How much money can criminals make scaring naive computer users? Try $5 million a year.
That is how much a marketing associate of one Russian operation appears to be earning from its sales of fake anti-virus software through an elaborate scheme that relies on e-mail spam and indirect control of thousands of unprotected PCs, according to internal company files posted online by a Russian hacker.
The company is Bakasoftware, a clandestine effort based in Russia that markets what it claims is an anti-virus program strictly to English-speaking computer users.
The program, whose name has recently been updated from Antivirus XP 2008 to Antivirus XP 2009, lodges itself on a victim’s computer and then begins generating a series of pop-up messages warning that the user’s computer is infected. If the user responds to the warnings, he is urged to buy a $49.95 program for disinfecting the machine.
Although tens of millions of Windows PC users have seen these irritating programs, which purport to warn against malware infections, there are few details about the operators who develop and distribute the software, known as scareware.
Financial details of the operation came to light recently after information posted by a computer hacker identifying himself as NeoN was discovered on a Russian electronic bulletin board by an American computer security researcher.
The researcher, Joe Stewart, who is director of malware research at SecureWorks of Atlanta, has tried to understand the nature of the fake anti-virus software and the way it is sold through a second tier of “bot-herders” — people who redistribute the program through illegal “botnets” or networks of Internet-connected PCs.
The scheme was partly unmasked, Stewart said, after NeoN broke into one of the computers used by Bakasoftware for accounting. Stewart said he believed the hacker posted the results of just one week’s operations.
Stewart also discovered that when the Bakasoftware…