Friday, August 5, 2011

Where did Mac Defender go? A RAID on a Russian payment companies could explain

Mac DefenderMac Defender: false antivirus stopped mid-June is updated. A RAID on a Moscow company can explain why.

You may remember Richard Gaywood interesting post questions "where is the Mac malware explosion, then?" on July 21 - where he pointed out that there had been no updates of the Mac Defender definitions on the Mac since 18 June.

This can be the answer.

Hop on Brian Krebs excellent Krebs on security, where he provides, that determine the "Fake-antivirus industry is down, but not out":

Many fake antivirus company, the hacker to the junk-e-safety software PC-users impose have paid that recently closed. The wave of closures is increased control of the industry by security experts and a variety of international law enforcement agencies. But it's also probably soon break out to the sparkling wine: the excessive profits this drive fake AV peddlers guarantee the market will rebound soon.

What has happened is that the payment company that uses fake AV companies more, they no longer have seen out, payments for their potential customers. If the money flow not payments not taken.

Cancer also, says that "there may be another reason for the suspension: Russian police arrested on 23 June, co-founder of Russian online payment giant ChronoPay and a major player in the fake AV market." Cancer had written in May that it seemed to be a connection between ChronoPay and the appearance of Mac Defender; He suggested that it was employees of ChronoPay, were pushing it. ChronoPay had to deny a statement issued.

This is where it gets interesting: cancer police in the ChronoPay offices in Moscow, say found "Mountains of evidence that supports ChronoPay technical and customer employees a variety were carried out by fake AV programs, including Mac Defender." (There is a photo of the offices, although much of which is in Russian, it has the names of the various fake AV products.)

So, last Saturday 18 June, new version of Mac Defender; Thursday 23 June, RAID on offices. Perhaps things just a little close to ChronoPay and so they not could the new updates.

Cancer refers to a problem but: fake AV is "ridiculously profitable". Once you have installed a few thousand, you are actually money print. So, even though Mac Defender (probably) has disappeared, the possibility - probability? -Remains, the fake AV scam, and perhaps even worse is to be to win those cooked up by people looking to Apple users and Windows.


View the original article here

No comments:

Post a Comment