KMeth Worm Strikes Yahoo! Messenger Users, Targeting Google AdSense Program in Money Making Scheme
Posted on: Tuesday, 3 October 2006, 18:00 CDT
FOSTER CITY, Calif., Oct. 3 /PRNewswire/ -- Research experts at FaceTime Security Labs(TM), the threat research division of IM and greynet security leader FaceTime Communications, have discovered a new threat targeting Yahoo! Messenger users, known as the w32.KMeth worm. The new threat sends users to a Web site serving a barrage of Google AdSense advertisements related to mesothelioma, a rare cancer caused by exposure to asbestos. Because of its relation to toxic tort litigation, the cost-per-click for the keyword "mesothelioma" is one of the highest in the online advertising pay-per-click market, making it a prime target for financially-motivated malware writers. Systems are set up by these cyber-rogues to funnel traffic through illicit means, generating clicks on high-paying keywords to produce higher returns on established advertising commissions.
Unlike the typical worm that propagates when a user clicks on a link to an executable file contained in an instant message, w32.KMeth downloads malicious files into the user's Windows temporary file directory when a user simply visits an infection site using Internet Explorer. When the user visits the infected Web page, the malware uses the PC as a launch pad, immediately sending infection messages to the user's Yahoo! Messenger contacts. The "status message" in Yahoo! Messenger can also be also hijacked, presenting enticing messages to their contacts, such as "check out my blog." The use of this additional social-engineering technique is designed to encourage more visits to the rogue Web pages. At the same time, the user's control panel is disabled, and the home page is hijacked to a Web page that contains text designed to generate maximum revenue through click fraud.
"Typically, financially-driven malware attacks use botnets to fraudulently increase traffic to specific online advertisements," said Chris Boyd, director of malware research for FaceTime Security Labs. "In this case, the hackers have cleverly borrowed tactics from botnet-creators to create a bot-less network of hijacked PC users to drive traffic to sites populated with these specific Google AdSense advertisements. Introducing the human factor into the scenario makes these 'bot-less nets' much more difficult to detect."
Google AdSense is a convenient way for Web site publishers to earn money by displaying Google ads relevant to their Web site. Because Google pays the host Web site based on the number of clicks on their ads, the process can be susceptible to what is commonly called "click-fraud," or an inflated number of clicks on a given ad.
The cost-per-click for the term "mesothelioma" is among the highest in the online advertising industry, because searchers using the term are very likely to be seeking legal services. The cost-per-click ranges from $4 to $13 and higher on various keyword bidding networks.
The FaceTime research team offers a detailed accounting of the worm and the possible financial motives at http://blog.spywareguide.com/ .
Who is affected: Users of both Yahoo! Messenger and Internet Explorer Threat Type: Worm Risk Level: Medium How to protect against this threat
This malware has the potential to infect any user of Internet Explorer who visits the infected Web site, but is specifically targeted at users of Yahoo! Instant Messenger. Users can protect themselves by not clicking on links sent to them by other users or contained in Yahoo! Messenger status messages of those contacts on their contact list. Currently, most commonly used anti-virus programs do not provide protection from w32.KMeth.
Companies that use FaceTime Enterprise Edition and IMAuditor and have auto-update features activated are automatically protected against this threat. FaceTime also recommends activating the Day Zero Defense System within IMAuditor. The system utilizes anomaly detection techniques to analyze multiple characteristics of IM-borne worms and other malicious code against normal behavior, and provides patent-pending protection against many IM threats -- in addition to traditional security signatures. FaceTime RTGuardian customers are automatically protected if they have auto update features enabled. FaceTime's X-Cleaner customers (formerly XBlock) should download the latest update and scan their PC for the worm.
About FaceTime Communications
FaceTime enables the safe and productive use of greynets like instant messaging, VoIP, Web conferencing and P2P file sharing. FaceTime Security Labs delivers the industry's first IMPact Index, which assesses "point-in-time" risks posed by viruses, worms and other malware propagating through greynet applications. FaceTime's award-winning solutions are used by more than 800 customers, among them nine of the ten largest U.S. banks. FaceTime supports or has strategic partnerships with all leading public and private IM network providers, including AOL, Google, Microsoft, Yahoo!, IBM, Reuters, Bloomberg, and Jabber.
FaceTime is headquartered in Foster City, California. For more information visit http://www.facetime.com/ or call 888-349-FACE.
NOTE: FaceTime, FaceTime Communications, IMAuditor, RTGuardian, GEM, FaceTime Enterprise Edition, FaceTime Security Labs, IMPact Index, SpywareGuide.com, X-Cleaner and the FaceTime logo are registered trademarks and trademarks of FaceTime Communications, Inc. Other trademarks and registered trademarks are the property of their respective owners.
FaceTime Contact: Emily Chamberlin A&R Edelman 650-762-2945 echamberlin@ar-edelman.com
FaceTime Communications, Inc.
CONTACT: Emily Chamberlin of A&R Edelman, +1-650-762-2945, orechamberlin@ar-edelman.com, for FaceTime Communications
Web site: http://www.facetime.com/
Source: PRNewswire
Related Articles
- Phony Austin, Texas Police Twitter Account Highlights Need for Nixle, a New Secure Community Information Service
- Oracle Introduces Oracle(R) Gadget Wizard for Google Apps and Support for Google's Secure Data Connector
- SnagFilms Acquires indieWIRE, the Leading News, Information, and Social Networking Site for the International Independent Film Community
- Thru Expands Availability of Thru Secure Communication Network(TM) (SCN) to Mid-Market Firms and Large Enterprises
- Gartner Says the Consumerization of IT is a Major Threat to Enterprise Security
- Leading Industry Analyst Firm Positions FaceTime in Visionaries Quadrant in Web Gateway Security
- Yahoo! Sites Register a Moderate Share Gain for the Second Consecutive Month
- Blue Ridge Networks Unveils the BorderGuard(R) 6000 Secure Communications Platform; BorderGuard 6000 Series Extends High Security to Wireless Environments
- Cavium Networks Acquires Brecis Communications' Secure Communication Processor Product Line
- Antelope Technologies and Secure Communication Systems Announce Production of Tough Hand-held Shell for the Modular Computing Core
User Comments (0)

RSS Feeds