Russian Payment Processor May Be Behind MacDefender Scareware

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
SECURITY WRITER BRIAN KREBS MAY HAVE FOUND A LINK CONNECTING RUSSIAN PAYMENT PROCESSOR CHRONOPAY WITH SOME OF THE RECENT MAC SCAREWARE SOFTWARE IN CIRCULATION.

It appears that a Russian online payment company may be behind the rogue antivirus MacDefender scam that has dominated security headlines for the past few weeks.

A few days after the first attacks surfaced, users on Apple support forums reported that the Mac malware was directing them to mac-defence.com and macbookprotection.com to pay for the scareware, wrote Brian Krebs on May 27 on his Krebs on Security blog. Both of these domains have the “distinct fingerprint” of ChronoPay in their registration records, according to Krebs.

[attachment=352]

Both domains included the contact address fc@mail-eye.com in the WHOIS information, Krebs found. Several internal documents and emails were leaked after ChronoPay suffered a security breach last year, and those documents revealed that the company owns the mail-eye.com domain and operates it using virtual servers in Germany, according to Krebs. The records also indicated that the email address belonged to ChronoPay’s financial controller Alexandra Volkova. Krebs identified multiple Mac-security related domains that have not shown up in rogue antivirus scams, such as appledefence.com and appleprodefence.com.

More details - link
 

Attachments

  • cpmacmal.jpg
    cpmacmal.jpg
    126.2 KB · Views: 402

MrXidus

Super Moderator (Leave of absence)
Apr 17, 2011
2,503
Hmm interesting, Atleast the sites are now down and Apple is doing something about this scareware problem. I'm aware they released an update for MacDefender but I'm afraid it won't be long before another malicious incident happens with threats on Macs, Google first needs to fix the poisoning Google Images has.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Glad that it was trace from the responsible in the scareware from Mac better late than never.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top