Google, Yahoo and Bing Searches hijacked by click-fraud botnet, India has most infected machines
A click fraud botnet has infected over 900,000 machines in the world, and almost 100,000 of them are in India.
A click fraud malware has infected over 900,000 machines in the world, and almost 100,000 of them are in India. The botnet stretches across the world, but mainly the botnet operates out of India. Other heavily affected countries include Malaysia, Greece, USA, Pakistan, Italy, Algeria and Brazil. The trojan named Redirector.Paco is used for generating money from Google AdSense.The botnet executes a man in the middle attack. It replaces legitimate search queries, with customized results, by redirecting the traffic between the user and the search engine. It installs fake certificates on the system, that fool the browsers into thinking they are having a secure connection with the search engines. The infection vector for the malware are modified installation files for popular programs. These include WinRar, YouTube Downloader, Connectify and Stardock.The modified installers schedule tasks on the computer. These are called "Adobe Flash Scheduler" and "Adobe Flash Update", and start up every time the machine is run. These scheduled tasks in turn run scripts that modify the internet settings of the user. The machine then reroutes traffic through a local or remote proxy server. Any search queries are replaced with a an implementation of Google custom search.BitDefender has details on the scripts, configuration files and JavaScript codes used by the malware.

Why AI notetakers are raising serious privacy and security concerns
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
How did Instagram run ads promoting child abuse in India?
Why has India halted WhatsApp’s username feature before launch?
