credit reports. Preserve receipts, emails, and screenshots as evidence. For enterprise or high‑risk environments, apply CISA’s hardening and ad‑filtering recommendations. (ftc.gov)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.