July 9, 2015 By Shane Schick 2 min read

Normally, we expect malware to disable older versions of key applications in order to steal information or take over a victim’s computer, but the latest in a string of problems involving Adobe Flash Player has cybercriminals offering a free update to the browser plugin instead.

As first revealed in a blog post by an independent security researcher known only as Kafeine on Malware don’t need Coffee, the latest version of the Kovter malware has been updating Flash as a sort of competitive tactic against other cybercriminals. The Kovter Trojan typically works by taking over a victim’s machine and clicking on online ads to generate revenue through crooked pay-per-click (PPC) affiliate programs.

In some respects, the real victims here may be advertisers, who don’t realize they’re getting impressions obtained by hijacking computers. As Naked Security noted, click-fraud malware can’t really work if it can’t see online ads properly, which is probably one of the reasons this variant of Kovter proactively updates Flash on the user’s behalf.

On the other hand, ensuring that a machine is using the latest version of the browser plugin could also be a way of guaranteeing rival click-fraud malware authors have a tougher time targeting the same computer later. Komando suggested this isn’t entirely a new tactic; earlier viruses could clean up a machine with their own antivirus tools before stealing information or taking control.

Perhaps the best defense strategy is beating Kovter to the punch by updating Flash first. There are certainly enough reasons by now: Just last week, The Guardian reported that a flaw in the plugin was allowing attackers to embed malware in a video file to take over victims’ computers. Around the same time, cybercriminals were taking advantage of the same flaw in drive-by download attacks using the Magnitude exploit kit.

Computerworld suggested malicious actors are getting much faster at seizing such opportunities, so users need to patch as quickly as possible. And as this latest incident involving Kovter proves, cybercriminals are becoming as interested in one-upping each other as they are using malware to steal data or make money.

More from

Government cybersecurity in 2025: Former Principal Deputy National Cyber Director weighs in

4 min read - As 2024 comes to an end, it’s time to look ahead to the state of public cybersecurity in 2025.The good news is this: Cybersecurity will be an ongoing concern for the government regardless of the party in power, as many current cybersecurity initiatives are bipartisan. But what will government cybersecurity look like in 2025?Will the country be better off than they are today? What are the positive signs that could signal a good year for national cybersecurity? And what threats should…

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

2024 trends: Were they accurate?

4 min read - The new year always kicks off with a flood of prediction articles; then, 12 months later, our newsfeed is filled with wrap-up articles. But we are often left to wonder if experts got it right in January about how the year would unfold. As we close out 2024, let’s take a moment to go back and see if the crystal balls were working about how the year would play out in cybersecurity.Here are five trends that were often predicted for…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today