Video: Techniques of the web criminal in 2008
Sophos releases videos of two of the most popular ways that the new breed of web criminal has targeted internet surfers this year.

Security firm Sophos has released two videos which highlight common ways that cybercriminals have been regularly exploiting the web in 2008.
One of these is the fake anti-virus attack or what Sophos calls scareware'. This is where a legitimate website has been compromised and is stuffed with keywords making them attractive in a Google search.
The homepage will have been modified with appended links to the malicious web page. It will also have been modified with obfuscated JavaScript, which will silently redirect the user to the fake anti-virus site.
Here it will alert you to the problem, and urge you to download security software. However this is actually a Trojan downloader, and instead of security software you've got malware.
Snickerdoodle cookies and fake anti-virus software
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Another threat was that of the comment section of a legitimate website, where users have linked to fake website, - in this case porn.
Once you have clicked or pasted in the link it says you can only watch the chosen video if you have downloaded a codec. Its insistent that you download an executable file, and once you have down this, the malware is now on your computer.
Malicious porn spammers lead to malware
Sophos also recently released its security threat report and new computerised virus images this month.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
96% of SMBs are missing critical cybersecurity skills – here's why
News The skills shortage hits SMBs worse as they often suffer from a lack of budget and resources
By George Fitzmaurice Published
-
Sophos Firewall Virtual review: Affordable network protection for those that like it virtualized
Reviews Extreme network security that's cheaper than a hardware appliance and just as easy to deploy
By Dave Mitchell Published
-
MSPs are struggling with cyber security skills shortages
News A shortage of tools and difficulties keeping pace with solutions were also ranked as key issues for MSPs
By George Fitzmaurice Published
-
Nearly 70 software vendors sign up to CISA’s cyber resilience program
News Major software manufacturers pledge to a voluntary framework aimed at boosting cyber resilience of customers across the US
By Solomon Klappholz Published
-
Sophos and Tenable team up to launch new managed risk service
News The new fully managed service aims to help organizations manage and protect external attack surfaces
By Daniel Todd Published
-
Ransomware groups are using media coverage to coerce victims into paying
News Threat actors are starting to see the benefits of a more sophisticated media strategy for extracting ransoms
By Solomon Klappholz Published
-
Shrinking cyber attack “dwell times” highlight growing war of attrition with threat actors
News While teams are becoming more proficient at detecting threats, attackers are augmenting their strategies
By Ross Kelly Published
-
Cyber security in the retail sector
Whitepapers Retailers need to ensure their business operations and internal data aren't breached
By ITPro Published