<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Rogue security software</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Rogue_security_software"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Rogue_security_software rootpage-Rogue_security_software skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Rogue security software</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p><b>Rogue security software</b> is a form of <a href="Malware" title="Malware">malicious software</a> and <a href="Internet_fraud" title="Internet fraud">internet fraud</a> that misleads users into believing there is a <a href="Computer_virus" title="Computer virus">virus</a> on their computer and aims to convince them to pay for a fake <a href="Malware" title="Malware">malware</a> removal tool that actually installs malware on their computer.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> It is a form of <a href="Scareware" title="Scareware">scareware</a> that manipulates users through fear, and a form of <a href="Ransomware" title="Ransomware">ransomware</a>.<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> Rogue security software has been a serious security threat in desktop computing since 2008.<sup id="cite_ref-microsoft-1_3-0" class="reference"><a href="#cite_note-microsoft-1-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> An early example that gained infamy was <a href="SpySheriff" title="SpySheriff">SpySheriff</a> and its clones,<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>a<span class="cite-bracket">]</span></a></sup> such as Nava Shield.
</p><p>With the rise of cyber-criminals and a black market with thousands of organizations and individuals trading exploits, malware, virtual assets, and credentials, rogue security software has become one of the most lucrative criminal operations.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Propagation">Propagation</h2></div>
<p>Rogue security software mainly relies on <a href="Social_engineering_(security)" title="Social engineering (security)">social engineering</a> (<a href="Fraud" title="Fraud">fraud</a>) to defeat the <a href="Security" title="Security">security</a> built into modern <a href="Operating_system" title="Operating system">operating system</a> and <a href="Web_browser" title="Web browser">browser software</a> and install itself onto victims' computers.<sup id="cite_ref-microsoft-1_3-1" class="reference"><a href="#cite_note-microsoft-1-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> A website may, for example, display a fictitious warning dialog stating that someone's machine is infected with a <a href="Computer_virus" title="Computer virus">computer virus</a>, and encourage them through <a href="Psychological_manipulation" class="mw-redirect" title="Psychological manipulation">manipulation</a> to install or purchase <a href="Scareware" title="Scareware">scareware</a> in the belief that they are purchasing genuine <a href="Antivirus_software" title="Antivirus software">antivirus software</a>.
</p><p>Most have a <a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horse</a> component, which users are misled into installing. The Trojan may be disguised as:
</p>
<ul><li>A browser <a href="Plug-in_(computing)" title="Plug-in (computing)">plug-in</a> or extension (typically toolbar)</li>
<li>An image, screensaver or <a href="File_archiver" title="File archiver">archive file</a> attached to an <a href="E-mail" class="mw-redirect" title="E-mail">e-mail</a> message</li>
<li>Multimedia <a href="Codec" title="Codec">codec</a> required to play a certain <a href="Digital_video" title="Digital video">video clip</a></li>
<li>Software shared on <a href="Peer-to-peer" title="Peer-to-peer">peer-to-peer</a> networks<sup id="cite_ref-symantec-2_5-0" class="reference"><a href="#cite_note-symantec-2-5"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup></li>
<li>A free online malware-scanning service<sup id="cite_ref-symantec-3_6-0" class="reference"><a href="#cite_note-symantec-3-6"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Some rogue security software, however, propagate onto users' computers as <a href="Drive-by_download" title="Drive-by download">drive-by downloads</a> which exploit <a href="Vulnerability_(computing)" class="mw-redirect" title="Vulnerability (computing)">security vulnerabilities</a> in web browsers, PDF viewers, or email clients to install themselves without any manual interaction.<sup id="cite_ref-symantec-2_5-1" class="reference"><a href="#cite_note-symantec-2-5"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-blog_adobe_7-0" class="reference"><a href="#cite_note-blog_adobe-7"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>More recently, malware distributors have been utilizing <a href="Spamdexing" title="Spamdexing">SEO poisoning</a> techniques by pushing infected <a href="URL" title="URL">URLs</a> to the top of search engine results about recent news events. People looking for articles on such events on a search engine may encounter results that, upon being clicked, are instead redirected through a series of sites<sup id="cite_ref-fsecure_8-0" class="reference"><a href="#cite_note-fsecure-8"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> before arriving at a landing page that says that their machine is infected and pushes a download to a "trial" of the rogue program.<sup id="cite_ref-eweek_9-0" class="reference"><a href="#cite_note-eweek-9"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-sc-magazine_10-0" class="reference"><a href="#cite_note-sc-magazine-10"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> A 2010 study by <a href="Google" title="Google">Google</a> found 11,000 domains hosting fake anti-virus software, accounting for 50% of all malware delivered via internet advertising.<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p><p><a href="Cold-calling" class="mw-redirect" title="Cold-calling">Cold-calling</a> has also become a vector for distribution of this type of malware, with callers often claiming to be from "Microsoft Support" or another legitimate organization.<sup id="cite_ref-coldcallscam_12-0" class="reference"><a href="#cite_note-coldcallscam-12"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Common_infection_vectors">Common infection vectors</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Black_Hat_SEO">Black Hat SEO</h3></div>
<p>Black Hat <a href="Search_engine_optimization" title="Search engine optimization">search engine optimization</a> (SEO) is a technique used to trick search engines into displaying malicious <a href="URL" title="URL">URLs</a> in search results. The malicious webpages are filled with popular keywords in order to achieve a higher ranking in the search results. When the end user searches the web, one of these infected webpages is returned. Usually the most popular keywords from services such as <a href="Google_Trends" title="Google Trends">Google Trends</a> are used to generate webpages via PHP scripts placed on the compromised website. These <a href="PHP" title="PHP">PHP</a> scripts will then monitor for search engine crawlers and feed them with specially crafted webpages that are then listed in the search results. Then, when the user searches for their keyword or images and clicks on the malicious link, they will be redirected to the Rogue security software payload.<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-auto_14-0" class="reference"><a href="#cite_note-auto-14"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Malvertising">Malvertising</h3></div>
