IDEAS home Printed from
   My bibliography  Save this paper

The Underground Economy of Fake Antivirus Software


  • Steigerwald, Douglas
  • Vigna, Giovanni
  • Kruegel, Christopher
  • Kemmerer, Richard
  • Abman, Ryan
  • Stone-Gross, Brett


Fake antivirus (AV) programs have been utilized to defraud millions ofcomputer users into paying as much as one hundred dollars for a phony softwarelicense. As a result, fake AV software has evolved into one of the most lucrativecriminal operations on the Internet. In this paper, we examine the operations of threelarge-scale fake AV businesses, lasting from three months to more than two years.More precisely, we present the results of our analysis on a trove of data obtainedfrom several backend servers that the cybercriminals used to drive their scam operations.Our investigations reveal that these three fake AV businesses had earned acombined revenue of more than $130 million dollars. A particular focus of our analysisis on the financial and economic aspects of the scam, which involves legitimatecredit card networks as well as more dubious payment processors. In particular, wepresent an economic model that demonstrates that fake AV companies are activelymonitoring the refunds (chargebacks) that customers demand from their credit cardproviders. When the number of chargebacks increases in a short interval, the fakeAV companies react to customer complaints by granting more refunds. This lowersthe rate of chargebacks and ensures that a fake AV company can stay in businessfor a longer period of time. However, this behavior also leads to unusual patternsin chargebacks, which can potentially be leveraged by vigilant payment processorsand credit card companies to identify and ban fraudulent firms.

Suggested Citation

  • Steigerwald, Douglas & Vigna, Giovanni & Kruegel, Christopher & Kemmerer, Richard & Abman, Ryan & Stone-Gross, Brett, 2011. "The Underground Economy of Fake Antivirus Software," University of California at Santa Barbara, Economics Working Paper Series qt7p07k0zr, Department of Economics, UC Santa Barbara.
  • Handle: RePEc:cdl:ucsbec:qt7p07k0zr

    Download full text from publisher

    File URL:;origin=repeccitec
    Download Restriction: no

    References listed on IDEAS

    1. Andrew V. Carter & Douglas G. Steigerwald, 2012. "Testing for Regime Switching: A Comment," Econometrica, Econometric Society, vol. 80(4), pages 1809-1812, July.
    2. Carter Andrew V. & Steigerwald Douglas G., 2013. "Markov Regime-Switching Tests: Asymptotic Critical Values," Journal of Econometric Methods, De Gruyter, vol. 2(1), pages 25-34, July.
    3. Jin Seo Cho & Halbert White, 2007. "Testing for Regime Switching," Econometrica, Econometric Society, vol. 75(6), pages 1671-1720, November.
    4. Cecchetti, Stephen G & Lam, Pok-sang & Mark, Nelson C, 1990. "Mean Reversion in Equilibrium Asset Prices," American Economic Review, American Economic Association, vol. 80(3), pages 398-418, June.
    5. Garcia, Rene, 1998. "Asymptotic Null Distribution of the Likelihood Ratio Test in Markov Switching Models," International Economic Review, Department of Economics, University of Pennsylvania and Osaka University Institute of Social and Economic Research Association, vol. 39(3), pages 763-788, August.
    Full references (including those not matched with items on IDEAS)

    More about this item


    Social and Behavioral Sciences; cheating; computer security; fraud detection;

    NEP fields

    This paper has been announced in the following NEP Reports:


    Access and download statistics


    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:cdl:ucsbec:qt7p07k0zr. See general information about how to correct material in RePEc.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: (Lisa Schiff). General contact details of provider: .

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service hosted by the Research Division of the Federal Reserve Bank of St. Louis . RePEc uses bibliographic data supplied by the respective publishers.