Latest news
The bots are controlled remotely through several Web servers. This allows the perpetrators to define, for example, the web pages on which the adverts are hosted or the maximum number of clicks from any one IP address in order not to arouse suspicions. Similarly, the number of clicks from the bot can be monitored as well as the computers online at any one time. The system used can evade fraud detection systems by sending click requests from different, unrelated IP addresses.
“Renting and selling of botnets has become a genuine business model for cyber-crooks. The scam we have now uncovered exploits infected systems to generate profits through ‘Pay per Click’ systems, instead of by installing spyware sending spam,” explains Luis Corrons, director of PandaLabs. “Given the proliferation of these networks, it is highly advisable for users to scan their systems with fully up-to-date anti-malware solutions, as bots like those involved in this case can be perfectly concealed on computers”.
The Clickbot.A mechanism consists of two parts. The first is an executable file that launches a dynamic link library on the system, which later deletes itself. The second is a component of Internet Explorer that notifies the attacker that computer is infected, even allowing the control components to be updated. The bot then registers in the database of the control system, checking that the creator has given authorization to start clicking, and if so, will request the list of addresses from which to click.
Bots represent one of the fastest growing threats on the Internet, given that they adapt perfectly to the new malware dynamic in which threat creators are no longer searching for notoriety, but for financial returns. With this in mind, they try to ensure their creations are installed without arousing the suspicions of users or security companies.
“The current situation requires the use of proactive technologies, which can detect unknown threats by examining their behavior and complements traditional antivirus products. For example, our TruPrevent proactive technologies have detected more than 46,000 examples of new malware since first released in 2004,” adds Corrons.


Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





