Update: Subverted search sites lead to massive malware attack in progress
Trojans, rootkits, password stealers hit users who click on a bad link after a search — A large-scale, coordinated campaign to steer users toward malware- spewing Web sites from Google and other Internet search engines …
Context & Ripple Effects
This lands eight months after scammers hijacked Google's own blog software to run their redirects — evidence that through 2007, attackers have been working Google's ecosystem from both sides: compromising its properties directly and, as this campaign does, gaming its results from outside. What makes this round notable is scale and coordination: Computerworld describes a large-scale operation steering searches toward malware-spewing sites across Google and other engines, not a single compromised page.
The story traveled fast — eWEEK picked it up the same day ('Malware Poisoning Results for Innocent Searches'), and SunbeltBLOG followed with post-incident cleanup notes, which suggests security vendors were already fielding infected machines rather than merely observing the campaign.
First-order effects
- Users who click a poisoned result are being hit immediately with trojans, rootkits, and password stealers — the payload installs on click, making ordinary search behavior the attack vector.
- Google and the other named engines face live, coordinated manipulation of their rankings and must identify and delist the malicious domains while the campaign keeps adapting.
Second-order effects
- Security vendors move from detection to remediation mode — Sunbelt's 'aftermath' coverage indicates cleanup traffic is already arriving, pushing antivirus and antispyware sellers to prioritize search-borne threats over purely email-borne ones.
- Legitimate sites competing for popular queries now contend with malware pages occupying result slots, degrading trust in organic and advertised placements and giving engines a quality-control problem they cannot outsource.
Third-order effects
- If poisoning at this scale proves repeatable, search-result integrity becomes a standing security surface — engines will need to treat ranking abuse as a threat-model item alongside spam, and malware distribution shifts decisively from inbox to search page.
- The economics favor attackers: hijacking trust in a trusted intermediary scales better than compromising destinations one by one, pointing toward an arms race between automated link vetting and automated poisoning that defines web security going forward.
The trend: Malware distribution is industrializing around search-result poisoning, forcing engines to absorb a security function their ranking systems were never designed for.