News aggregator

Trick or Threat?

Fri, 10/30/2009 - 11:27
The month of October in the threat landscape is often associated with scary social engineering tactics in time for Halloween. As in years past, the threats that lurk in and plague the current threat landscape are real. Most of them can cause irreparable damage, often resulting in information, or worse, identity theft as shown in [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Trick or Threat?

Categories: New Viruses

This Halloween, Enjoy the Treats but Be Wary of Online Tricks

Fri, 10/30/2009 - 10:06
We often associate Halloween with pumpkins and costumes but for cybercriminals it’s merely another avenue to exploit, steal, and trick users into giving away their personal identities. Treats are fun but we all need to be on the lookout for the sneaky and tricky ways cybercriminals slither into our computers.  Below are the TrendLabs, top 7 [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

This Halloween, Enjoy the Treats but Be Wary of Online Tricks

Categories: New Viruses

Social Engineering Watch: Spam Leads to Canadian Pharmacy Sites

Thu, 10/29/2009 - 10:05
Trend Micro researchers found over 200 email samples that spamvertised male sexual enhancement pills. These bore subjects like “Re: Go wild in bedroom,” “Re: Let your lever straight up,” and “Re: Be her concrete-rod satisfier” and contains a URL that points to all-too-familiar Canadian pharmacy websites. While spammed messages that lead to Canadian pharma sites are not [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Social Engineering Watch: Spam Leads to Canadian Pharmacy Sites

Categories: New Viruses

Taiwan: Spear Phishers Target Gmail Users

Thu, 10/29/2009 - 09:44
Trend Micro threat analysts found several phishing sites registered in China that target specific people or companies. The said email can customize phishing URLs using the names of intended recipients via a technique called “spear phishing.” Spear phishing has been used by cybercriminals before in attacks that involved specific targets. In the previous post, “So Is It Twitter or [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Taiwan: Spear Phishers Target Gmail Users

Categories: New Viruses

Fake Facebook Password Notification Leads to Malware

Wed, 10/28/2009 - 08:02
A new spam campaign that purports to be from Facebook is making rounds today. It bears the subject, “Facebook Password Reset Confirmation,” and informs users that their passwords have been changed for security purposes. It then asks them to open the attached .ZIP file that supposedly contains their new passwords, which in actual fact is [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Fake Facebook Password Notification Leads to Malware

Categories: New Viruses

FDIC Spam Points to Info Stealer

Wed, 10/28/2009 - 06:06
Trend Micro researchers recently found spam emails fashioned to come from Federal Insurance Deposit Corporation (FDIC). The email message informs users that they should visit the “official” FDIC’s website (provided in the email) to check their Deposit Insurance Coverage. However, clicking the URL leads users to a fake FDIC website where they are ask to download [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

FDIC Spam Points to Info Stealer

Categories: New Viruses

IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security

Mon, 10/26/2009 - 20:57
Have you ever noticed how security often takes a backseat when trying something new? When I am trying out a protocol out for the first time, I barely skim the Security Considerations section of the RFC. Just the same, as more of us start experimenting with IPv6, the use of tunneling protocols is likely to [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security

Categories: New Viruses

Spoofed Contract Carries Malware

Sat, 10/24/2009 - 12:58
Trend Micro researchers found spammed messages with a .ZIP file attachment that contains a malware. It bears the subject, “Contract of Settlements,” and purports to come from LSM Company. It informs users to open and check the attached file that holds a contract, which in actual fact, is an executable file (contract_1.exe) detected by Trend [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Spoofed Contract Carries Malware

Categories: New Viruses

FAKEAV Goes Open Source… Or Not?

Fri, 10/23/2009 - 21:38
In the recent FAKEAV spam campaign, I realized something was off. Once the user clicks the URL and gets the bogus Antivirus 2010 up and running on his/her system, files are added. The additional files I found were related to ClamAV, the open source AV toolkit for UNIX. The files include the ClamAV virus definition file and [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

FAKEAV Goes Open Source… Or Not?

