Jump to content

Coincidence? I think NOT! - New Malware found to inject Bing results into Google Seaches

rcmaehl

Source:
The Register
AiroAV Report
 

Summary:
Malware disguised as Adobe Flash plugins using MITM attacks to inject Bing results into Google Searches.

Quotes/Excerpts:

Quote

A devious and baffling new strain of malware intercepts and tampers with internet traffic on infected Apple Macs to inject Bing results into users' Google search results. A report out...by security house AiroAV details how...a software nasty ...configures compromised macOS computers to route the user's network connections through a local proxy server that modifies Google search results. Normally, malware that squirts ads and other junk into websites as they are visited on Macs typically relies on installing browser or operating system extensions, or injecting AppleScript, to pull off this kind of caper. The malware masquerades as an installer for an Adobe Flash plugin...that the user is tricked into running,... asks the victim for their macOS account username and password,... install a local web proxy and configure the system so that all web browser requests go through it. When the user opens their browser and attempts to run a Google search on an infected Mac, the request is routed to the local proxy, which injects into the Google results page an HTML iframe containing fetched Bing results for the same query, weirdly enough. It's believed the Bing results bring in web ads that generate revenue for the malware's masterminds. "To our understanding, the attackers make money out of ads they are managed to serve via this process," an Airo spokesperson told us. "It could be Bing ads in this case, or other ads throughout the process." "This aggressive search takeover and injection method seem to be a response to recent changes in macOS Mojave which had deprecated ‘traditional’ methods such as extension installation and browser setting takeovers," the pair explained. 

 

My Thoughts:

MY GOD... Someone inform the UN. We need top minds on this NOW! Someone needs to put this criminal in jail immediately. Unless you're looking for specific content in which Bing is significantly better for... Regardless, it's interesting to watch Malware adapt to Apple continuously removing permissions on macOS.

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

46 minutes ago, rcmaehl said:

Unless you're looking for specific content in which Bing is significantly better for

Yandex works too

🙂

Link to comment
Share on other sites

Link to post
Share on other sites

59 minutes ago, rcmaehl said:

Regardless, it's interesting to watch Malware adapt to Apple continuously removing permissions on macOS

While Apple is quick in patching vulnerabilities when discovered, they don’t necessarily have the best practices in keeping their users safe. 

  • Apple’s payouts for their iOS bug bounty is cheap compared to other companies which also allows everyone to participate in the bug bounty. Apple’s bug bounty is an invite only. 
  • They don’t have a macOS bug bounty. [here]
  • macOS’ built in antivirus called “XProtect” only relies on static signatures unlike Windows Defender and others which has additional components that uploads unknown and suspicious files to the cloud for analysis. 
  • Apple can be quite selfish when it comes to virus discoveries. 

And yet, there are still some ill-informed Mac users who still believe that Macs can’t get infected. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Now that's funny. 

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Mr. horse said:

dose bing still have that thing were if you use it you get gift cards?

Could this would be why they are doing this? Or maybe someone from M$ did this ?

Yeah, they still have it via microsoft rewards. Takes ages to get points bc its 5 per search with a 50 point a day limit, and you have to spend like 1.3k points for a 1.25 cent gift card

Current PC (Second Build) : CPU: Ryzen 5 1600 (OC @3.8GHz, sometimes pushed to 4GHz) RAM: 16gb Corsair Vengeance RGB Pro DDR4-2666 (OC @2733Mhz, sometimes pushed to 2800 for testing purposes)   GPU: PowerColor Radeon RX570 8gb MOBO: ASRock B450m Pro4 SSD: Inland 120gb HDD: 1tb Seagate Barracuda PSU: Cooler Master Masterwatt 500w Lite Case: NZXT H500 OS: Arch Linux+ KDE Plasma [Desktop Environment] & Windows 10 Pro [Broken due to grub 50% of the time]

 

Accessories: Mouse: Alienware AW958 Elite Keyboard: Corsair K63 Wireless  Headphones: Samsung Level On Pro

 

Phone (waiting on arrival): Samsung Galaxy Note 9

Link to comment
Share on other sites

Link to post
Share on other sites

This is probably made by apple themselves so they could kill flash quicker.

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, ImAyaanKhan said:

Yeah, they still have it via microsoft rewards. Takes ages to get points bc its 5 per search with a 50 point a day limit, and you have to spend like 1.3k points for a 1.25 cent gift card

it's 150 on pc, 50 on mobile

Don't forget to use the "Quote" feature or mention me ( @Gegger) if you want me to see your reply!

