Skip to main content
  1. Home
  2. Computing
  3. Web
  4. Legacy Archives

Google: IP spoofing on the rise

Add as a preferred source on Google
Google Safe Browsing/IP Spoofing
Image used with permission by copyright holder

Google has been running its Safe Browsing service for about four years, with a goal towards providing an open service that Web browsing applications can check against to see if a particular site is suspected of hosting malware or phishing scams. Now, Google has published an analysis (PDF) of more than 160 million Web pages on more than 8 million sites to look for trends in how malware is distributed—and finds that while social engineering tricks play a small role and plug-in and browser exploits are still common, malware distributors are increasingly turning to IP spoofing in hopes of avoiding detection.

Overall, Google finds that malware distributors rely on exploiting a vulnerability in a browser or a plug-in to install malware on users’ systems in what are known as drive-by attacks: typically, all users need to do is load a Web with the malicious code, and their systems are compromised. Google’s Safe Browsing initiative has automated tools that scan sites looking for these attempted exploits, and adds them to its database of questionable and dangerous sites if they’re found.

Recommended Videos

However, malware authors are increasingly turning to IP spoofing to avoid detection. In this case, the technique doesn’t involve using router trickery in order to make traffic from one source look like it comes from another; instead, the malware distributors try to detect connections from Google’s Safe Browsing survey (and services like it) and serve perfectly safe, innocuous Web pages to those services…saving its nasty payload for visitors they believe to be real users.

“The concept behind cloaking is simple: serve benign content to detection systems, but serve malicious content to normal Web page visitors,” wrote Lucas Ballard and Niels Provos in the Google Online Security blog. “Over the years, we have seen more malicious sites engaging in IP cloaking.”

Google emphasizes it is constantly adjusting its scanners with “state-of-the-art malware detection” to compensate for IP cloaking techniques, but notes malware distributors and security services will always be in an arms race…with security folks most often trying to play catch-up.

Google also notes that, with only a couple exceptions, browser and plug-in vulnerabilities used by malware distributors are only used for a comparatively short period of time: as soon as a new vulnerability is discovered—or an old one is patched—malware authors quickly move on to another exploit.

Google also notes that while getting people to install malware using social engineering—tricking people into downloading dangerous software, usually by promising a plug-in or antivirus package—is still common and on the rise, it’s employed by only about two percent of sites that distribute malware.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Google Earth’s AI misadventure lasted only a day. It was a tale of dangerous ignorance.
Nuclear reactors, tanks, and historical destruction on a life-like satellite map? Yeah, that's bad.
Nano Banana AI image generator representation.

Technology behemoths are clearly not reading the room, or they are just moving faster than they should when it comes to AI deployment. Google has already stuffed its Gemini AI in every corner of its software stack, from Android to daily productivity tools like Gmail that are used by hundreds of millions of users every day. AI is everywhere. Not all of it is bad, mind you. But in a few places, it just feels forced.

In its latest AI-fication experiment, the company targeted Google Earth. The idea was to let the audience use its Nano Banana 2 AI image generator and make images that can be placed on the map view. On paper, it's a cool idea. What would the Colosseum of Rome look like in your urban neighborhood? Yeah, fun stuff like that.

Read more
AMD is apparently gearing up to raise GPU prices right after Nvidia’s steep hike
AMD has reportedly told AIB partners about a price hike that goes into effect in. August.
AMD RX 7800

AMD is next in line to raise the asking price of its Radeon GPUs, merely days after the news of a similar hike coming for Nvidia graphics cards started making waves. As per ChannelGate on Weibo (h/t VideoCardz), AMD has informed its board partners that the price of GPU and memory bundles will go up by at least 10% in August.

Is a similar price hike coming for standalone graphics cards? I won't be surprised if that happens. The situation is so bad that AMD is planning to bring back graphics cards with 4GB of onboard memory. AMD just introduced the RX 9050 GPU, which costs $279. Notably, it's just $20 less than the RX 9060 XT that offers double the graphics memory.

Read more
Microsoft will make Windows work well with just 8GB RAM. We desperately need it
The dream of a reliable and affordable Windows laptop hinges on the next milestone at Microsoft.
Surface laptop on wooden table

The year 2026 has marked a huge course correction for Microsoft after years of frustrating users with plenty of confusing processes, unoptimized UI elements, and just the generous bloatware that can bring any Windows system to a crawl. Microsoft has finally shifted into a new phase. From fixing the right-click behavior to speeding up the Search system, the company has fixed plenty of papercuts.

The next major milestone is making Windows 11 run smoothly on Windows PCs with just 8GB of RAM. That directly means entry-level and budget laptops will at least get the basics right, even if that means sacrificing the on-device AI bells and whistles. Let's face it. The increasingly AI-first approach to computing on a Windows 11 machine is a little too taxing on the hardware at hand.

Read more