Worm Serves Fake Search Results On Google, Yahoo, MSN

BILBAO, Spain — Representatives at Panda Software have found a worm they said sends infected users to fake versions of popular search engines like Yahoo, Google and MSN. The fake sites, exact copies of the legitimate engines, serve up fake search results designed to bolster traffic on web pages that host pornographic content and pirated software.

According to Patrick Hinojosa, the chief technology officer at Panda, the worm could potentially earn a lot of money for sites embedded in the fake search results.

“This is a business; this is organized crime,” Hinojosa said. “People are making money on it.”

According to the latest studies from Panda, the “P2Load.a” worm modifies the Windows HOSTS file. When an infected user types in “Google.com,” or even a misspelled variation of the search engines in question, they are instead sent to a phony site originating in Germany. The program also installs a fake Google toolbar in a user’s browser.

Luis Corrons, director of Panda’s research facility, said in a statement that the worm focuses on giving sites illegal placement at the top of search results.

“The creator of this worm has taken advantage of the importance of a company appearing among the first few links in the search results of an Internet browser,” Corrons said. “Its aims are none other than to increase visits to the pages linked by the creator of this malware or earn an income from companies that want to appear in the first few results in computer where the identity of [a search engine] has been spoofed. In both case, the motivation of the author of this malware is purely financial.”

Hinojoa said the infected program that houses the worm is called PremiumSearch. The company has yet to determine how many machines have been infected with the worm, but have notified federal authorities in both the United States and in Germany, as well as the ISPs that originally hosted the program.

Representatives at the leading search engines have yet to comment on the worm.

This is not the first time Google has been targeted by hackers. In March a DNS cache infection sent Google traffic to hacker sites, just days before it was discovered that several variations of the Google.com web address sent users to fake sites hosted in Russia. Once on these sites, a surfer’s computer was infected with software designed to steal bank statements and other valuable personal data.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Texas Resumes AV Lawsuit Against Aylo Following SCOTUS Decision

A district court judge in Texas has unfrozen the state’s $1.6 million lawsuit against Aylo for allegedly failing to comply with age verification requirements, Bloomberg Law is reporting.

JuicyAds Wins Trademark Infringement Case Against Fraudulent Domain

JuicyAds has won its World Intellectual Property Organization (WIPO) case against a website using a similar domain to impersonate the company's site and defraud customers.

Anissa Kate, Jordan Starr Top AEBN for Q2 of 2025

AEBN has published its top-selling stars for the second quarter of 2025, with Anissa Kate landing atop the leaderboard for straight theaters and Jordan Starr heading up the gay rankings.

AEBN Reveals Eva Maxim as Top Trans Star for Q2 of 2025

AEBN has published its top trans stars list for the second quarter of 2025, with Eva Maxim landing atop the leaderboard.

France Reinstates Age Verification Rule for EU Sites

France’s highest court, the Council of State, on Tuesday reinstated age verification rules for EU-based sites under the country’s Security and Regulation of the Digital Space (SREN) law, ruling in favor of the French government and against Hammy Media.

Whisper Fans Joins Pineapple Support as Supporter-Level Sponsor

Whisper Fans has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Utherverse Launches 'Red Light Center' Virtual World

Virtual reality and metaverse technology company Utherverse has launched its new virtual world, RedLightCenter.io.

European Commission Approves AV Guidelines, Unveils Prototype App

The European Commission on Monday released its final, approved guidelines for protecting minors online under the EU’s Digital Services Act (DSA) and made public a “white label” age verification app intended to help sites and platforms comply with age verification rules under the DSA.

Show More