Phishers Use Fake Google Toolbar As Bait

MOUNTAIN VIEW, Calif. – Security experts have issued a warning that a new phishing scam involving a fake Google toolbar is the latest lure being used to steal personal information from web users.

Phishing is where emails, instant messages or websites pretend to be legitimate companies for the purpose of stealing personal information, financial account numbers and passwords.

The scam spreads itself via IM and Internet Relay Chat and downloads a fake Google toolbar and adware on users’ machines, which re-direct to a page collecting credit card information.

According to security firm FaceTime, the scam borrows the exploits of an application commonly referred to as "CoolWebSearch" and uses two URLs via IM that lead users to a web page that begins the toolbar install and calls a Windows Help File. Once this happens, the fake Google toolbar appears and the anti-spyware program known as "World Antispy" launches. At this point, users may also experience a pop-up window that asks for personal information.

So far, Yahoo Messenger is the only IM service being used in this attack.

"Our research finds that this phishing scam is financially motivated by a third party using incredibly elaborate bundles that deliver a rogue Google toolbar with many of the same elements as the real Google toolbar,” Chris Boyd, senior researcher at FaceTime, said. "Hackers are clearly using new tricks such as IM to take advantage of reputable, trusted brands such as Google.”

FaceTime is reporting that there are three distinct versions of this attack, each one exploiting different security vulnerabilities and installing a different payload using different vectors, including IM and IRC.

The new scam marks an increasing trend in using IM as a phishing tool, Boyd said.

According to security firm IMlogic, phishing attacks that use IM as their vehicle have jumped by 14 times since the first of the year, and by the third quarter, IMlogic tracked 10 times the number of IM threats than in all of 2004.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Vendo Launches 'Pay by Bank' Service

Vendo has launched its new Pay by Bank checkout system.

CrakRevenue Taps Maxime Bergeron as New CEO

CrakRevenue has appointed longtime staffer Maxime Bergeron as the company's new CEO.

Clips4Sale Adds 'Spatial Video' Category

Clips4Sale (C4S) has debuted a “spatial video” category for the next generation of VR and AR devices.

Lemon Social Launches Educational Program, 'Metaverse' Feature

Premium fan platform Lemon Social has debuted an "Adult Content University" program and a "Lemon Social Metaverse" feature.

Australian Conservatives Raise Concerns About US-Born Online Censor

Long after progressive free speech advocates in Australia questioned eSafety Commissioner Julie Inman Grant over her campaigns to target adult content, conservatives and libertarians are now raising concerns about the powers granted to the country’s top censor — an unelected former tech exec born in the U.S. — with some calling for her ouster.

Cupcake Girls, Aylo Partner on Educational Video Series for Performers

The Cupcake Girls and Aylo have teamed up to produce a series of educational videos focused on safety standards for adult performers.

My.Club Appoints Nicole Aniston as New Brand Ambassador

My.Club has named Nicole Aniston its newest brand ambassador.

Elevated X Implements Age Verification Solution, Integration API

Elevated X is now offering age verification services (AVS) through an API.

MojoHost Rolls Out 'Star Wars Day' Promo

MojoHost will celebrate “Star Wars Day” on Saturday by offering a special discount on new purchases of dedicated servers, VPS and CDN prepay plans throughout the month of May.

2024 XBIZ Miami Show Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for XBIZ Miami, the adult industry's biggest summer conference, set to take place May 13-16.

Show More