Fake URLs new malware threat

Hoaxing famous URLs has become big business for cyber crims

According to Websense Security Labs, criminals are seeking to mislead web surfers by flooding the internet with URLs that include words like FaceBook, MySpace and Twitter.

The fake domains, which have no connection to the legitimate websites, are designed to trick users into entering sensitive information, such as passwords, bank account details and PIN numbers, or into downloading malicious code.

“These new threats illustrate that attackers will continue to target Facebook, MySpace and Twitter, along with other social networking sites, for three reasons,” said Charles Renert, senior director, advanced content research, Websense. “These Web sites are popular – fraudsters are able to target lots of victims; people trust the content on it – because they think it’s from other people in their network; and they are easy to compromise because they allow anybody to create and post content. Traditional Web filtering is not enough to protect users from threats on trusted sites, and isn’t enough to keep up with fraudsters generating new URLs almost instantaneously to avoid detection. Only real-time analysis of Web content can prevent users from being exploited by this attack.”

The most common fake site used to dupe people is fake FaceBook sites. According to WebSense, the fake URLs include examples such as unblock.facebookproxy.com. Over 200,000 fake FaceBook URLs were found by the company.

More about: Facebook, Websense

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: cyber crime, domain names, fraud
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/15/angry-ip-scanner/

Angry IP Scanner

Angry IP Scanner (or simply ipscan) is an open-source and cross-platform network scanner designed to be fast and simple to use. It scans IP addresses ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia