Go To Google Groups. Get Tricked Into Downloading Malware. Do Not Pass Go
by Duncan Riley on January 29, 2008

ggmalware.jpg

Above is a shot of one of many spam blog comments I’ve received lately with multiple links to pages on Google Groups.

Spammers have always targeted Google products, and services such as Blogger have always been a favorite destination for spammers. Google Groups isn’t as well known as a spam platform, but after some investigation I found that it has become a leading destination for those seeking Google search results for various offers.

There is varying forms of spam across Google’s platform. Most spam sites usually serve as gateways to various affiliate programs (particularly porn and meds), and although they’re not welcome by most, they’re fairly harmless in the scale of things. The links above however are in a different category.

Following one of the links above takes you to a page like this one (link tagged nofollow). The title (in this case) on the Google Groups page says “Free rachel starr trailer in PORNO!!!,” then presents what looks like a YouTube embed complete with the spinning loading wheel. Directly below that is “click here to see the movie.” Clicking there takes you to a page that is mocked up to look like Porntube, but isn’t. No links here because the content is most definitely NSFW. Clicking on one of the videos shown immediately creates an ActiveX error, and suggests that you should download a plugin to fix it. Suffice to say the plugin is an .exe file, so it’s targeted at Windows users, but its safe to say that what ever it is, it wouldn’t be wise to install it.

The problem of spam on Google Groups isn’t new, I found articles going back two years discussing spam pages on Google Groups, so the question then becomes: if this has been going on for years, why hasn’t Google acted? Surely if Google can track down and punish users of services such as PayPerPost or those running text link ads it could find spammers using its own services to direct users to download malware? or is it that it’s easier to target others than look after your own backyard?

Comments

How is it possible that when ” You ” conduct a poll to see who you will endorse to represent the parties for President that when the results come back ” YOU CHANGE YOU POLL? Ron Paul DOES support Education! He wants the States to take care of it! He wants Parents to be Responsible! That is the way the Constitution states it.

 

Bob
wrong post son, wrong post.

 

lol !

and the moral of the story is ….. ?

 

I’ve been annoyed by the spam on Google Groups. For example, I wanted to discuss a Google Labs product called Sets, and all I get on the forum are adverts for Nike trainers from Chinese sources.

 

Lately you’ve pushed Grouply too much. This sounds like another push to me. What’s your motivation? Journalism?

 

oops
Grouply? WTF? I’m highlighting a deficiency in Google, not pushing anyone other than hopefully some one asleep at the wheel at Google who might be able to fix this.

 

Duncan, let’s see what’s gonna be your next post… it’s a subliminal message after so many Grouply posts.

 

or at least, looks like… no offense.

 

oops
I checked, I’ve written ONE post on Grouply (and I had to check, because I didn’t remember the company), and it was about a round of funding with ZERO endorsement of the product. You’re confusing me with Nick. If you’re going to troll, at least try to get it right :-)
http://www.techcrunch.com/tag/grouply/

 

Spamming (especially the ActiveX error variety) is quite common and is prevalent everywhere..I’ve seen that on emails, social networks, too..Was Google Groups referred to just to give it a web 2.0 look?

 

you, Nick - you guys are all writing for Techcrunch, no, are you so independent? But that’s fine, I may be wrong of course, but that’s what I felt to be honest after all these posts one after another.

 

That fake Youtube embed spinning wheel is very clever.

 

oops,
let me give you a clue. I’m 180kms south of Perth in Western Australia, so colluding would be very hard. Also Grouply aggregates data from Yahoo and Google Groups, it’s not a standalone service nor even a competitor, so I’m still completely lost as to what you’re suggesting; this post is not even close to, nor is even remotely relevant to Grouply. If you’ve got an issue with Nick’s previous posts, take it up with him.

 

I run the website for a small event in Wisconsin, and I recently replaced an outgoing webmaster. Said webmaster inserted into our homepage (after the body tag so no one would immediately notice) a similar spam chunk which got us delisted from Google (and which caused me a small headache).

If Google can find the crap in OUR website, why the heck can’t it find it on it’s own?

 

Glad to see someone bringing this up.

I keep reporting these damn sites - they continually spam wikis with these google groups links.

 

“Surely if Google can track down and punish users of services such as PayPerPost or those running text link ads it could find spammers using its own services to direct users to download malware? or is it that it’s easier to target others than look after your own backyard?”

You just hit the nail squarely on the head.

 

Naked Mickey Mantle? WTF….

 

I’m impressed, why you guys from Techcrunch bother to answer some comments

 

As the old adage goes; it’s easier to clean up and organize someone else’s mess than it is your own.

 

Orkut is also rife with spam, but as yet Google has not made any effort to address the issue. I spent a whole 2 mins on one Orkut community and found at least 50 spam accounts that were still active and being used to spam users + communities.

 

If you’re going to troll, at least try to get it right

 

This should be proof enough that Google is its own operating system.

 

the captcha is hacked by russians!

 

Duncan, as someone who’s in the Spyware business, we love running into resources like these. We continually have to keep our Spyware database updated because our customers are always finding new ways to install these apps.

We are kind of unique as we believe that security is a service! That’s why we provide live 24/7 chat support to our customers both pre and post sale.

 

Leave a Reply

Create a Gravatar for your comments.
« Back to text comment