Download.com Malware Distribution and the CNET TechTracker Controversy
For years, Download.com served as a primary hub for users seeking software. However, the platform became the center of a significant cybersecurity controversy when it transitioned from a simple directory to a distributor using its own installation software. This shift introduced risks that blurred the line between legitimate software and malicious code.
The Rise of CNET TechTracker
In August 2011, Download.com launched CNET TechTracker, an installation manager designed to deliver software titles from its extensive catalog. While presented as a convenience, this installer began bundling trojans and bloatware—unnecessary software often installed without the user's explicit consent—such as various toolbars.
CNET acknowledged these concerns in its download FAQ, stating that a small number of security publishers had flagged the installer as adware or a potentially unwanted application (PUA), which refers to software that may be unwanted but not necessarily malicious.
[ไม่มีภาพประกอบ]Public Backlash and Security Warnings
The controversy intensified in December 2011 when Gordon Lyon, writing under the pseudonym Fyodor, published a critique of the installation manager and its bundled software. His findings gained significant traction across social networks and media outlets. The core issue was the deception created by mixing original author software with CNET's own bundled content, leading to accusations of copyright and trademark violations.
By 2014, the risks became more severe. The Register and US-CERT warned that the platform was distributing foistware—software that tricks users into installing unwanted programs. They cautioned that this could allow an attacker to download and execute arbitrary code on a user's system.
Industry Research and Findings
In 2015, research conducted by Emsisoft suggested that while many free download portals bundled their offerings with potentially unwanted software, Download.com was the worst offender among them.
Technical Analysis of Malware Packaging
A 2015 study by How-To Geek provided empirical evidence of malware within Download.com installers. By testing the top 10 most popular apps in a virtual machine, researchers found that every single one contained crapware or malware. For instance, the KMPlayer installer bundled a rogue antivirus called 'Pro PC Cleaner' and attempted to execute WajamPage.exe. Some downloads, such as YTD, were blocked entirely by Avast antivirus software.
Beyond simple adware, How-To Geek discovered that Download.com was installing fake SSL certificates (Secure Sockets Layer certificates used to encrypt internet connections). This practice is similar to the Lenovo Superfish incident and is highly dangerous because it can compromise SSL encryption, enabling man-in-the-middle attacks, where an attacker intercepts communication between two parties.
[ไม่มีภาพประกอบ]Key Facts
- CNET TechTracker: An installation manager introduced in 2011 that bundled software with trojans and bloatware.
- Security Risks: US-CERT warned in 2014 that the platform's foistware could allow the execution of arbitrary code.
- Malware Evidence: A 2015 How-To Geek study found malware in all of the top 10 downloaded apps.
- Encryption Breach: The platform installed fake SSL certificates, exposing users to man-in-the-middle attacks.
- Resolution: By July 2016, the installer program was discontinued and adware/malware was no longer included.
| Year | Issue/Event | Impact/Finding |
|---|---|---|
| 2011 | Launch of TechTracker | Bundled trojans, toolbars, and bloatware. |
| 2014 | US-CERT Warning | Risk of arbitrary code execution via foistware. |
| 2015 | How-To Geek Study | Malware in top 10 apps; fake SSL certificates installed. |
| 2016 | Program Discontinuation | Installer removed; adware/malware distribution ceased. |
Frequently Asked Questions
What was CNET TechTracker?
CNET TechTracker was an installation manager introduced by Download.com in August 2011 to deliver software from its catalog, but it became notorious for bundling unwanted software and trojans.
What is foistware?
Foistware is a type of software distribution where unwanted programs are "foisted" or tricked onto a user's computer, often bundled with a legitimate application the user intended to download.
Why were the fake SSL certificates dangerous?
Fake SSL certificates compromise the encryption that secures web traffic, which can allow attackers to perform man-in-the-middle attacks to steal sensitive data.
Which specific malware was found in the 2015 study?
The How-To Geek study identified 'Pro PC Cleaner' (a rogue antivirus) and WajamPage.exe as examples of software bundled within the KMPlayer installer.
Does Download.com still use the TechTracker installer?
No. According to findings in July 2016, the installer program was discontinued and the platform stopped including adware and malware in its downloads.