<p>Most websites usually employ third-party services for advertising on their webpages. If one of these advertising services is compromised, they may end up inadvertently infecting all of the websites using their service by advertising rogue security software.<sup id="cite_ref-auto_14-1" class="reference"><a href="#cite_note-auto-14"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Spam_campaigns">Spam campaigns</h3></div>
<p><a href="Email_spam" title="Email spam">Spam</a> messages that include malicious attachments, links to binaries and drive-by download sites are another common mechanism for distributing rogue security software. Spam emails are often sent with content associated with typical day-to-day activities such as parcel deliveries, or taxation documents, designed to entice users to click on links or run attachments. When users succumb to these kinds of social engineering tricks they are quickly infected either directly via the attachment, or indirectly via a malicious website. This is known as a drive-by download. Usually in drive-by download attacks the malware is installed on the victim's machine without any interaction or awareness and occurs simply by visiting the website.<sup id="cite_ref-auto_14-2" class="reference"><a href="#cite_note-auto-14"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Operation">Operation</h2></div>
<p>Once installed, the rogue security software may then attempt to entice the user into purchasing a service or additional software by:
</p>
<ul><li>Alerting the user with the fake or simulated detection of malware or <a href="Pornography" title="Pornography">pornography</a>.<sup id="cite_ref-ftc-1_15-0" class="reference"><a href="#cite_note-ftc-1-15"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup></li>
<li>Displaying an animation simulating a system crash and reboot.<sup id="cite_ref-microsoft-1_3-2" class="reference"><a href="#cite_note-microsoft-1-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup></li>
<li>Selectively disabling parts of the system to prevent the user from uninstalling the malware. Some may also prevent anti-malware programs from running, disable automatic <a href="System_software" title="System software">system software</a> updates and block access to websites of anti-malware vendors.</li>
<li>Installing actual malware onto the computer, then alerting the user after "detecting" them. This method is less common as the malware is likely to be detected by legitimate <a href="Malware#Malware" title="Malware">anti-malware programs</a>.</li>
<li>Altering system registries and security settings, then "alerting" the user.</li></ul>
<p>Developers of rogue security software may also entice people into purchasing their product by claiming to give a portion of their sales to a charitable cause. The rogue Green antivirus, for example, claims to donate $2 to an environmental care program for each sale made.
</p><p>Some rogue security software overlaps in function with <a href="Scareware" title="Scareware">scareware</a> by also:
</p>
<ul><li>Presenting offers to fix urgent performance problems or perform essential maintenance on the computer.<sup id="cite_ref-ftc-1_15-1" class="reference"><a href="#cite_note-ftc-1-15"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup></li>
<li>Scaring the user by presenting authentic-looking pop-up warnings and security alerts, which may mimic actual system notices.<sup id="cite_ref-microsoft-3_16-0" class="reference"><a href="#cite_note-microsoft-3-16"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> These are intended to use the trust that the user has in vendors of legitimate security software.<sup id="cite_ref-microsoft-1_3-3" class="reference"><a href="#cite_note-microsoft-1-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Sanction by the FTC and the increasing effectiveness of anti-malware tools since 2006 have made it difficult for <a href="Spyware" title="Spyware">spyware</a> and <a href="Adware" title="Adware">adware</a> distribution networks—already complex to begin with<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>—to operate profitably.<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> Malware vendors have turned instead to the simpler, more profitable <a href="Business_model" title="Business model">business model</a> of rogue security software, which is targeted directly at users of <a href="Personal_computer" title="Personal computer">desktop computers</a>.<sup id="cite_ref-symantec-1_19-0" class="reference"><a href="#cite_note-symantec-1-19"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p>Rogue security software is often distributed through highly lucrative <a href="Affiliate_network" title="Affiliate network">affiliate networks</a>, in which affiliates supplied with Trojan kits for the software are paid a fee for every successful installation, and a commission from any resulting purchases. The affiliates then become responsible for setting up infection vectors and distribution infrastructure for the software.<sup id="cite_ref-symantec-4_20-0" class="reference"><a href="#cite_note-symantec-4-20"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> An investigation by security researchers into the Antivirus XP 2008 rogue security software found just such an affiliate network, in which members were grossing commissions upwards of $<a href="US_dollar" class="mw-redirect" title="US dollar">USD</a>150,000 over 10 days, from tens of thousands of successful installations.<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</p><p>Despite its use of old-fashioned and somewhat unsophisticated techniques, rogue security software has become a significant security threat, due to the size of the impacted populations, the number of different variants that have been unleashed (over 250), and the profits that have been made for <a href="Cyber_criminals" class="mw-redirect" title="Cyber criminals">cyber-criminals</a> (over $300,000 a month).<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Countermeasures">Countermeasures</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Private_efforts">Private efforts</h3></div>
<p>Law enforcement and legislation in all countries are slow to react to the appearance of rogue security software. In contrast, several private initiatives providing discussion forums and lists of dangerous products were founded soon after the appearance of the first rogue security software. Some reputable vendors, such as Kaspersky,<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup> also began to provide lists of rogue security software. In 2005, the Anti-Spyware Coalition was founded, a coalition of anti-spyware software companies, academics, and consumer groups.
</p><p>Many of the private initiatives were initially informal discussions on general <a href="Internet_forum" title="Internet forum">Internet forums</a>, but some were started or even entirely carried out by individual people. The perhaps most famous and extensive one is the Spyware Warrior list of rogue/suspect antispyware products and websites by Eric Howes,<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> which has however not been updated since May 2007. The website recommends checking the following websites for new rogue anti-spyware programs, most of which are not really new and are "simply re-branded clones and knockoffs of the same rogue applications that have been around for years."<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Government_efforts">Government efforts</h3></div>
<p>In December 2008, the <a href="United_States_District_Court_for_the_District_of_Maryland" title="United States District Court for the District of Maryland">US District Court for Maryland</a>—at the request of the <a href="Federal_Trade_Commission" title="Federal Trade Commission">FTC</a>—issued a <a href="Injunction" title="Injunction">restraining order</a> against Innovative Marketing Inc, a <a href="Kyiv" title="Kyiv">Kyiv</a>-based firm producing and marketing the rogue security software products <a href="WinFixer" title="WinFixer">WinFixer</a>, <a href="WinAntivirus" class="mw-redirect" title="WinAntivirus">WinAntivirus</a>, <a href="DriveCleaner" class="mw-redirect" title="DriveCleaner">DriveCleaner</a>, <a href="ErrorSafe" class="mw-redirect" title="ErrorSafe">ErrorSafe</a>, and <a href="XP_Antivirus" class="mw-redirect" title="XP Antivirus">XP Antivirus</a>.<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> The company and its US-based web host, ByteHosting Internet Hosting Services LLC, had their assets frozen, were barred from using <a href="Domain_name_system" class="mw-redirect" title="Domain name system">domain names</a> associated with those products and any further advertisement or false representation.<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p><p>Law enforcement has also exerted pressure on banks to shut down merchant gateways involved in processing rogue security software purchases. In some cases, the high volume of <a href="Credit_card" title="Credit card">credit card</a> <a href="Chargeback" title="Chargeback">chargebacks</a> generated by such purchases has also prompted processors to take action against rogue security software vendors.<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Anti-virus" class="mw-redirect" title="Anti-virus">Anti-virus</a></li>
<li><a href="Privacy" title="Privacy">Privacy</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Technical_support_scam" title="Technical support scam">Technical support scam</a></li>
<li>Winwebsec</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Notes">Notes</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-lower-alpha">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text">The clones of SpySheriff are BraveSentry, Pest Trap, SpyTrooper, Adware Sheriff, SpywareNo, SpyLocked, SpywareQuake, SpyDawn, AntiVirGear, SpyDemolisher, System Security, SpywareStrike, SpyShredder, Alpha Cleaner, SpyMarshal, Adware Alert, Malware Stopper, Mr. Antispy, Spycrush, SpyAxe, MalwareAlarm, VirusBurst, VirusBursters, DIARemover, AntiVirus Gold, Antivirus Golden, SpyFalcon, and TheSpyBot/SpywareBot.</span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.bumc.bu.edu/it/infosec/prevention/rogue/">"Rogue Security Software » BUMC Information Technology | Boston University"</a>. <i>www.bumc.bu.edu</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-11-13</span></span>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20120515123212/http://eval.symantec.com/mktginfo/enterprise/white_papers/b-symc_report_on_rogue_security_software_exec_summary_20326021.en-us.pdf">"Symantec Report on Rogue Security Software"</a> <span class="cs1-format">(PDF)</span>. Symantec. 2009-10-28. Archived from <a rel="nofollow" class="external text" href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-symc_report_on_rogue_security_software_exec_summary_20326021.en-us.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2012-05-15<span class="reference-accessdate">. Retrieved <span class="nowrap">2010-04-15</span></span>.</cite></span>
</li>
<li id="cite_note-microsoft-1-3"><span class="mw-cite-backlink">^ <a href="#cite_ref-microsoft-1_3-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-microsoft-1_3-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-microsoft-1_3-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-microsoft-1_3-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=aa6e0660-dc24-4930-affd-e33572ccb91f&displaylang=en">"Microsoft Security Intelligence Report volume 6 (July - December 2008)"</a>. <a href="Microsoft" title="Microsoft">Microsoft</a>. 2009-04-08. p. 92<span class="reference-accessdate">. Retrieved <span class="nowrap">2009-05-02</span></span>.</cite></span>
</li>
