All the latest UK technology news, reviews and analysis

Microsoft links Mac Defender to Windows scareware campaign

by Phil Muncaster

20 May 2011

Comment: 1

  • Tweet this

Microsoft has been doing some detective work and reckons that the same team behind Windows-based scareware known as Winwebsec is responsible for the Mac Defender rogue security software which hit the headlines this week after Apple reportedly tried to sweep the problem under the carpet.

Mac Defender was discovered by security firm Intego early this month, and it didn't take long before Apple user forums were full of reports of the scareware, which tries to persuade users to buy an 'anti-virus' product by tricking them into believing their machine is infected.

More controversially, it was then reported that Apple's support service, AppleCare, had been told not to confirm or deny the malware if asked by a customer.

In a posting on the Threat Research and Response blog, Microsoft suggested that the two families of scareware have remarkably similar traits.

"The best example is that the URL format that FakeMacdef uses to call home is almost identical to that which we see in Winwebsec. The purchase pages are also similar," the blog noted.

"In addition to using similar UIs, we noticed that they even share the same payment gateway (this is the site where users are duped into giving the criminals their credit card information). Simply changing the file name from 'buy.php' to 'mac.php' causes the 'branding' to change from the Windows version to the Mac version."

In many ways it's not surprising that the same cyber crime team is targeting scareware at Mac and Windows users, as scammers and malware writers are increasingly looking to exploit users of an Apple platform which until recently has not been popular enough to warrant their attention.

As if to highlight this trend, possibly the world's first cyber crime kit aimed at Macs was found on an underground internet forum by Danish IT security vendor CSIS Security Group earlier this month.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

2%

14%

53%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Functional Oracle Support Analyst

Functional Oracle Support Analyst - EBS Financials, Support...

Oracle E-Business Suite Technical Consultant

Oracle E-Business Suite Technical Consultant - EBS...

Oracle Applications DBA

Oracle Applications DBA - East London - All salaries...

Oracle Functional Consultants

Oracle Functional Consultants - Financial - Project Accounting...

To send to more than one email address, simply separate each address with a comma.