These days Fake Adobe Flash Players are everywhere. The bad guys know that the majority of people cannot tell the difference between them.
To be honest, when Adobe prompts you for a Flash Player update, it looks almost identical to some of those pop ups you will encounter while browsing the web.
Fake Flash Player update
The following one comes from a Russian website, and although my Russian is a little rusty I can guess what it’s for:
Looks pretty legit. I press the button to install it…
Suddenly my Desktop is hijacked by a window asking for some password…
Ransomware
This is called ransomware. Unless I follow the instructions that involve spending money, I can’t get rid of this screen.
The process responsible for it is a file called kasper_zaebal.exe. It will kill your browser to prevent you from downloading an Antivirus program I assume?
All this makes me wonder if the best way to deliver program updates should not be done silently? Although it is a good idea to warn end users that some of their software is out of date, the bad guys are employing the exact same methods to distribute their malware. Other alternatives would be programs dedicated to software updates… but would you remember to run them every once in a while?
Suffice to say, always think twice before doing any ‘update’.
Jerome Segura
'IT 보안소식' 카테고리의 다른 글
청와대 및 주요 5기관 DDoS 공격 발생!! (0) | 2010.07.07 |
---|---|
웹센스(Websense), Fake Input Method Editor(IME) Trojan (0) | 2010.07.07 |
트렌드마이크로(TrendMicro), ZeuS/ZBOT Targets Russian Banks (2) | 2010.07.06 |
네이트온 악성코드 사진변경(2010-07-05) (2) | 2010.07.05 |
Adobe PDF 취약점으로 인한 주의(/Launch /Action 명령어) (4) | 2010.07.05 |
댓글