Microsoft throws cold water on claims Fireball virus infected 250 million PCs
Fuzzy math.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
Microsoft is firing back at security researchers who claim that a recently discovered virus has infected hundreds of millions of PCs. According to Microsoft, the virus exists, but the true tally of infected machines is closer to 5 million.
Check Point, the company behind the popular ZoneAlarm firewall and security products, recently released a report saying it discovered a "high volume Chinese threat operation" affecting more than 250 million computers around the world. Called Fireball, the malware takes over target browsers and turns them into zombies.
The culprit is a digital marketing agency (Rafotech) that is primarily using Fireball to redirect browser traffic to generate ad revenue, at least for now. However, once a system is infected with Fireball, the malware has the ability to download any files and/or additional dirty software
"Currently, Fireball installs plug-ins and additional configurations to boost its advertisements, but just as easily it can turn into a prominent distributor for any additional malware," Check Point warns.
Check Point called Fireball's spread to 250 million PCs and 20 percent of corporate networks around the world "alarming." These figures are based in part on Alexa's web traffic data, which shows that Rafotech's fake search engines have been gaining in popularity.
While Check Point only recently discovered Fireball, Microsoft says it has been tracking the virus since 2015 and that initially it came exclusively through software bundling. Pirated games and key generators were especially prone to bundling Fireball. Nevertheless, Microsoft says that the number of infected PCs is nowhere near what Check Point claims.
"In their report, Check Point estimated the size of the Fireball malware based on the number of visits to the search pages, and not through collection of endpoint device data. However, using this technique of site visits to estimate the volume of infected machines can be tricky," Microsoft stated in a blog post.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
One reason why looking at the number of visits to search pages can be tricky is because not every PC that visits those sites are necessarily infected with malware. Microsoft points out that search pages earn revenue regardless of how a user arrives at a particular page.
"Some may be loaded by users who are not infected during normal web browsing, for example, via advertisements or domain parking," Microsoft says.
Microsoft also called into question the estimates that were made from Alexa's ranking data, which are estimates of visitor numbers based on a small percentage of of Internet users.
"Alexa’s estimates are based on normal web browsing. They are not the kind of traffic produced by malware infections, like the Fireball threats, which only target Google Chrome and Mozilla Firefox. The Alexa traffic estimates for the Fireball domains, for example, differ from Alexa competitor SimilarWeb," Microsoft points out.
In contrast to Check Point's data collection, Microsoft said it combed through intelligence gathered from 300 million Windows Defender AV clients since 2015, plus monthly scans by the MSRT on over 500 million machines since October 2016. In doing so, Microsoft said it witnessed Fireball fizzling over time. It also used the opportunity to promote its Edge browser in Windows 10, which is immune to Fireball's browser hijacking techniques.
Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).


