How Search Engines Can Lead Users to Malware

82 views
•
November 8, 2011
by
RSAC Cybersecurity
YouTube video player
How Search Engines Can Lead Users to Malware

TL;DR

Search results are not inherently safe because attackers can manipulate rankings and route users from apparently relevant pages to malware. They create link farms, tailor malicious downloads to a user’s intent, conceal redirects from researchers, and exploit browsers or plug-ins, so protection must account for the complete path from a search query to the final destination.

Transcript

Presentation, uh, for the audio check. Okay, this is the audio check for my presentation. Uh, my name is Chris Larsen. I'm a engineer, malware researcher with Blue Coat, and this is a condensed version of my RSA presentation. That's good, Chris. Okay. Thank you, and, um, I'm gonna start the camera when I give you the signal. I'll point to you, and ... Read More

Key Insights

  • Modern web pages are multi-host systems that can make dozens or even more than a hundred requests to domains supplying images, movies, advertisements, analytics, and other content. This complexity gives browsers many more external interactions than the simple, single-server pages common in the earlier web.
  • Contemporary cybercriminals are professionals who generally prefer invisible compromises over conspicuous website defacement. Their objective is often to obtain data that can be converted into money, which makes stealth and continued access more valuable than public recognition of an attack.
  • The browser and its associated plug-ins are major attack vectors. Email remains relevant, but attackers commonly place malicious links in messages because harmful attachments are more likely to be filtered, shifting the dangerous interaction from the inbox to a website.
  • Fake antivirus software works by presenting an animated scan that falsely reports infections and offers paid assistance. According to the presentation, a victim may lose 50 dollars and could also install software that gives attackers the ability to add further malicious programs and control the computer.
  • Fake downloads exploit a user’s existing intention to acquire software, games, movies, music, pornography, or other content. Attackers insert themselves into that search process and present malware as the desired file, benefiting from the user’s readiness to download and trust a seemingly relevant result.
  • Social-network messages can create a download mindset by appearing to come from a trusted friend. A message promoting a video may lead to a page that asks the recipient to download a player, run a file, or upgrade the browser before viewing the promised content.
  • Drive-by downloads can compromise a visitor without an obvious prompt. A small line of HTML on an otherwise innocent, compromised website can silently direct the browser elsewhere, retrieve data, and exploit vulnerabilities in the browser or supporting applications such as Acrobat Reader.
  • Search ranking manipulation works by creating many pages that link to a target page, making it appear important to a search engine. A malicious page can also change its behavior based on the referring search engine and query, showing harmless HTML to direct investigators but encrypted JavaScript to search visitors.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why can search engine results contain malicious links?

Search engines rank pages by evaluating signals such as content and incoming links, but attackers can manufacture those signals. They create numerous supporting pages that point toward a chosen target, raising its apparent importance for particular search terms. The target can then appear prominently in results even though visiting it redirects the user toward malware or serves harmful code.

Q: How do attackers manipulate search engine rankings?

Attackers create link farms containing many pages and links that point to a selected malicious or intermediary page. The pages may include paragraphs, headings, varied text, highlighting, and collections of links so that a search crawler interprets them as useful content. These manufactured signals raise the target page’s visibility for queries that potential victims are likely to enter.

Q: What is a fake antivirus attack?

A fake antivirus attack begins when a page claims that the visitor’s computer may be infected and displays an animated scan. The fabricated results report malware and offer a supposed remedy. The presentation says the victim may lose 50 dollars, and the installed program may also compromise the computer, enabling attackers to place additional software on it.

Q: How do fake downloads exploit a user’s search intent?

Fake downloads succeed because the user is already looking for something to bring onto the computer. An attacker presents a malicious file as the requested free or pirated software, game, movie, music, pornography, or other material. Since the offer matches the active search, the user may treat the file as relevant and accept it without sufficient suspicion.

Q: How can social-network messages spread malicious downloads?

A social-network message can appear to come from a friend and invite the recipient to view a video. Trust in the apparent sender encourages the click and places the recipient in a download-oriented mindset. The destination may then request a video download, executable file, browser upgrade, or other installation that actually introduces malicious software to the computer.

Q: What is a drive-by download attack?

A drive-by download occurs when visiting a website causes the browser to retrieve and run harmful data without the visitor knowingly approving a download. The initial website may be legitimate but compromised. A small hidden HTML instruction sends the browser to another site, where code targets a vulnerability in the browser or a supporting application such as Acrobat Reader.

Q: How can a malicious page hide its behavior from researchers?

A malicious page can examine how a visitor reached it and respond differently based on that context. In the example, directly inspecting the suspicious page revealed only clean, generic HTML without JavaScript or an iframe. Arriving through a particular Google search produced encrypted JavaScript instead, allowing the page to look harmless during direct examination while targeting search users.

Q: How common were malicious URLs in the cited Google research?

The presentation cites a paper by Google researchers reporting that approximately 1.3 percent of incoming search queries returned at least one malicious URL on the results page. The speaker uses that figure to show why ordinary trust in search results can be dangerous, even when the search provider has strong resources and a clear motivation to identify harmful destinations.

Summary & Key Takeaways

  • Modern web pages combine content from many domains, supporting servers, advertisers, analytics services, and community contributors. This complexity creates many background requests and expands the opportunity for malicious content. The web has also become a critical business and personal tool while accumulating large quantities of unreliable and potentially dangerous material.

  • Cybercriminals evolved from amateurs seeking visible recognition into professionals who prefer hidden compromises and monetizable data. Their primary attack surface became the browser and associated plug-ins. Even email attacks increasingly direct victims to malicious websites through links instead of relying on attachments that security tools have become effective at filtering.

  • Search engines support three recurring attack categories: fake antivirus scanners, fake downloads, and drive-by downloads. Attackers improve malicious pages’ rankings with networks of linking pages, then may selectively deliver harmful JavaScript only when visitors arrive through particular search queries, allowing an apparently harmless page to conceal its actual purpose.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