• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Chinese ‘Fireball’ Malware Infects 250 Million Computers

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
June 3, 2017, 2:07 PM ET

The security firm Check Point says it has found a malware infection of staggering scope and destructive potential. Originating in China, the “Fireball” malware package is believed to have infected more than 250 million computers worldwide and is present on 20% of corporate networks, with major infection centers in India, Brazil, and Mexico.

Check Point calls it “possibly the largest infection operation in history.”

The malevolent software appears to be mainly intended to generate fake clicks and traffic for its creator, a Beijing advertising firm called Rafotech. When installed, the software redirects a user’s browser to websites that mimic the look of the Google or Yahoo search homepages. The fake pages surreptitiously gather private information on the user using so-called tracking pixels.

Get Data Sheet, Fortune’s technology newsletter.

But Fireball also has the ability to execute commands remotely—including downloading further malicious software. Fireball’s creators (or third-party hackers who find a way to take control) could theoretically transition from ad-scamming to selling harvested data, or even harness infected machines into a globe-spanning botnet of immense destructive power.

Many botnets much smaller than Fireball’s collection of 250 million compromised machines have been involved in major DDoS (for “distributed denial of service”), spam, or other campaigns. The Mirai botnet that knocked out Internet service for millions of people last December was estimated to have included as few as 120,000 devices—and those were mostly connected cameras and routers with far less power than the PCs targeted by Fireball.

According to Check Point, another scenario would simply see Rafotech mass-harvest data from infected machines and sell it—from credit card numbers to business plans and patents—to the highest bidder.

The San Carlos, Calif. security company describes Fireball as “a pesticide armed with a nuclear bomb.” Rafotech, Check Point warns, “holds the power to initiate a global catastrophe.” It adds: “The potential loss is indescribable.”

According to Check Point, the Fireball package is mostly surreptitiously inserted into free software downloads and installed without the user’s knowledge. Check Point provides a few examples of software found to contain the Fireball package, including Soso Desktop and FVP Imageviewer. The clearest sign of an infection is finding your browser has been redirected to a new homepage. Checkpoint’s post provides detailed instructions for detecting and eliminating infections.

“According to our analysis, Rafotech’s distribution methods appear to be illegitimate and don’t follow the criteria which would allow these actions to be considered naïve or legal,” Check Point writes. “The malware and the fake search engines don’t carry indicators connecting them to Rafotech, they cannot be uninstalled by an ordinary user, and they conceal their true nature.”

Rafotech’s homepage, Rafotech.com, is currently offline, but archived versions from 2016 tout the company’s ability to sell “creative ads” for website operators. The site also makes thoroughly ironic claims about a “strong anti-spamming system.”

The archived site also touts Rafotech’s role in publishing mobile apps including games like Cutie Clash and Casual Warrior. Considering recent revelations about the potential for Android apps to load malicious software onto phones, it’s worth steering clear of these and any other Rafotech products.

Rafotech’s LinkedIn page describes the company as a unit of “one of the premium publisher powering over 6 billion monthly impressions” and touts its “deep understanding of what it means to monetize more.”

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Most Popular

placeholder alt text
Personal Finance
Janet Yellen warns the $38 trillion national debt is testing a red line economists have feared for decades
By Eva RoytburgJanuary 5, 2026
2 days ago
placeholder alt text
Success
Blackstone exec says elite Ivy League degrees aren’t good enough—new analysts need to 'work harder' and be nice 
By Ashley LutzJanuary 5, 2026
2 days ago
placeholder alt text
AI
Experienced software developers assumed AI would save them a chunk of time. But in one experiment, their tasks took 20% longer
By Sasha RogelbergJanuary 5, 2026
2 days ago
placeholder alt text
Personal Finance
Current price of silver as of Monday, January 5, 2026
By Joseph HostetlerJanuary 5, 2026
2 days ago
placeholder alt text
Economy
Mark Cuban on the $38 trillion national debt and the absurdity of U.S. healthcare: we wouldn't pay for potato chips like this
By Nick LichtenbergJanuary 6, 2026
15 hours ago
placeholder alt text
Future of Work
Bank of America CEO says he hired 2,000 recent Gen Z grads from 200,000 applications, and many are scared about the future
By Ashley LutzJanuary 3, 2026
4 days ago

Latest in Tech

AIRecruiting
To ease recruiters’ fears of being replaced by AI, Zillow experimented with ‘prompt-a-thons.’ Now the real estate giant has 6 new recruitment tools
By Paige McGlauflin and HR BrewJanuary 6, 2026
10 hours ago
zhan, deepak
AIRobotics
Robots are really advancing because they’re learning to think for themselves—and they’re close to figuring out door handles, execs say
By Nick LichtenbergJanuary 6, 2026
11 hours ago
LawAmazon
Amazon is cutting checks to millions of customers as part of a $2.5 billion FTC settlement. Here’s who qualifies and how to get paid
By Sydney LakeJanuary 6, 2026
13 hours ago
InvestingU.S. economy
Ray Dalio says AI is in ‘the early stages of a bubble,’ so watch out for 2026
By Tristan BoveJanuary 6, 2026
13 hours ago
musk
AISocial Media
Elon Musk’s Grok chatbot draws global backlash for generating sexualized images of women and children without consent
By Kelvin Chan and The Associated PressJanuary 6, 2026
13 hours ago
Databricks CEO Ali Ghodsi speaking on stage at a Fortune tech conference.
AIEye on AI
Want AI agents to work better? Improve the way they retrieve information, Databricks says
By Jeremy KahnJanuary 6, 2026
13 hours ago