Our Goal

Our goal here, or mission statement if you will, is to stamp out malicious software on the internet. Whether it be adware, spyware, malware, or viruses... we aim to find products to keep your computer safe. There is way too much junk on the net these days, stay safe!

What You'll Find

spyware, spyware removal, remove spyware, spyware protection, free spyware removal, spyware remove, spyware detector, spyware detection, spyware killer, free spyware detection, free spyware, malware, adware, spyware removal program, anti-virus, free software, prevention, protection

Fake GoogleTalk Application In The Wild

We’re still trying to pin down exactly how new this is, but it seems someone has released a fake Google Talk application into the wild.

Compare the fake application on the left with the real thing on the right, and note the differences:

fakereal.jpg

Immediately, we can see that the real thing has a rounded curve at the top – the fake is blocky, and looks like a regular Windows application box. There’s an “Inbox” link at the top when you start up the fake application – there isn’t a link like that when firing up Google Talk for the first time. The Username / Password box is much lower down on the fake application, and (again) the real “Sign In” button is curved on the real application. Finally, you’ll see “Forgot your account / Don’t have an account” on the genuine Google Talk program – not so on the fake.

How does this work?

Well, the program doesn’t connect to the Internet – for this attack to be successful, the hacker needs physical access to a PC that lots of people use. Could be a workplace PC, could be in a school, library, Net Cafe – anywhere where it’s possible to run an executable file then retreat to a safe distance while the potential victim sits down and thinks “Just need to check something on IM…”

Assuming the victim enters their login details into the fake application, they will immediately see a fake error message, and probably think no more of it:

fakegoog2.jpg

Once they’ve finished whatever they were doing and left the PC, the attacker only has to sit down and browse to the C Drive where they’ll see this:

fakegoog3.jpg

As you probably guessed, any all login details typed into the fake application will be stored in this text file:

fakegoog4.gif

We detect this application as Fake Googletalk.

Research Summary Write-Up: Chris Boyd, Director of Malware Research
Additional Research: Chris Mannon, FSL Senior Threat Researcher

If you enjoyed this post, make sure you subscribe to my RSS feed!

Leave a Reply

Subscribe to Comments?

Spam Protection by WP-SpamFree Plugin

RECENTCOMMENTS

  • None found

MOSTCOMMENTS

  • None found

Recent Readers. These are the cool and trendy people that reads my blog!Recent Readers

My New PriusBryan & JeriPoor GuyHard @ WorkReading Light FailI'm A MacI Am Obviously The Strongest Man AliveJohn Chow Style