Malicious Proxy Redirects SSL Google Traffic for 1 Million IPs

Bitdefender has analysed a click fraud bot that currently operates on nearly one million computers worldwide. The bot, named Redirector.Paco tampers with the internet configuration settings in order to forward searches on popular search engines such as Google and Yahoo to a third party, malicious server, controlled by cyber-criminals.

This particular campaign is mostly detrimental for private companies that pay for ad impression and clicks. While the infected user will not directly lose money, their search results may be poisoned as per the proxy servers instructions. Basically, the cyber-criminals own the search results for the victim’s computer.