<li id="cite_note-symantec-2-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-symantec-2_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-symantec-2_5-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFDoshi2009" class="citation cs2">Doshi, Nishant (2009-01-19), <a rel="nofollow" class="external text" href="https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=469f4d10-0ca5-4bd7-8c3b-ae3c8cb56243&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments"><i>Misleading Applications – Show Me The Money!</i></a>, <a href="NortonLifeLock" class="mw-redirect" title="NortonLifeLock">Symantec</a><span class="reference-accessdate">, retrieved <span class="nowrap">2016-03-22</span></span></cite></span>
</li>
<li id="cite_note-symantec-3-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-symantec-3_6-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFDoshi2009" class="citation cs2">Doshi, Nishant (2009-01-21), <a rel="nofollow" class="external text" href="https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=cdbf390b-d72a-4d75-a364-018ce76f09d5&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments"><i>Misleading Applications – Show Me The Money! (Part 2)</i></a>, <a href="NortonLifeLock" class="mw-redirect" title="NortonLifeLock">Symantec</a><span class="reference-accessdate">, retrieved <span class="nowrap">2016-03-22</span></span></cite></span>
</li>
<li id="cite_note-blog_adobe-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-blog_adobe_7-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html">"News Adobe Reader and Acrobat Vulnerability"</a>. blogs.adobe.com<span class="reference-accessdate">. Retrieved <span class="nowrap">25 November</span> 2010</span>.</cite></span>
</li>
<li id="cite_note-fsecure-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-fsecure_8-0">^</a></b></span> <span class="reference-text">
<cite id="CITEREFChuHong2009" class="citation cs2">Chu, Kian; Hong, Choon (2009-09-30), <a rel="nofollow" class="external text" href="http://www.f-secure.com/weblog/archives/00001779.html"><i>Samoa Earthquake News Leads To Rogue AV</i></a>, <a href="F-Secure" title="F-Secure">F-Secure</a><span class="reference-accessdate">, retrieved <span class="nowrap">2010-01-16</span></span></cite></span>
</li>
<li id="cite_note-eweek-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-eweek_9-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFHines2009" class="citation cs2">Hines, Matthew (2009-10-08), <a rel="nofollow" class="external text" href="https://web.archive.org/web/20091221073322/http://securitywatch.eweek.com/seo/malware_distributors_mastering_news_seo.html"><i>Malware Distributors Mastering News SEO</i></a>, <a href="EWeek" title="EWeek">eWeek</a>, archived from <a rel="nofollow" class="external text" href="http://securitywatch.eweek.com/seo/malware_distributors_mastering_news_seo.html">the original</a> on 2009-12-21<span class="reference-accessdate">, retrieved <span class="nowrap">2010-01-16</span></span></cite></span>
</li>
<li id="cite_note-sc-magazine-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-sc-magazine_10-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFRaywood2010" class="citation cs2">Raywood, Dan (2010-01-15), <a rel="nofollow" class="external text" href="https://web.archive.org/web/20141029225846/http://www.scmagazineuk.com/rogue-anti-virus-prevalent-on-links-that-relate-to-haiti-earthquake-as-donors-encouraged-to-look-carefully-for-genuine-sites/article/161431/"><i>Rogue anti-virus prevalent on links that relate to Haiti earthquake, as donors encouraged to look carefully for genuine sites</i></a>, SC Magazine, archived from <a rel="nofollow" class="external text" href="http://www.scmagazineuk.com/rogue-anti-virus-prevalent-on-links-that-relate-to-haiti-earthquake-as-donors-encouraged-to-look-carefully-for-genuine-sites/article/161431/">the original</a> on 2014-10-29<span class="reference-accessdate">, retrieved <span class="nowrap">2010-01-16</span></span></cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite id="CITEREFMoheeb_Abu_Rajab_and_Luca_Ballard2010" class="citation journal cs1">Moheeb Abu Rajab and Luca Ballard (2010-04-13). <a rel="nofollow" class="external text" href="http://krebsonsecurity.com/wp-content/uploads/2010/04/leet10.pdf">"The Nocebo Effect on the Web: An Analysis of Fake Anti-Virus Distribution"</a> <span class="cs1-format">(PDF)</span><span class="reference-accessdate">. Retrieved <span class="nowrap">2010-11-18</span></span>.</cite> <span class="cs1-visible-error citation-comment"><code class="cs1-code">{{cite journal}}</code>: </span><span class="cs1-visible-error citation-comment">Cite journal requires <code class="cs1-code">|journal=</code> (help)</span></span>
</li>
<li id="cite_note-coldcallscam-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-coldcallscam_12-0">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://www.bbc.co.uk/news/uk-11754487">"Warning over anti-virus cold-calls to UK internet users"</a>. <i>BBC News</i>. 2010-11-15<span class="reference-accessdate">. Retrieved <span class="nowrap">7 March</span> 2012</span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.sophos.com/en-us/why-sophos/our-people/technical-papers/sophos-seo-insights.aspx">"Sophos Technical Papers - Sophos SEO Insights"</a>. <i>sophos.com</i>.</cite></span>
