Bizarre Google Search Risk Claim is Overhyped
Claims that typing "Are Bengal cats legal in Australia?" into Google could destroy your computer and empty your bank account are somewhat overblown. But beneath the hyperbole, there's an interesting tactic from hackers.
Numerous media sources have written stories about the supposed dangers of a "six word phrase" that users must not type for fear of exposing their personal data. The implication is that there's some sort of magical booby trap, but the reality is a little duller.
The problem was spotted by Sophos which noted that several of the top search results for the query about the cats were bogus websites, a so-called "SEO poisoning" campaign. In most cases, the sites would attempt to deliver malware to the user's computer, taking advantage of bugs and flaws in browsers.
Info Stealer Malware
It's a tactic sometimes dubbed a "drive by attack" because, when it works, it doesn't require any action by the victim other than visiting the site. In this case it seems to be an evolution of an existing malware campaign that disguised the files through links in posts on discussion forums.
The malware in question, Gootloader, is particularly nasty. Sophos describes it as a "highly evasive info stealer and remote access" which also acts as a route in for other attacks such as ransomware. (Source: sophos.com)
This all means that some of the presentation of the story isn't quite accurate: simply typing the phrase into Google isn't enough to cause any harm, it's clicking on the resulting links that causes problems.
Neither is there anything particularly special about the phrase "Are Bengal cats legal in Australia?" It's either the phrase the hackers are using to test their approach, or simply one among many variants of the attack that Sophos happened to spot.
Search Term Targeting
The real key is that the hackers are using the same targeting tactics that many legitimate website use when trying to attract an audience. They need to target a keyword that has enough interest to bring a big enough potential audience to make it worth building the website, but is obscure enough that there's limited competition and they stand a decent chance of getting high up in the rankings.
In this case the attackers are specifically targeting queries about Australia. This not only helps adjust the popularity/niche balance but also makes it more likely the victim will be comparatively financially well off.
And for anyone who is looking to answer the question, the Australian government says Bengal cats (a hybrid of an Asian leopard cat and a domestic cat) are legal, but can only be imported if there's documented proof the cross-breeding was at least five generations ago. (Source: gov.au)
What's Your Opinion?
Had you heard this story, including in the more scaremongering forms? Are you surprised at the tactic? Do you take more care when searching for particular phrases on Google?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Social engineering
Reminds me of PT Barnum.
But the internet adds an additional dimension: they don't have to pay to inside.
Remember the 900 telephone numbers? They were you call, you pay toll numbers.
This is very similar.
Create a seemingly innocuous phrase and get the curious to google it, thus driving traffic to your *maybe now, maybe later* infected site.
Caveat emptor