Home
BYTE Newsletter
Keep up with all the BYTE News and Reviews

Subscribe

Google Spreads Word On DNSChanger Malware

Comments | Mathew J. Schwartz, InformationWeek | May 23, 2012 12:21 PM


"Your computer appears to be infected."

Google began displaying that message Tuesday to anyone using one of its search engine sites with a PC that appears to be infected with the DNSChanger malware.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"After successfully alerting a million users last summer to a different type of malware, we've replicated this method and have started showing warnings via a special message that will appear at the top of the Google search results page for users with affected devices," said Google security engineer Damian Menscher in a blog post. The previous effort targeted a fake antivirus software campaign.

[ Read about some real-world examples of mobile malware and the challenges of thwarting them. See 6 Findings That Prove Mobile Malware's Mettle. ]

"Our goal with this notification is to raise awareness of DNSChanger among affected users," Menscher said. Furthermore, since about half of infected PCs appear to be located in non-English-speaking countries, "we believe directly messaging affected users on a trusted site and in their preferred language will produce the best possible results."

Why the proactivity with respect to this particular piece of malware? Because any PC infected by DNSChanger stands to lose Internet access on July 9, 2012. That's the court-ordered date for the FBI and the Internet Systems Consortium to disconnect the domain name system (DNS) servers they're currently using to resolve Internet addresses for PCs infected by DNSChanger. The FBI commissioned the servers after "Operation Ghost Click," in which the bureau and Estonian police worked together to bust six Estonians for using the malware to conduct a four-year click fraud campaign that raked in an estimated $14 million.

To perpetrate the click fraud--forcing a Web browser to "click" on certain advertisements, thus generating revenue from pay-per-impression advertising networks or referral fees--the criminals used their malware to alter the DNS settings on infected PCs to their own rogue DNS servers. Even after the botnet operators were arrested, however, the infected PCs were still relying on the rogue DNS servers to resolve domain names into IP addresses.

For anyone left with a PC infected by DNSChanger come July 9, when the temporary DNS server gets disconnected, the resulting loss of connectivity may not be easy to diagnose. "In the simplest terms, connectivity will not be severed for DNSChanger-infected systems, but Internet communications will not function for infected systems that have not been cleaned up," explained Kurt Baumgartner, senior security researcher for the global research and analysis team at Kaspersky Lab, via Threatpost. "In the U.S., government agencies, home users, and other organizations still infected with the malware will have systems that effectively can't get online, can't send email, etc. It will look like they are connected to their network, but they just won't communicate with anything."

Google's outreach effort alone, of course, won't solve this malware-infection problem. "While we expect to notify over 500,000 users within a week, we realize we won't reach every affected user," said Menscher. Still, reducing the number of infections by any amount will help. "If more devices are cleaned and steps are taken to better secure the machines against further abuse, the notification effort will be well worth it," he said.

Since the botnet takedown, numerous service providers--including AT&T, Bell Canada, CenturyLink, Comcast, COX, Time Warner, and Verizon--have also begun notifying customers whose PCs that appear to be infected. Meanwhile, for anyone else who suspects their PC may have been infected, the DNSChanger Working Group (DCWG) also maintains a list of websites that will identify if your PC is carrying the malware.

When it comes to regulatory compliance, auditors consider more than how you protect your company's covered assets from external attackers. In the Compliance From The Inside Out report, we show you how to create and implement a security program that will defend against malicious and inadvertent internal incidents and satisfy government and industry mandates. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events