Home > Security News > New malcode disguised as fake security, CNN bulletins
Security News:
EMAIL THIS

New malcode disguised as fake security, CNN bulletins

By Bill Brenner, News Writer
21 Jan 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Two new pieces of malicious code appeared in the wild Friday -- one disguised as a message from Romanian security firm BitDefender; the other as a CNN news alert.

BitDefender CTO Bogdan Dumitru said in a statement that a virus called Sticy-A was spreading in an e-mail message with a spoofed "from" field [support@bitdefender.com], prompting users to download harmful executables from the "http://playb.........a.go.ro/" Web site. He said a virus definitions update has been issued, and the company that hosts the Web site in question has been contacted and asked to remove the offending site.

"We expect this to be the work of a bored Romanian student or somesuch," Dumitru said. "The whole set-up is amateurish in the extreme. Nevertheless, we have been receiving about 20 bounced e-mails per minute, so I suspect the virus is spreading at a steady pace."

He warned users not to follow the link or download the executables in question "under any circumstances whatsoever." He also recommended they update their antivirus with the latest virus definitions and to initiate a full scan of their computers "at their earliest convenience."

"The BitDefender support team does not, under any circumstances, send security warnings of any kind," he added.

Meanwhile, Lynnfield, Mass.-based antivirus firm Sophos has spotted a worm posing as a CNN news alert.

Crowt-A takes its subject lines, message content and attachment names from headlines gathered in real-time from the CNN Web site. It attempts to send itself by e-mail to addresses found on infected computers, the firm said.

"Its subject line and attachment share the same name, but continually change to mirror the front-page headline on the CNN news site," Sophos said. "The message text is also lifted from CNN's site, duping the recipient into thinking that they are reading a bona-fide newsletter rather than receiving an infected e-mail."

Crowt-A also installs a backdoor Trojan horse that tries to log keystrokes on infected PCs and send data back to a remote user. Attackers often use these Trojans to take control of PCs and to steal personal information like bank passwords, Sophos said.

"Virus writers are always looking for new tricks to entice innocent computer users into running their malicious code; this latest ploy feeds on people's desire for the latest news," Carole Theriault, a security consultant for Sophos, said in a statement. "Many people subscribe to legitimate e-mail news updates, but the message is simple -- businesses need to makes sure their antivirus detection is constantly updated and users need to be suspicious of all unsolicited e-mail whether it's promising celebrity pictures or news updates."

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts