• Skip to primary navigation
  • Skip to main content
  • Skip to footer
OpSec Security

OpSec Blog

  • Events
  • Partners
  • Brand
      • OpSec protects your entire brand continuum, covering every facet of your product’s life cycle. From conception through consumers, both online and offline, we provide you with valuable insight to protect your revenue streams, product integrity, and brand reputation.

      • Licensing
      • Fashion & Apparel
      • Luxury Goods
      • Consumer Products
      • Automotive
      • Industrial
      • Pharma & Medical Devices
      • Transaction Cards
  • Government
      • Working closely with key commercial partners, government agencies and security specialists, we have earned a reputation as innovators in combining digital solutions with optical and material sciences.

      • Revenue Protection & Tax Stamps
      • Security Foils & Labels
      • Vehicle Protection & SecureETags
  • OpSec Online
      • OpSec Online includes an industry-leading product and service line to help brands combat brand abuse across all online spaces.

      • Why Brand Protection
      • AntiCounterfeiting
      • AntiPiracy – Digital Media
      • AntiFraud – Phishing
      • AntiFraud – Malware
      • Partner Compliance
      • Online Brand Protection
      • IP Protection
      • AntiPiracy – NetResult Live Streaming Protection
      • AntiFraud – Dark Web & Cyber Intelligence
      • Managed Services
  • Resources
  • About Us
      • In a world getting more complex, OpSec helps ensure the integrity of goods and documents that build deeper and more profitable relationships.

      • Leadership
      • Associations
      • Careers
  • Contact Us

SEO Poisoning: A Persistent Malware Threat Targeting High-Profile Brands

OpSec Security

by OpSec Security

antifraud | Brand Protection | Online Brand Protection

It’s bad enough that malware is virally spread via paid search and social networking links. But now there are more accounts of it being spread via natural search links as well. In a practice called SEO Poisoning fraudsters use Search Engine Optimization (SEO) techniques to mix malware-laden search results with legitimate ones. Many infected URLs are found within the top 10 search results and thus have a higher likelihood of a user clicking through.

Many of these attacks are targeting major product events and popular websites. Just last month for example two attacks (as reported by Websense) targeted the much anticipated Google Wave beta invitation and the Microsoft Securing Essentials (MSE) product launch. Earlier this year the March Madness basketball tournament was also targeted. In these situations fraudsters anticipated that people would be searching on these topics and leveraged black hat SEO techniques (such as keyword stuffing and link farms) to push their malware-linking results to the top of the search engine results page. While Google has automatic scanners for detecting and blacklisting malware sites there remains a window of opportunity for fraudsters to push their results to the top of the results page before being detected and expunged.

Another common SEO poisoning tactic takes advantage of a common practice used among popular websites caching search queries to boost the site’s ranking among the major search engines. While making search queries on these websites fraudsters inject common search terms and an iframe script (snippets of HTML code for us non-techies) designed to redirect visitors to malicious sites. These search queries then go back to the search engine with the malicious code attached. So when a user conducts a search on these common search terms relating to the popular website and clicks through on one of the infected links on the search engine results page he/she is redirected via the Javascript code to a compromised website where social engineering tactics often trick the user to install malware. These types of attacks have targeted such high-trafficked sites as ABCNews.com CNET properties News.com Target.com Walmart.com and Wired.com. (As an aside in all of these SEO poisoning attacks only the links in the natural search results not the website itself are infected.)

What can brand owners do to protect their brand from these attacks? First and foremost brand owners need to remain vigilant on how and where their brand is being used to preserve the trust in their brands especially around major product announcements. Malicious links are now found everywhere in organic and paid search results as well as blogs and micro-blogs so brand owners should take a holistic approach to monitoring for potential abuse across the entire Internet. If malware is detected on Google brand owners can report the suspected malware link via the Google Safe Browsing malware reporting page. Brand owners with search capabilities in their websites can also guard against the tactic described above by filtering out scripts in their search queries before the results are exchanged with the search engines. Finally enterprise anti-malware solutions such as our own provide brand owners with an efficient response for blacklisting and shutting down these sites and retrieving stolen information.”

antifraud, black hat, black hat seo, brand owners, fraud, malware, online brand protection, paid search, seo, Social Media, social network

OpSec Security

About OpSec Security

In a world getting more complex, OpSec helps ensure the integrity of goods and documents that build deeper and more profitable relationships.

Related Post

Confused businesswoman annoyed by online problem looking at laptop

OpSec Security 5 Min Read Mar 25, 2020

Prepare to be Scammed: How People Can Make the Difference

The year 2020 came in with a bang and it hasn’t let up yet. From the UK’s Brexit initiative, the US Presidential election ...

antiphishing, bec scam, business email compromise, covid, cyber security, cybercriminals, eac, eac scam, email scam, ncsc, phishing, scam, w-2

Surfers in the ocean

OpSec Security 2 Min Read Oct 25, 2019

Unpacking brand protection (in time for the holidays)

The internet has a lot to answer for. While both consumers and brands have the world at their fingertips thanks to the int...

antifraud, data protection, hospitality, online brand protection, online consumer, travel industry, travel protection

Access granted

OpSec Security 2 Min Read Oct 22, 2019

Deep diving into the dark web

Much of our perception of the dark web is limited to what we see on TV — a hub for criminals, illicit goods and illegal ac...

Brand Protection, customer education, dark web, data breach, deep web, hack, illicit goods

Footer

Careers

Be a part of a collaborative global team determined to fight counterfeits and build strong, lasting partnerships with our clients.

View Available Positions

Brand

  • Licensing
  • Fashion & Apparel
  • Luxury Goods
  • Consumer Products
  • Automotive
  • Industrial
  • Pharma & Medical Devices
  • Transaction Cards

Government Applications

  • Revenue Protection & Tax Stamps
  • Security Foils & Labels
  • Vehicle Protection & Secure eTags

© 2021, OpSec. All rights reserved. Modern Slavery Statement Privacy Terms Of Use Contact Us

Facebook Twitter LinkedIn YouTube Instagram