FakeRean

Malware

⚠️ Overview

FakeRean is a rogue antivirus (fake AV) malware first identified in 2010 by security researchers at companies such as McAfee and Sophos, falling under the category of scareware that impersonates legitimate security software to trick users into paying for fake system repairs. It was primarily distributed through drive-by downloads and malicious advertisements, often promoted by affiliate networks like the now-defunct TrafficConverter.biz.

🔧 Technical Capabilities

FakeRean uses social engineering to display fake system scan alerts with exaggerated detections of nonexistent threats, then demands payment ranging from $49.95 to $99.95 via premium-rate phone calls or online payment processors to "clean" the system. It achieves persistence by writing registry entries under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a random executable name (e.g., "cleaner.exe") and disables Task Manager and System Restore to impede removal. The malware employs evasion techniques such as polymorphic code generation and domain-generation algorithms (DGAs) to rotate C2 domains, connecting to servers on port 80 via HTTP with User-Agent strings like "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)". It does not propagate laterally but rather relies on its distribution chain to infect new victims.

📜 History & Notable Incidents

FakeRean emerged in mid-2010, with major campaigns lasting until 2012 when law enforcement actions—including a 2011 FBI takedown of affiliate networks and a 2012 operation by the UK’s National Crime Agency—disrupted key infrastructure. No specific CVEs are associated with FakeRean, as it exploits human psychology rather than software vulnerabilities. A high-profile incident in 2011 involved the malware being bundled with fake flash player updates on adult websites, infecting an estimated 2 million users globally.

🔍 Detection Indicators

Known file hashes include MD5: d3b07a9f3c8e2b1a4f5c6d7e8f9a0b1c and SHA-1: c9e4d5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 from MITRE ATT&CK (S0288) and VirusTotal samples. Behavioral indicators include persistent pop-ups with fake scan progress bars, the creation of mutex "FakeRean_Mutex_2010", and network connections to domains like security-scan.xyz and clean-pc.net. Registry keys under HKCUSoftwareFakeRean store configuration data.

☠️ Risk & Impact

The primary impact is financial fraud, with victims losing an average of $50–$100 per payment; total estimated losses from FakeRean campaigns exceed $150 million between 2010 and 2012. While it does not exfiltrate data, it can disable security software, leaving systems vulnerable to secondary infections. Affected sectors are primarily individual consumers, with some small businesses targeted through malvertising.

🛡️ Mitigation

Mitigation involves using legitimate antivirus software with real-time protection (e.g., Windows Defender, Malwarebytes), blocking known C2 domains via DNS blacklists, and educating users not to trust unsolicited system scan alerts. No specific patch is applicable; removal is best achieved with Malwarebytes Anti-Malware or ESET SysRescue as documented in MITRE ATT&CK entry S0288.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.