Fake Angry Birds follow-up – Bad Piggies game: 80,000 Chrome users victims of ad injection

Barracuda Labs’ new research reveals how complacency to data permissions could allow cybercriminals access and misuse user email addresses and online credit card information
October 11, 2012 8:37 by Barracuda Networks
October 10, 2012 – Research from Barracuda Networks Inc., a leading provider of security, networking and data protection solutions, has revealed that more than 80,000 users of the Google Chrome browser have fallen victim of counterfeit Bad Piggies game. The study from Barracuda Labs found that as a fake version of the game is installed, so too is a plug-in that displays additional advertisements on popular websites such as Yahoo and MSN.
Last month, Rovio, the company behind hit game, Angry Birds, released a new puzzle video game called Bad Piggies. The game was easy to download for Apple and Android users, Android (free) iOS (£0.69), and Mac (£2.99) and hit the top spot in the App Store after only 3 hours. A free fake version of the game for users without an Apple or Android device quickly followed. Excited users who thought they had found a free version of the game became exposed to a flurry of irritating ads and unknowingly could have allowed cyber criminals access to their credit card details.
To install one of the counterfeit games, users are requested permission to ‘access your data on all websites’ in order to play a game. Users who clicked ‘agree’ run the risk of getting their browsers hijacked. The plug-in authors can acquire all the web data when users browse the Internet with Google Chrome. They are then able to misuse users’ information, such as stealing user email addresses and online credit card information.
Highlighted findings from the Barracuda Labs study include:
- Searching for “Bad Piggies” in the Chrome Web Store turns up at least eight ‘free’ matches
- All of the matches have “Bad Piggies” in their game descriptions, so that they show up when you search for the game
- Seven of the eight fake versions of the game found come from the same source (playook.info), a maker of “free” flash games
- When installing any of the fake versions, a request to “access your data on all websites” flashes up before the user is able to play a game
- None of the counterfeit versions of the game are authentic: they are not Bad Piggies, but are just pigs-shoot-birds games
- Once installed, so too are additional ads, which pop up on popular websites such as Angry Birds’ Chrome site, Disney, eBay, IMDB, Kickass Torrents, MSN, MySpace, The Pirate Bay, Yahoo, V9 and 9Gag
Barracuda advises: “When installing a plug-in inside the Chrome web store, consider the requested permissions with a critical eye toward the intent of the plug-in. If the plug-in requests any permission that does not seem reasonable, do not install it. If you have already installed, uninstall it immediately and change your passwords on other websites if possible.
As Chrome gains more browser market-share, Google should provide better secures solutions on Chrome web store to protect its users. Until then, it’s especially important the Chrome users know how to protect themselves.”
About Barracuda Labs
Barracuda Labs is a global multi-disciplinary research and threat analysis team that fulfills a critical role in developing innovative technologies across Barracuda Networks’ business areas. The team evaluates the threat ecosystem and creates security intelligence to defend Barracuda Networks customers. Barracuda Labs’ threat research areas, which include email, Web, network and cloud security and technology, are designed to improve the world’s security posture by promoting security awareness and education, developing and innovating new defense technologies, and working with government and law enforcement agencies to reduce cybersecurity crime. For more information, please visit www.barracudalabs.com.
About Barracuda Networks Inc.
Barracuda Networks combines premises-based gateways and software, virtual appliances, cloud services, and sophisticated remote support to deliver comprehensive content and network security, data protection and application delivery solutions. The company’s expansive product portfolio includes offerings for protection against email and Web threats as well as products that improve application delivery and network access, message archiving, backup and data protection. Coca-Cola, FedEx, Harvard University, IBM, L’Oreal, and Europcar are among the more than 150,000 organizations protecting their IT infrastructures with Barracuda Networks’ range of affordable, easy-to-deploy and manage solutions. Barracuda Networks is privately held with its International Headquarters in Campbell, Calif. For more information, please visit www.barracudanetworks.com.
More on Press Release
-
NEC Display Solutions launches Full HD 3D ready compact meeting room projector
-
When Marketing Academia Met (& Meant) Business
-
Sourcefire Delivers Unprecedented Visibility And Tracking Of Malware
-
Starcom MediaVest Group wins Yas Marina Circuit account
-
Taste Of Lebanon
-
Starcom MediaVest Group Elevates Rayan Karaky to Chief Digital Officer, MENA and Emerging Markets
-
CANALI’S EXCLUSIVE “SU MISURA” EVENT FOR PERSONALIZED MENSWEAR IN THE UAE
-
Plextor launches new SSD with Stunning True Speed Performance
-
Dubai Duty Free wins DFNI Asia/Pacific Award for “Middle East Travel Retailer of the Year”
-
Sovereign art gallery opens at Jumeirah Lakes Towers
-
ManageEngine Expands NoSQL Support with Redis Monitoring
-
RGH ENTERTAINMENT PRODUCES NEW ANIMATED FEATURE FILM, LIFE AND ADVENTURES OF SANTA CLAUS
-
Dubai Duty Free Honoured at the 4th Sheikh Mohammed bin Rashid Al Maktoum Patrons of the Arts Awards 2013
-
Axtrom To Showcase Its Axpad Range At DISTREE
-
Kindi enters into strategic partnership with MadVillage
-
First UTM solution to deliver combined gateway, endpoint and cloud web protection
-
Red Hat Expands Technical Account Management Services to Offer SAP® Solution-centric Support
-
R&M’s New CSR Report Highlights Company’s Achievements in Advancing Ecological Efficiency and Social Accountability
-
ManageEngine Adds Auditing Capabilities to Exchange Reporter Plus
-
Pro Art Gallery to Host ‘‘Contemporary Turkish Art Exhibition’’
Lately on Kipp
-
Dubai ruler makes horse doping illegal
-
CEO-elect of UAE’s fraud-hit RAKBANK has quit
-
Over 90% of passwords vulnerable to hacking
-
‘Renewable energy absolutely necessary’ – Saudi
-
NEC Display Solutions launches Full HD 3D ready compact meeting room projector
-
Saudi Arabia confirms another death from SARS-like virus
Gold iPad at Burj Al Arab
Minimum wage ‘unfair’ for employers?
Taking on Abercrombie & Fitch
Fake pilot ‘on the run’
“Your customers aren’t fools”
Behind the curtain of Simone Heng
Chatting with the man behind Dubai City Pass
A business discussion with the author of ‘Connect The Dots’
































