Phishers Use Fake Google Toolbar As Bait

MOUNTAIN VIEW, Calif. – Security experts have issued a warning that a new phishing scam involving a fake Google toolbar is the latest lure being used to steal personal information from web users.

Phishing is where emails, instant messages or websites pretend to be legitimate companies for the purpose of stealing personal information, financial account numbers and passwords.

The scam spreads itself via IM and Internet Relay Chat and downloads a fake Google toolbar and adware on users’ machines, which re-direct to a page collecting credit card information.

According to security firm FaceTime, the scam borrows the exploits of an application commonly referred to as "CoolWebSearch" and uses two URLs via IM that lead users to a web page that begins the toolbar install and calls a Windows Help File. Once this happens, the fake Google toolbar appears and the anti-spyware program known as "World Antispy" launches. At this point, users may also experience a pop-up window that asks for personal information.

So far, Yahoo Messenger is the only IM service being used in this attack.

"Our research finds that this phishing scam is financially motivated by a third party using incredibly elaborate bundles that deliver a rogue Google toolbar with many of the same elements as the real Google toolbar,” Chris Boyd, senior researcher at FaceTime, said. "Hackers are clearly using new tricks such as IM to take advantage of reputable, trusted brands such as Google.”

FaceTime is reporting that there are three distinct versions of this attack, each one exploiting different security vulnerabilities and installing a different payload using different vectors, including IM and IRC.

The new scam marks an increasing trend in using IM as a phishing tool, Boyd said.

According to security firm IMlogic, phishing attacks that use IM as their vehicle have jumped by 14 times since the first of the year, and by the third quarter, IMlogic tracked 10 times the number of IM threats than in all of 2004.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

CamSoda Launches 'Trick or Tease' AI Companions

CamSoda has launched its Halloween-themed Trick or Tease AI companions.

Russian Lawmakers Call for Age Verification

Two Russian lawmakers have called on the country’s government to implement age verification for adult content.

British Documentary Spotlights XBIZ Amsterdam With Candid Conversations

British creator and host Josh Pieters traveled to XBIZ Amsterdam to film a documentary about the annual European adult industry conference.

XBIZ 2026 to Debut 'New Talent Go-See' Special Event

XBIZ 2026, North America’s premier adult industry conference, will debut a special event designed to help new talent jump-start their careers: the New Talent Go-See.

Penthouse Announces Digital Archive Launch

Penthouse Magazine has announced that it will launch a comprehensive digital archive in 2026.

Dreamcam Joins Pineapple Support as Supporter-Level Sponsor

Dreamcam has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

AEBN Publishes Popular Searches by Country for August, September

AEBN has released the list of popular searches from its straight and gay theaters by country in August and September.

AV in Focus: A Guide to Unlocking Compliance With Clarity

The age verification era isn’t coming — it’s here. Laws are already on the books in numerous U.S. states, as well as in the U.K., France and beyond.

Canadian Privacy Commissioner Endorses National AV Bill

Philippe Dufresne, privacy commissioner of Canada, has voiced support for a bill that would impose fines of up to $500,000 on adult sites that do not implement age verification for Canadian viewers.

Ricky Johnson Launches 'Ricky's Resort' Through YourPaysitePartner

Ricky's Room studio honcho Ricky Johnson has launched his latest site, RickysResort.com, through YourPaysitePartner (YPP).

Show More