Land kiezen

Australia flag Australia Canada flag Canada/English Germany flag Deutschland Spain flag España France flag France China flag Hong Kong India flag India Ireland flag Ireland Netherlands flag Nederland New Zealand flag New Zealand Portugal flag Portugal South Africa flag South Africa Switzerland flag Schweiz Switzerland flag Suisse United Kingdom flag United Kingdom United States flag United States Japan flag 日 本 ×

Webroot® Threat Advisory: Searching for Presidential Campaign Videos Puts Users at Risk for Infection

Malware Installed on Infected Computer Opens Users Up To Identity Theft

Boulder, CO – September 29, 2008

Webroot, a leading provider of security solutions for the consumer, enterprise and SMB markets, today announced that it has detected malicious software being propagated as campaign videos for John McCain and Barack Obama. Hackers are taking advantage of unsuspecting users during the U.S. Presidential election season by utilizing the Gnutella file sharing network and seeding it with malware disguised as material relevant to the campaigns. This file sharing network is commonly accessed by clients such as LimeWire and FrostWire.

A search of the FrostWire network indicated that of the 34 search results for "Obama Speech" 14 contained active malware while five of the 19 results for "McCain Speech" were found to be harboring malware.

"Peer to peer networks pose some of the greatest security risks on Internet," said Paul Piccard, director, Threat Research, Webroot. "Because P2P networks lack the security measures found in enterprise networks or trusted Websites, users of these networks may put themselves or their companies at increased risk by downloading malicious content or leaking confidential data."

The most common malware variant spreading through this method is W32/Zipwire. Users become infected with the malware after downloading a zip file with a name such as "Democratic Convention 2008 - Barack Obama Acceptance Speech.zip." The contents of these zip files contain executable files (such as Setup.exe). When run, these files infect the host machine with random malware, including rogue antivirus applications, which detect fake security issues on the infected machine in order to entice users to buy the rogue application for disinfection. Other malware threats such as password stealers and backdoors can be downloaded as well, which may give a hacker remote access to the infected machine or allow them to gather personal data such as usernames and passwords.

According to the Webroot® Threat Research Center, this threat poses a number of different risks. For example, once infected the computer can be accessed remotely, which allows for the potential installation of new malware. These could include system monitors that spy on the user in an attempt to gather the information needed –including social security numbers, bank accounts, home addresses and more - to steal their identity.

"Webroot is focused on identifying emerging threats so that we can help consumers avoid being attacked and compromised," said Paul Lipman, Webroot's senior vice president and general manager of Consumer Business. "However, hackers are constantly evolving their attack vectors so it is essential for PC users to have best-in-class antispyware, antivirus and firewall software installed on their computers to ensure that their personal and confidential information is safe."

Webroot recommends several steps to users to prevent this type of malware attack:

  1. Always have a current version of antispyware, antivirus and firewall product;
  2. Never download free product or purchase them from unknown Web sites and vendors, or peer to peer networks;
  3. Never click on a link while visiting a peer to peer site;
  4. Never purchase a product that is the result of an unknown alert;
  5. Make sure the computer is up-to-date by always installing new Microsoft or Apple security updates;
  6. Make it a point to check your credit through one of the three credit bureaus; and, 
  7. Use a credit card that has sufficient fraud protection and never use a debit card online

©2014 Webroot Inc. All rights reserved. Webroot, SecureAnywhere, and Webroot SecureAnywhere are trademarks or registered trademarks of Webroot Inc. in the United States and other countries.

OVER WEBROOT

Webroot® is the market leader in cloud-based, real-time internet threat detection for consumers, businesses and enterprises. We have revolutionized internet security to protect all the ways users connect online. Webroot delivers real-time advanced internet threat protection to customers through its BrightCloud® security intelligence platform, and its SecureAnywhere™ suite of cloud-based security products for endpoints, mobile devices and corporate networks. Meer dan 7 miljoen consumenten, 1,5 miljoen zakelijke gebruikers en 1,3 miljoen mobiele gebruikers worden beschermd door Webroot. Market-leading security companies, including Cisco, F5 Networks, GateProtect, HP, Microsoft, Palo Alto Networks, Proofpoint, RSA and others choose Webroot to provide advanced Internet threat protection for their products and services. Founded in 1997 and headquartered in Colorado, Webroot operates globally across North America, Europe and the Asia Pacific region. For more information on our products and services, visit www.webroot.com.