Community Standards // Forum Quickstart Guide // Floatplane // Forum FAQ // The Parrot Gang
Banned by Linus in the "banning game" thread who added insult to injury by putting this crap in my sig >(

WE ARE THE DARK SIDE Don't be a light theme peasant

Spoiler

             ........:oo:........

           o//ssssssssyhhysssss+////o               .''''''''''''''. 

          mddmmm/::ddddddddddddddmmmyss::/mmN       |   PARTY ON   |

          o..+oodddmmmhhhhhhhhhhhdmmmmmdddooy       | ,............'

         h::oyyhddmmm+++///////////++++++mmmddy::s  |/

      Nyyo[[sddhyyyyy::::::::::::::::::::yyymmh//oyym

     h..:oohmm+:://///::::////////////////+mmmmms..sNN

     m++sddmmm+::hddhhy::+ddddddddddddddhhhmmmmmdhh+++d

    Nsssyyhmmhssooodmmhhh::+mmdyyyyyyyyddddddmmmmmmmmo::d

   mmd../mmmmmo::shhdmmhhh::+mmhooooooooyhhmmmmmmmmmmmyssdmm

  +++++smmdddo::///dmmhhh::+mmhooooooooooommmmmddddmmmdd/++m

 ``+hhhmmhoo/:::::oooooossymmhooooooooyyymmdoooooydddmmo//N

 ++:mmmmmy:::::::::::::/yyhmmhooooooooyhhmmd:::::+yyhmmyssddd

ooommmmmy:::::::::::::://ommhooooooooooommd:::::://shhdmm+..

yyhmmh++/::::::::::::::::+mmhooooooooyyymmd::::::::/++hmm+//

dddmmh++/::::::::::::::::+mmhooooooooyhhddh:::::::::::hmmysshhd

mmmmmdhhs::::::::::::::::+mmhoooooooohhhhhy:::::::::::hmmhhh``+

mmmmmh++/::::::::::::::::+mmdhhsooooodmm++/:::::::::::hmmsss``+

dddmmhoo+::::::::::::::::+dddddyssyyydmm::::::::::::::hmmsoo++o

dddmmdhho::::::::::::::::+hhdmmddddmmmmm::::::::::::::hmmsooNNN

mmmmmh///::::::::::::::::+hhdmmmmmmmmddd::::::::::::::hmmsoo++/

yyhmmdss+::::::::::::::::/ooydddmmmmmsoo::::::::::::::yddhyy::+

++ommmmmy:::::::::::::::::::ohhdmmddd/::::::::::::::::shhdmmsssNNNmmN

..+mmmmmy:::::::::::::::::::://shh+//:::::::::::::::::://dmmmmdoo+..o

``+dddmmhss+:::::::::::::::::::+++/::::::::::::::::::::::ooodddhhysshNNy++m ``+hhdmmdhhs///:::::::::::::::::::::::::::::::::::::::::::::yyymmmmmmmmo++hNNmdd ``+hhdmmdhhhhh+:::::::::::::::::::::::::::::::::::::::::::::::/hhhhhdmmmmmsoo... ``+ddmmmdhhhhhyyyyyyyyyyyo:::::::::::::::::::::::::::::::::::::+++++sdddmmdhhsss//+ ``+mmmmmhsshhhhhhhhhhhhhhy++/:::::::::::::::::::::::::::::::::::::::+ssyyydmmddd///hhd ``+mmmmmy::shhhhhhhhhhhhhhhhs:::::::::::::::::::::::::::::::::::::::::::::ymmmmmmmh../ ``+mmmmmy:://////////////ohhhyy+::::::::::::::::::::::::::::::::::::::::::///hddmmmhhs++s ``+mmmmmhssssssssssssssssydddddysssssssssssssssssssssssssssssssssssssssssssssdddmmmmmy::s ``+mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmhooh

 

Link to comment
Share on other sites

Link to post
Share on other sites

I think it may go deeper then this.

What I mean is that, Bing gives user back a small percentage return from the money they make as points (exchangeable for money via gift cards or give as donations or as tickets to get a chance to win MS Stores prices such as Surface's, laptops, etc.). I won't be surprise if there is work being put where the malware makers gets the clicks from people searches to its account to get these points.

 

Considering that Bing is actually pretty good based on my 3 month challenge, where only 1 or twice a week I had to switch to Google for better results (I am a dev, and I sometimes I do very specific searches), I am sure the presented results added in the Google page are pretty good.

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, ImAyaanKhan said:

Yeah, they still have it via microsoft rewards. Takes ages to get points bc its 5 per search with a 50 point a day limit, and you have to spend like 1.3k points for a 1.25 cent gift card

6,550 points gives you a 5$ Starbucks gift card. It is worth more the points if you get XBox or MS Store gift cards instead.

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, Gegger said:

it's 150 on pc, 50 on mobile

Oh, sorry, I haven't used it in so long I forgot

Current PC (Second Build) : CPU: Ryzen 5 1600 (OC @3.8GHz, sometimes pushed to 4GHz) RAM: 16gb Corsair Vengeance RGB Pro DDR4-2666 (OC @2733Mhz, sometimes pushed to 2800 for testing purposes)   GPU: PowerColor Radeon RX570 8gb MOBO: ASRock B450m Pro4 SSD: Inland 120gb HDD: 1tb Seagate Barracuda PSU: Cooler Master Masterwatt 500w Lite Case: NZXT H500 OS: Arch Linux+ KDE Plasma [Desktop Environment] & Windows 10 Pro [Broken due to grub 50% of the time]

 

Accessories: Mouse: Alienware AW958 Elite Keyboard: Corsair K63 Wireless  Headphones: Samsung Level On Pro

 

Phone (waiting on arrival): Samsung Galaxy Note 9

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×