<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title> by Ruth Brackett</title>
      <link>https://padlet.com/ruthbrackett/ln4o1618op</link>
      <description></description>
      <language>en-us</language>
      <pubDate>2013-10-01 04:21:40 UTC</pubDate>
      <lastBuildDate>2017-05-17 11:49:21 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Microsoft uncovers Sefnit Trojan return after
Groupon click-fraud scam</title>
         <author>ruthbrackett</author>
         <link>https://padlet.com/ruthbrackett/ln4o1618op/wish/14025054</link>
         <description><![CDATA[<p>

<p><b><a href="http://www.v3.co.uk/v3-uk/news/2297027/microsoft-uncovers-sefnit-trojan-return-after-groupon-click-fraud-scam">Source Link</a></b></p>
<p>The authors of the notorious Sefnit Trojan have resurfaced using advanced infection
and <b><a href="http://www.socialphy.com/posts/off-topic/23320/Abney-and-Associates-Fraud-Watch_-Watch-for-Internet-scams.html">click-fraud</a></b> techniques to earn vast
sums of money through bogus advertising, according to Microsoft.</p>
<p>Microsoft antivirus researcher Geoff McDonald reported discovering an evolved version of
the Sefnit Trojan, which takes money by targeting popular websites, such as
Groupon.</p>
<p>In a blog post on the company's Malware Protection Centre, McDonald wrote:
"The Sefnit click-fraud component is now structured as a proxy service
based on the open-source 3proxy project. The botnet of Sefnit-hosted proxies
are used to relay HTTP traffic to pretend to click on advertisements. In this
way, the new version of Sefnit exhibits no clear visible user symptoms to bring
attention to the botnet. This allowed them to evade attention from anti-malware
researchers for a couple years.</p>
<p>"The Sefnit botnet uses the hosted 3proxy servers to redirect internet traffic and
perform fake advertisement clicks. A recorded example of this click-fraud path
is shown below by using the legitimate affiliate search engine Mywebsearch.com
to simulate a search for ‘cat' and fake a click on an advertisement provided by
Google to defraud the advertiser Groupon."</p>
<p>He said the technique allowed the criminals behind the malware to increase the
revenue <b><a href="http://www.topix.com/forum/business/TAFDGLA1AGHF339F5">they made using the scam.</a></b>
"The end result is Groupon paying a small amount of money for this fake
advertisement ‘click' to Google. Google takes a portion of the money and pays
the rest out to the website hosting the advertisement – Mywebsearch. The Sefnit
authors likely signed up as an affiliate for Mywebsearch, resulting in the
Sefnit criminals then receiving a commission on the click."</p>
<p>A Groupon spokesperson told V3 the company actively monitors its network for any
illicit activity. "We actively monitor our thousands of global affiliate
marketers, and those who violate the rules are removed from the
programme."</p>
<p>McDonald said Microsoft uncovered evidence linking Sefnit to the Mevade malware used in
the world's first large-scale Tor botnet.</p>
<p>"​Recently Trojan:Win32/Mevade made news for being the first large botnet to use Tor to
anonymise and hide its network traffic. Within a few weeks, starting
mid-August, the number of directly connecting Tor users increased by almost 600
percent – from about 500,000 users per day to more than three million," he
wrote.</p>
<p>"Last week we concluded, after further review, that Mevade and Sefnit are the same
family and our detections for Mevade have now been moved to join the Sefnit
family."</p>

<p>As well as its links to Mevade, McDonald said the attack is also using a host of
new custom-built components to improve its infection rate. "This latest
version of Sefnit shows they are using multiple attack vectors, even going as
far as writing their own bundler installers to achieve the maximum number of
infections that make this type of click fraud a financially viable
exercise," he wrote.</p>
<p>"The authors have adapted their click-fraud mechanisms in a way that takes user
interaction out of the picture while maintaining the effectiveness. This
removal of the user-interaction reliance in the click-fraud methodology was a
large factor in the Sefnit authors being able to stay out of the security
researchers' radars over the last couple of years."</p>
<p>Sefnit is one of many variations of malware to receive technical upgrades in recent
months. Earlier this month FireEye researchers reported discovering a reworked
version of the Darkleech campaign targeting Java and Adobe vulnerabilities to
spread the Reveton ransomware.</p>
</p>]]></description>
         <enclosure url="" />
         <pubDate>2013-10-01 04:22:22 UTC</pubDate>
         <guid>https://padlet.com/ruthbrackett/ln4o1618op/wish/14025054</guid>
      </item>
   </channel>
</rss>
