Scare Ware

What is Scare Ware

This is a cleverly designed site that when visited either by typing in a URL search or clicking on a link, will redirect a user to a site that was not intended. Some of these sites can be triggered by a simple dragging a mouse pointer over a hidden URL. The name of a scare ware site can be a misspelling of one of the hundreds of popular sites on the web. The metadata contained in the scare ware code is usually loaded with SEO (Search Engine Optimization) metadata that is related to the popular sites it is intentionally spelled similar too. Some have metadata that is loaded with the latest popular search terms. Deceiving users is the key.

Why is it called scare ware

These sites are designed to scare an uninformed user into making a rash decision. How is this done? These site will quickly (as in millionths of a second) scan through your PC looking for applications that are installed to mitigate viruses, spyware, and the like. During this scan the level of service that a user is subscribed will be obtained as well as other pertinent information. This provides an air of legitimacy to the user. Then the user will be bombarded with warnings that appear to be coming from whichever antivirus or spyware prevention software that is installed on the user's PC. These will be rather large pop-ups that mimic the familar software. Once the user clicks on the warning, this may trigger another pop-up informing the user that the subscription level they are paying for does not include this particular malware or virus that the warning triggered. Which is followed by a familar SSL payment portal that looks exactly (or close enough) like the antivirus software's payment portal. Most likely followed by another urgent warning to act now. By the way, none of the warings and pop-ups will go away. If the user manages to close one, this will cause two more to appear. The scare ware code will also provide a convincing name of the malware that urgently needs to be quarantined. Once the payment is processed a successful message will appear making the user have a feel better moment. This is why it is called scare ware.

Behind the scenes the code behind the scare ware site will be coded with obfuscation in mind. It can be terribly difficult to untangle the code used to create the scare ware. The user may not be aware they were scammed until their next credit card statement arrives. It will be the weird entry of a combination of letters and numbers that is not familiar. It is the amount paid that is recalled. But this is not the usual billing information associated with the antivirus/malware software. This is when the user may realize they were scammed.

What the scare ware criminals are relying on is a few important details. The payment was processed and received by the time a user figures out they were scammed. The user feeling foolish for being scammed mqy not insist on a refund. The credit card company will not take the time and effort to recover such a small amount. They will stonewall the customer until it is forgotten. The credit card company is aware that once the payment is processed it will be moved to a different account. Any requests to the receiver will be ignored.

What makes processing a refund difficult? The domain name, some misspelled site dot com, will be registered through a domain name registrar that is operating from a country that has very strict privacy laws concerning the information of the domain owner. None of the information related to the scare ware payment process is legally available to the credit card holder. To make a person extremely frustrated law enforcement will inform the user they are wasting their time. It is the privacy laws again. It would be pointless for a United States law enforcement agency to serve this registrar with any type of subpoena. It will be ignored. This is how scare ware generates income. Hundreds of sites scamming victims every day, from dozens of countries around the world with airtight privacy laws. If five-hundred sites generate $250.00 each per day, that's $125,000.00 per day. In a month these scare ware sites could generate $3,750,000.00.

What can be done

How can law enforcement get ahead of these scare ware operations? By having concrete evidence of an individual who is complicit in the operation of a scare ware site that resides within their jurisdiction. Her name is Thea Felice Magnusson. The image below proves that Ms. Magnusson has access to the code repository of a scare ware site. The two PDFs listed below the image are the actual code of the scare ware site Ms. Magnusson is complicit in. The other is a distribution network analysis that was derived from the actual code. Along with Ms. Magnusson, there other accomplices that reside within the jurisdiction of United States law enforcement agencies. The information related to these suspects are available to law enforcement. All they need do is ask.