Conficker Followed up by Scareware-Powered Spam

Preparation and persistence helped many to dodge the Conficker threat, and while many may have dodged that bullet, the war against malware is far from over. The recently released Microsoft Security Intelligence Report (SIR), which covers the final 6 months of 2008, indicates that rogue security software threats are on the rise. Those pieces of […]

Written By: Frank Ohlhorst
Apr 9, 2009
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Preparation and persistence helped many to dodge the Conficker threat, and while many may have dodged that bullet, the war against malware is far from over. The recently released Microsoft Security Intelligence Report (SIR), which covers the final 6 months of 2008, indicates that rogue security software threats are on the rise. Those pieces of malware, also known as scareware, has increased significantly and is duping users into revealing important information and opening access to their systems to parties unknown.

Scareware works by leveraging users’ fears of cyber-attacks by mimicking legitimate advertisements for products that “fix” infected systems. Users are enticed to pay for "full versions" of the offered product to protect their systems from Trojans, worms and other kinds of malware. In reality, both the free and paid for versions of the mock utilities offered are actually malware applications. Those who choose to pay for the mock security software are providing nefarious individuals with credit information, while those who choose to accept “free offers” are setting their systems up to be compromised remotely or at the very least, have their systems turned into zombies spewing spam on a botnet.

While we may thank the hype surrounding Conficker for increasing security awareness, one has to wonder how many new “victims” were recruited by the purveyors of scareware leveraging that hype. Add to that the re-emergence of some old worms, such as W32.Downadup and W32.Waledac, and it becomes easy to see that another malware and spam storm is on the horizon.

The .C  variant of W32.Downadup is particularly resilient,  it incorporates a previously unseen algorithm to remove itself from the infected host on May 3, 2009, removing most traces that the system has been infected and compromised. Of even greater concern is how W32.Downadup may be linked to W32.Waledac, which steals sensitive information, turns computers into spam zombies, and establishes a back door remote access.

The pieces are in play and users need to protect themselves from these new merged threats, which may be responsible for the latest increases in spam and have the potentially to power another round of fraudulent and malicious activity.

Luckily, protection should be simple, just as simple as Conficker – install the latest patches and make sure you are using legitimate anti-malware products. The old buyers axiom still reigns supreme – if it seems too good to be true – then it probably is.

The questions remain: Did Conficker actually succeed in a way not anticipated? Did thousands, if not millions of users download phony security tools to combat the Conficker threat?  Only time will answer those questions, and perhaps IT professionals will pull together to stamp out the coming threats.

 

Recommended for you...

Concentric AI Adds Integrations to Data Governance Platform

Concentric AI adds Wiz, Salesforce, and GitHub integrations to boost Semantic Intelligence platform’s AI-driven data governance and security capabilities.

Jordan Smith
Aug 15, 2025
Brivo Launching New Solution to Boost Security Suite

Brivo and Envoy partner to unify access control & visitor management, delivering scalable, compliant, and secure workplace experiences.

Jordan Smith
Aug 13, 2025
GitHub CEO Steps Down as Microsoft Tightens AI Integration

GitHub CEO Thomas Dohmke to step down in 2025 as Microsoft moves platform into CoreAI, deepening its role in the company’s AI development strategy.

Allison Francis
Aug 13, 2025
Backblaze CEO on GTM Strategy & AI Demand on M&E Datasets

Backblaze CEO on record growth, AI and M&E wins, and how new products and partnerships are driving enterprise cloud storage adoption.

Jordan Smith
Aug 13, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.