Original URL: http://www.channelregister.co.uk/2008/02/12/malware_punts_symantec_check_point/
Unscrupulous affiliates are using malware to advertise security software from legitimate firms. The practice is the brainchild of people who make a commission for every sale they generate - and not security vendors themselves. The practice raises serious concerns about the integrity and policing of affiliate programs from big names in security including Symantec and Check Point.
Instances of the dodgy practice, compiled by security firm Sunbelt Software, include PC Tools being "malvertised" last month in manipulated search results created on machines infected with the DNSChanger Trojan (video here (http://www.sunbelt-software.com/ihs/alex/dnschanger_01222007.wmv)). Separately, popups generated by the C2 (AKA Lop (http://research.sunbelt-software.com/threatdisplay.aspx?name=C2.lop&threatid=8144)) adware package maliciously punted Symantec and Check Point products last week.
Sunbelt is seeking to throw a spotlight on dodgy practices by affiliates rather than make marketing capital out of the development. "Affiliate programs are a great way to spread the word on your product, but they need to be monitored carefully for abuse," notes (http://sunbeltblog.blogspot.com/2008/02/legitimate-security-companies.html) Alex Eckelberry, president and chief exec of Sunbelt.
The US-based anti-spyware firm is not the only security watcher to pick up on instances of malvertisement. Independent security researcher Ben Edelman, an assistant professor at the Harvard Business School, has spotted examples of popups for Symantec's online store generated by the SurfSideKick adware (http://www.symantec.com/security_response/writeup.jsp?docid=2004-112118-0309-99) package that's described as potentially unwanted by Symantec and other security vendors. ®
Adware package tops malware charts for first time (6 March 2008)
http://www.channelregister.co.uk/2008/03/06/adware_tops_malware_chart/
Facebook blocks Secret Crush over adware row (8 January 2008)
http://www.channelregister.co.uk/2008/01/08/facebook_blocks_secret_crush/
Dutch regulator slaps spyware purveyors with €1m fine (18 December 2007)
http://www.channelregister.co.uk/2007/12/18/duch/
NZ police cuff teenage botnet mastermind suspect (30 November 2007)
http://www.channelregister.co.uk/2007/11/30/kiwi_teen_botmaster_arrest/
Miscreants subvert search results to punt malware (28 November 2007)
http://www.channelregister.co.uk/2007/11/28/botnets_use_search_to_build_zombies/
DoubleClick caught supplying malware-tainted ads (13 November 2007)
http://www.theregister.co.uk/2007/11/13/doubleclick_distributes_malware/
Fake smut codec ruse used to punt Google Pack (12 November 2007)
http://www.channelregister.co.uk/2007/11/12/google_pack_fake_codec_ruse/
FTC demands bigger spyware penalties (30 October 2007)
http://www.channelregister.co.uk/2007/10/30/ftc_spyware_sanctions/
Zango abandons PC Tools adware lawsuit (29 August 2007)
http://www.channelregister.co.uk/2007/08/29/zango_pc_tools_lawsuit_dropped/
© Copyright 2008