</li>
<li id="cite_note-auto-14"><span class="mw-cite-backlink">^ <a href="#cite_ref-auto_14-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-auto_14-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-auto_14-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophosfakeantivirusjourneyfromtrojantpna.pdf?la=en.pdf?dl=true">"Sophos Fake Antivirus Journey from Trojan tpna"</a> <span class="cs1-format">(PDF)</span>.</cite></span>
</li>
<li id="cite_note-ftc-1-15"><span class="mw-cite-backlink">^ <a href="#cite_ref-ftc-1_15-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ftc-1_15-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation cs2"><a rel="nofollow" class="external text" href="https://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt121.shtm"><i>"Free Security Scan" Could Cost Time and Money</i></a>, <a href="Federal_Trade_Commission" title="Federal Trade Commission">Federal Trade Commission</a>, 2008-12-10<span class="reference-accessdate">, retrieved <span class="nowrap">2009-05-02</span></span></cite></span>
</li>
<li id="cite_note-microsoft-3-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-microsoft-3_16-0">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://www.yahoo.com/news/sap-crossroads-losing-1-3b-verdict.html">"SAP at a crossroads after losing $1.3B verdict"</a>. <i><a href="Yahoo!_News" class="mw-redirect" title="Yahoo! News">Yahoo! News</a></i>. 24 November 2010<span class="reference-accessdate">. Retrieved <span class="nowrap">25 November</span> 2010</span>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation cs2"><a rel="nofollow" class="external text" href="http://www.cdt.org/testimony/20050511schwartzspyware.pdf"><i>Testimony of Ari Schwartz on "Spyware"</i></a> <span class="cs1-format">(PDF)</span>, <a href="Senate_Committee_on_Commerce%2C_Science%2C_and_Transportation" class="mw-redirect" title="Senate Committee on Commerce, Science, and Transportation">Senate Committee on Commerce, Science, and Transportation</a>, 2005-05-11</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite id="CITEREFLeyden2009" class="citation web cs1">Leyden, John (2009-04-11). <a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2009/04/21/zango">"Zango goes titsup: End of desktop adware market"</a>. <i>The Register</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2009-05-05</span></span>.</cite></span>
</li>
<li id="cite_note-symantec-1-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-symantec-1_19-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFCole2006" class="citation cs2">Cole, Dave (2006-07-03), <a rel="nofollow" class="external text" href="https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=209b435c-c8cf-4394-baea-4cbe466b267f&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments"><i>Deceptonomics: A Glance at The Misleading Application Business Model</i></a>, <a href="NortonLifeLock" class="mw-redirect" title="NortonLifeLock">Symantec</a><span class="reference-accessdate">, retrieved <span class="nowrap">2016-03-22</span></span></cite></span>
</li>
<li id="cite_note-symantec-4-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-symantec-4_20-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFDoshi2009" class="citation cs2">Doshi, Nishant (2009-01-27), <a rel="nofollow" class="external text" href="https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=5d5c4b41-a94b-43e3-b959-bfd3c77992ec&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments"><i>Misleading Applications – Show Me The Money! (Part 3)</i></a>, <a href="NortonLifeLock" class="mw-redirect" title="NortonLifeLock">Symantec</a><span class="reference-accessdate">, retrieved <span class="nowrap">2016-03-22</span></span></cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite id="CITEREFStewart" class="citation web cs1">Stewart, Joe. <a rel="nofollow" class="external text" href="https://www.secureworks.com/research/rogue-antivirus-part-2">"Rogue Antivirus Dissected - Part 2"</a>. <i>Secureworks.com</i>. SecureWorks<span class="reference-accessdate">. Retrieved <span class="nowrap">9 March</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite id="CITEREFCovaLeitaThonnardKeromytis2009" class="citation book cs1">Cova, Marco; Leita, Corrado; Thonnard, Olivier; Keromytis, Angelos; Dacier, Marc (2009). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/5494349"><i>Gone Rogue: An Analysis of Rogue Security Software Campaigns</i></a>. pp. <span class="nowrap">1–</span>3. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FEC2ND.2009.8">10.1109/EC2ND.2009.8</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-4244-6049-6</bdi><span class="reference-accessdate">. Retrieved <span class="nowrap">2024-02-09</span></span>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://support.kaspersky.com/viruses/rogue">"Safety 101"</a>. <i>support.kaspersky.