HomeSecurityEnd to a network of adware bots on Skype

End to a network of adware bots on Skype

Skype

Several scammers who were promoting adware to Skypesaw the bots they were using removed from the popular messenger, based on the network's new operating policy.

The scam involved fake calls to users, who believed they were receiving a new video message. The caller's username, however, included a link to a domain with malicious scripts hosted on the cloud . When the user selected the URL, the browser took them to a site that required the user to download and install a video player to view the supposed video message.

Researcher Ronnie Tokazowski found that despite the fact that a regular video player on the system, the installation process also includes other programs (some of which are questionable in their nature and functions), and he believes that they are part of some affiliate program, so that the scammers can make money from the installations.

The researcher wrote in a blog post last Wednesday about the installation process. Once the user runs the executable as an administrator, they are presented with a new screen with options to install different features of the program. Then, VideoPlayer.exe begins downloading and installing adware on the system.

However, upon closer inspection, Tokazowski determined that all of the IPs used in the campaign were from AWS. He immediately reported the matter to Amazon’s security team, and the issue was quickly resolved by removing the accounts. The scammers were using over 15 different domains for their scam.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS