Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
First detected on Friday, the message reads: “This update is critical and provides you with the latest version of Microsoft Outlook/Outlook Express and offers the highest levels of stability and security.” The email instructs users to visit the “Microsoft Update Center,” but when attempting to follow the link, they download a trojan known as “ZBot” or “Zeus,” Ivan Macalintal, threat researcher at Trend Micro, told SCMagazineUS.com. “ZBot is a notoriously known information stealer,” Macalintal said. Upon execution, ZBot copies itself onto a user's computer and creates two files -- one is an encrypted file that is downloaded from a remote server and contains commands from the botnet master. The commands contain a list of targeted banking institutions, social networks and other sites for the trojan to monitor, including Facebook, MySpace, Flickr, Bank of America and Wachovia, Macalintal said. If a user visits one of these sites, the trojan will log a user's keystrokes to obtain login credentials, along with credit card or other sensitive information. It saves the information that is gathered in a second file created on the user's computer, and then sends the file back to the attacker's server, Macalintal said.Macalintal added that there have been many variants of this trojan in the wild and it was previously infecting users by means of drive-by download. A previous variant masqueraded as an email notice from UPS. A different email attack, spoofed to look like it was coming from Delta Airlines to confirm a ticket purchase, had distributed a trojan with properties of ZBot.The most recent attack is still being circulated in the wild, Macalintal said. Considering that there have been many legitimate Microsoft updates in the past, this malware has the potential to infect a large number of users, he added.In October, security researchers warned of a similar attack, in which a fake phishing email seemingly coming from Microsoft contained a different trojan.See original article on scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.