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">11 November</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.spywarewarrior.com/rogue_anti-spyware.htm">"Spyware Warrior: Rogue/Suspect Anti-Spyware Products & Web Sites"</a>. <i>spywarewarrior.com</i>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.bleepingcomputer.com/virus-removal/">"Virus, Spyware, & Malware Removal Guides"</a>. <i>BleepingComputer</i>.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite class="citation cs2"><a rel="nofollow" class="external text" href="https://www.ftc.gov/os/caselist/0723137/081203innovativemrktgtro.pdf"><i>Ex Parte Temporary Restraining Order RDB08CV3233</i></a> <span class="cs1-format">(PDF)</span>, <a href="United_States_District_Court_for_the_District_of_Maryland" title="United States District Court for the District of Maryland">United States District Court for the District of Maryland</a>, 2008-12-03<span class="reference-accessdate">, retrieved <span class="nowrap">2009-05-02</span></span></cite></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><cite id="CITEREFLordan2008" class="citation cs2">Lordan, Betsy (2008-12-10), <a rel="nofollow" class="external text" href="https://www.ftc.gov/opa/2008/12/winsoftware.shtm"><i>Court Halts Bogus Computer Scans</i></a>, <a href="Federal_Trade_Commission" title="Federal Trade Commission">Federal Trade Commission</a><span class="reference-accessdate">, retrieved <span class="nowrap">2009-05-02</span></span></cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite id="CITEREFKrebs2009" class="citation cs2">Krebs, Brian (2009-03-20), <a rel="nofollow" class="external text" href="https://archive.today/20120723064537/http://voices.washingtonpost.com/securityfix/2009/03/sunlight_disinfects_rogue_anti.html">"Rogue Antivirus Distribution Network Dismantled"</a>, <i><a href="Washington_Post" class="mw-redirect" title="Washington Post">Washington Post</a></i>, archived from <a rel="nofollow" class="external text" href="http://voices.washingtonpost.com/securityfix/2009/03/sunlight_disinfects_rogue_anti.html">the original</a> on July 23, 2012<span class="reference-accessdate">, retrieved <span class="nowrap">2009-05-02</span></span></cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><span class="noviewer" typeof="mw:File"></span> Media related to <a href="https://commons.wikimedia.org/wiki/Category:Rogue_software" class="extiw external" title="commons:Category:Rogue software">Rogue software</a> at Wikimedia Commons</li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Malware_topics109" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div id="Malware_topics109" style="font-size:114%;margin:0 4em"><a href="Malware" title="Malware">Malware</a> topics</div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">Infectious malware</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Comparison_of_computer_viruses" title="Comparison of computer viruses">Comparison of computer viruses</a></li>
<li><a href="Computer_virus" title="Computer virus">Computer virus</a></li>
<li><a href="Computer_worm" title="Computer worm">Computer worm</a></li>
<li><a href="List_of_computer_worms" title="List of computer worms">List of computer worms</a></li>
<li><a href="Timeline_of_computer_viruses_and_worms" title="Timeline of computer viruses and worms">Timeline of computer viruses and worms</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Concealment</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Backdoor_(computing)" title="Backdoor (computing)">Backdoor</a></li>
<li><a href="Clickjacking" title="Clickjacking">Clickjacking</a></li>
<li><a href="Man-in-the-browser" title="Man-in-the-browser">Man-in-the-browser</a></li>
<li><a href="Man-in-the-middle_attack" title="Man-in-the-middle attack">Man-in-the-middle</a></li>
<li><a href="Rootkit" title="Rootkit">Rootkit</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horse</a></li>
<li><a href="Zombie_(computing)" title="Zombie (computing)">Zombie computer</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Malware for profit</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adware" title="Adware">Adware</a></li>
<li><a href="Botnet" title="Botnet">Botnet</a></li>
<li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="Fleeceware" title="Fleeceware">Fleeceware</a></li>
<li><a href="Form_grabbing" title="Form grabbing">Form grabbing</a></li>
<li><a href="Dialer#Fraudulent_dialer" title="Dialer">Fraudulent dialer</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke logging</a></li>
<li><a href="Internet_bot#Malicious_purposes" title="Internet bot">Malbot</a></li>
<li><a href="Privacy-invasive_software" class="mw-redirect" title="Privacy-invasive software">Privacy-invasive software</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Web_threat" title="Web threat">Web threats</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">By operating system</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li>Android malware</li>
<li>Classic Mac OS viruses</li>
<li>iOS malware</li>
<li><a href="Linux_malware" title="Linux malware">Linux malware</a></li>
<li>MacOS malware</li>
<li><a href="Macro_virus" title="Macro virus">Macro virus</a></li>
<li><a href="Mobile_malware" title="Mobile malware">Mobile malware</a></li>
<li><a href="Palm_OS_viruses" title="Palm OS viruses">Palm OS viruses</a></li>
<li><a href="HyperCard_viruses" class="mw-redirect" title="HyperCard viruses">HyperCard viruses</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Protection</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anti-keylogger" title="Anti-keylogger">Anti-keylogger</a></li>
<li><a href="Antivirus_software" title="Antivirus software">Antivirus software</a></li>
<li><a href="Browser_security" title="Browser security">Browser security</a></li>
<li><a href="Data_loss_prevention_software" title="Data loss prevention software">Data loss prevention software</a></li>
<li><a href="Defensive_computing" title="Defensive computing">Defensive computing</a></li>
<li><a href="Firewall_(computing)" title="Firewall (computing)">Firewall</a></li>
<li><a href="Internet_security" title="Internet security">Internet security</a></li>
<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a></li>
<li><a href="Mobile_security" title="Mobile security">Mobile security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Countermeasures</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Computer_and_network_surveillance" title="Computer and network surveillance">Computer and network surveillance</a></li>
<li><a href="Honeypot_(computing)" title="Honeypot (computing)">Honeypot</a></li>
<li><a href="Operation%3A_Bot_Roast" title="Operation: Bot Roast">Operation: Bot Roast</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox" aria-labelledby="Information_security92" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="3"><div id="Information_security92" style="font-size:114%;margin:0 4em"><a href="Information_security" title="Information security">Information security</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Threat_(computer)" class="mw-redirect" title="Threat (computer)">Threats</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adware" title="Adware">Adware</a></li>
<li><a href="Advanced_persistent_threat" title="Advanced persistent threat">Advanced persistent threat</a></li>
<li><a href="Arbitrary_code_execution" title="Arbitrary code execution">Arbitrary code execution</a></li>
<li><a href="Backdoor_(computing)" title="Backdoor (computing)">Backdoors</a></li>
<li>Bombs
<ul><li><a href="Fork_bomb" title="Fork bomb">Fork</a></li>
<li><a href="Logic_bomb" title="Logic bomb">Logic</a></li>
<li><a href="Time_bomb_(software)" title="Time bomb (software)">Time</a></li>
<li><a href="Zip_bomb" title="Zip bomb">Zip</a></li></ul></li>
<li><a href="Hardware_backdoor" title="Hardware backdoor">Hardware backdoors</a></li>
<li><a href="Code_injection" title="Code injection">Code injection</a></li>
<li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="Cross-site_scripting" title="Cross-site scripting">Cross-site scripting</a></li>
<li><a href="Cross-site_leaks" title="Cross-site leaks">Cross-site leaks</a></li>
<li><a href="DOM_clobbering" title="DOM clobbering">DOM clobbering</a></li>
<li><a href="History_sniffing" title="History sniffing">History sniffing</a></li>
<li><a href="Cryptojacking" title="Cryptojacking">Cryptojacking</a></li>
<li><a href="Botnet" title="Botnet">Botnets</a></li>
<li><a href="Data_breach" title="Data breach">Data breach</a></li>
<li><a href="Drive-by_download" title="Drive-by download">Drive-by download</a></li>
<li><a href="Browser_Helper_Object" title="Browser Helper Object">Browser Helper Objects</a></li>
<li><a href="Computer_virus" title="Computer virus">Viruses</a></li>
<li><a href="Data_scraping" title="Data scraping">Data scraping</a></li>
<li><a href="Denial-of-service_attack" title="Denial-of-service attack">Denial-of-service attack</a></li>
<li><a href="Eavesdropping" title="Eavesdropping">Eavesdropping</a></li>
<li><a href="Email_fraud" title="Email fraud">Email fraud</a></li>
<li><a href="Email_spoofing" title="Email spoofing">Email spoofing</a></li>
<li><a href="Exploit_(computer_security)" title="Exploit (computer security)">Exploits</a></li>
<li><a href="Dialer#Fraudulent_dialer" title="Dialer">Fraudulent dialers</a></li>
<li><a href="Hacktivism" title="Hacktivism">Hacktivism</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li>
<li><a href="Insecure_direct_object_reference" title="Insecure direct object reference">Insecure direct object reference</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke loggers</a></li>
<li><a href="Malware" title="Malware">Malware</a></li>
<li><a href="Payload_(computing)" title="Payload (computing)">Payload</a></li>
<li><a href="Phishing" title="Phishing">Phishing</a>
<ul><li><a href="Voice_phishing" title="Voice phishing">Voice</a></li></ul></li>
<li><a href="Polymorphic_engine" title="Polymorphic engine">Polymorphic engine</a></li>
<li><a href="Privilege_escalation" title="Privilege escalation">Privilege escalation</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Rootkit" title="Rootkit">Rootkits</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Shellcode" title="Shellcode">Shellcode</a></li>
<li><a href="Spamming" title="Spamming">Spamming</a></li>
<li><a href="Social_engineering_(security)" title="Social engineering (security)">Social engineering</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Software_bug" title="Software bug">Software bugs</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horses</a></li>
<li><a href="Hardware_Trojan" title="Hardware Trojan">Hardware Trojans</a></li>
<li><a href="Remote_access_trojan" class="mw-redirect" title="Remote access trojan">Remote access trojans</a></li>
<li><a href="Vulnerability_(computer_security)" title="Vulnerability (computer security)">Vulnerability</a></li>
<li><a href="Web_shell" title="Web shell">Web shells</a></li>
<li><a href="Wiper_(malware)" title="Wiper (malware)">Wiper</a></li>
<li><a href="Computer_worm" title="Computer worm">Worms</a></li>
<li><a href="SQL_injection" title="SQL injection">SQL injection</a></li>
<li><a href="Zombie_(computing)" title="Zombie (computing)">Zombie</a></li></ul>
</div></td><td class="noviewer navbox-image" rowspan="3" style="width:1px;padding:0 0 0 2px"><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Defenses</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Application_security" title="Application security">Application security</a>
<ul><li><a href="Secure_coding" title="Secure coding">Secure coding</a></li>
<li>Secure by default</li>
<li><a href="Secure_by_design" title="Secure by design">Secure by design</a>
<ul><li><a href="Misuse_case" title="Misuse case">Misuse case</a></li></ul></li></ul></li>
<li><a href="Computer_access_control" title="Computer access control">Computer access control</a>
<ul><li><a href="Authentication" title="Authentication">Authentication</a>
<ul><li><a href="Multi-factor_authentication" title="Multi-factor authentication">Multi-factor authentication</a></li></ul></li>
<li><a href="Authorization" title="Authorization">Authorization</a></li></ul></li>
<li><a href="Computer_security_software" title="Computer security software">Computer security software</a>
<ul><li><a href="Antivirus_software" title="Antivirus software">Antivirus software</a></li>
<li><a href="Security-focused_operating_system" title="Security-focused operating system">Security-focused operating system</a></li></ul></li>
<li><a href="Data-centric_security" title="Data-centric security">Data-centric security</a></li>
<li><a href="Obfuscation_(software)" title="Obfuscation (software)">Software obfuscation</a></li>
<li><a href="Data_masking" title="Data masking">Data masking</a></li>
<li><a href="Encryption" title="Encryption">Encryption</a></li>
<li><a href="Firewall_(computing)" title="Firewall (computing)">Firewall</a></li>
<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a>
<ul><li><a href="Host-based_intrusion_detection_system" title="Host-based intrusion detection system">Host-based intrusion detection system</a> (HIDS)</li>
<li><a href="Anomaly_detection" title="Anomaly detection">Anomaly detection</a></li></ul></li>
<li><a href="Information_security_management" title="Information security management">Information security management</a>
<ul><li><a href="Information_risk_management" class="mw-redirect" title="Information risk management">Information risk management</a></li>
<li><a href="Security_information_and_event_management" title="Security information and event management">Security information and event management</a> (SIEM)</li></ul></li>
<li><a href="Runtime_application_self-protection" title="Runtime application self-protection">Runtime application self-protection</a></li>
<li><a href="Site_isolation" title="Site isolation">Site isolation</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Related<br>security<br>topics</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Computer_security" title="Computer security">Computer security</a></li>
<li><a href="Automotive_security" title="Automotive security">Automotive security</a></li>
<li><a href="Cybercrime" title="Cybercrime">Cybercrime</a>
<ul><li><a href="Cybersex_trafficking" title="Cybersex trafficking">Cybersex trafficking</a></li>
<li><a href="Computer_fraud" title="Computer fraud">Computer fraud</a></li></ul></li>
<li><a href="Cybergeddon" title="Cybergeddon">Cybergeddon</a></li>
<li><a href="Cyberterrorism" title="Cyberterrorism">Cyberterrorism</a></li>
<li><a href="Cyberwarfare" title="Cyberwarfare">Cyberwarfare</a></li>
<li><a href="Electronic_warfare" title="Electronic warfare">Electronic warfare</a></li>
<li><a href="Information_warfare" title="Information warfare">Information warfare</a></li>
<li><a href="Internet_security" title="Internet security">Internet security</a></li>
<li><a href="Mobile_security" title="Mobile security">Mobile security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li>
<li><a href="Copy_protection" title="Copy protection">Copy protection</a></li>
<li><a href="Digital_rights_management" title="Digital rights management">Digital rights management</a></li></ul>
</div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-09" href="https://en.wikipedia.org/wiki/?title=Rogue_security_software&oldid=1299630023">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>