Technology by Design

Technology news, reviews, and how to keep your technology running fast and smooth!

  • Home
  • About TbyD
    • Who is TbyD
    • Why Choose TbyD?
    • 16 Things
    • Your Computer Guy
  • Products and Services
    • Business Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
      • Performance Analysis
      • Optimization
      • Core Security Solution
      • Managed Backups
      • Computer and Network Systems
      • Computer Setup
      • Domain Names
      • Email Services
      • Extended Warranties
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
      • Websites
    • Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
        • Computer Setup
      • Core Security Solution
      • Managed Backups
      • Extended Warranties
      • Performance Analysis
      • Optimization
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
    • Products
      • Computers
      • Servers
  • Testimonials
    • What Our Clients Say About Us
  • Blogs
    • ALERTS
    • FAQ
    • How To Videos
  • Newsletters
    • TechTips Newsletters
  • Reviews
  • Media
    • Email Red Flags
    • E-Books
    • Disaster Prevention Planning Kit
    • Free Reports
  • Contact Us
    • Contact Us
    • Quick Support

ALERT: Search Toolbar is a Malware Conduit

August 7, 2015 by The T By D Team Leave a Comment

Baidu ToolbarALERT:  Security Firm Warns Search Toolbar is Malware Conduit

The toolbar distributed by Chinese-language search engine Baidu, is being targeted by opportunistic attackers and use to exfiltrate corporate secrets, says Rob Eggebrecht, president and CEO of security firm InteliSecure.

Baidu, like all major search engines, including Bing, Google, and Yahoo, distributes a toolbar that can be used to speed up search engines.  But Eggebrecht says that multiple organizations have traced data breaches to an intrusion that began when outsiders used the Baidu toolbar to sneak data-stealing malware into their company.  Refusing to specify, he says that one recent victim was a U.S. pharmaceutical firm, from which attackers compromised research and development work worth millions of dollars.Baidu

Eggebrecht’s firm believes that the attacks can be traced back to individuals associated with the Chinese government.  

“Our take on it, not trying to directly pick on the Chinese, is that…when users hit certain links, attackers drop down…malware, or phone-home technology, that starts capturing information.”

Eggebrecht states the toolbar-enabled data exfiltration comes at a time when his firm has witnessed a spike in attacks against corporate networks – and not just those targeting toolbars – by what appear to be attackers with ties to China.  To date, hacking U.S. and Canadian organizations seems to trigger few, if any, penalties against either Chinese individuals or the government itself.

APT-style attacks – often beginning with a phishing email, and relying on targets to execute attachments and thus infect their systems with malware – are seen as the hallmark of corporate espionage.  But attackers have never been adverse to employing simpler options when available.  Eggebrecht states:

Targeting the toolbar “was an opportunistic way for the Chinese government to capture information in a very nonchalant manner, because…they know they have a good expat user base in the research community” that is going to rely on a Chinese-language search engine.  

All browser toolbars should be blocked by default, states Alan Woodward, a computer science visiting professor at the University of Surrey, and a cybersecurity adviser to Europol, the association of European police agencies.  

“These so-called ‘helper’ add-ins, I mean, god knows what they’re doing.  It’s a well-known attack vector.”

Ask your I.T department if toolbars are blocked through your security settings.

Ask us about our Core Security Solution Package!

 

You can’t stop CyberCriminals from targeting your company or employees.
But you can be prepared for their arrival, and have full shield up.

Got CyberBugs?

Call 1-204-800-3166

For Cyber-Extermination!

#itthatworks

Filed Under: ALERTS, Featured

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Sign Up For The Monthly TechTips Newsletter!

* = required field
unsubscribe from list

powered by MailChimp!

Recent Posts

  • ALERT: Celebrity Death Scams
  • ALERT: Uber Hacked
  • ALERT: Netflix Email Scam
  • ALERT: Bad Rabbit
  • Scam – Reset Password Alert

Recent Comments

  • ALERT: New Ransomware Targets MS Office 365 Users - Technology by Design on Managed Backups
  • ALERT: FBI Warns Email Extortion Heating Up for Summer! - Technology by Design on ALERT: AshleyMadison Hack Blows Up
  • ALERT: Evil Android Trojan Empties Your Bank Account - Technology by Design on Definition: Phishing
  • ALERT: HTML Attachments - Technology by Design on Definition: Phishing
  • ALERT: New Ransomware Also Steals Your Bitcoins - Technology by Design on Managed Backups

Copyright © 2025 · Dynamik Website Builder on Genesis Framework · WordPress · Log in