Categories: New Viruses

Windows 7? No Problem for Trend Micro Users

Fri, 10/23/2009 - 10:06
Microsoft’s new OS, Windows 7, was made available to the general public earlier today. To say that this was eagerly anticipated is an understatement, however, as in the United Kingdom, pre-orders on Amazon for copies exceeded both the last book of the Harry Potter series as well as the Nintendo Wii. This made it the biggest grossing pre-ordered item [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Windows 7? No Problem for Trend Micro Users

Categories: New Viruses

ZBOT and a CapitalOne Phish

Thu, 10/22/2009 - 13:09
In this most recent spam campaign, our spam traps caught an uncanny combination of a CapitalOne phish and a ZBOT variant. Below is a screenshot of an email sample making the rounds: The spam campaign would have you believe that you would need to install a Digital Certificate in order to use CapitalOne’s website. [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

ZBOT and a CapitalOne Phish

Categories: New Viruses

Halloween Job Spam Spooks Users

Thu, 10/22/2009 - 09:54
Holidays are spammers’ favorite times of the year. After all, these give them additional opportunities to lure more victims to their specially crafted scams apart from a theme to focus on. As one of the most celebrated holidays across the globe, it is not surprising that Halloween, which is barely a week away, has been [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Halloween Job Spam Spooks Users

Categories: New Viruses

FAKEAV Uses Conficker Worm as Bait

Wed, 10/21/2009 - 22:20
Very recently, cybercriminals have found another avenue to lure victims into their trap by using Microsoft as bait. A screen shot of one such campaign is shown in Figure 1 below. The email asks the recipient to download and install the attached .zip file (shown in Figure 2) which is actually a malicious file which purports [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

FAKEAV Uses Conficker Worm as Bait

Categories: New Viruses

Fake Agents for Russian Websites Spreading

Tue, 10/20/2009 - 12:16
In the past few weeks, Trend Micro researchers have become aware that the Russian cybercriminal underground has been overflowing with offers for a new kind of information-stealing malware. These new malware variants pose as agent programs used by Russian social networking sites, such as Odnoklasniki and Vkontakte. (Agent programs are programs used by some websites [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Fake Agents for Russian Websites Spreading

Categories: New Viruses

New Banking Trojan Uses GMER

Tue, 10/20/2009 - 11:22
Brazilian banks are once again in the hotseat as a banking Trojan emerges with a new technique. This time, the cybercriminals targeting these banks are using GMER, a popular anti-rootkit application. Trend Micro detects this banking Trojan as TROJ_DLOAD.BB. Upon execution, this Trojan downloads a legitimate copy of GMER and a malicious rootkit component detected [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

New Banking Trojan Uses GMER

Categories: New Viruses

Another Day, a New Zero-Day Exploit for Adobe

Fri, 07/24/2009 - 14:14
It has been a busy week for Adobe as only a few days after the software company announced that it would put up a vulnerable PDF Reader on its download site, a more serious one bubbled up. Trend Micro researchers recently came across samples that exploited a new zero-day vulnerability in Adobe Reader 9.1.2 and Adobe [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Another Day, a New Zero-Day Exploit for Adobe

Categories: New Viruses

“Solar Eclipse 2009 in America” Leads to FAKEAV

Thu, 07/23/2009 - 07:28
Yesterday’s solar eclipse over parts of Asia was witnessed by millions of people, so it shouldn’t come as a surprise that it should attract the attention of cybercriminals. And it has. Cybercriminals wasted no time in riding on the said phenomenon as they use SEO poisoning to lead users into redirecting to a site peddling [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

“Solar Eclipse 2009 in America” Leads to FAKEAV

Categories: New Viruses

New KOOBFACE Upgrade Makes It Takedown-Proof

Wed, 07/22/2009 - 14:51
Early this week, the KOOBFACE Command and Control (C&C) servers issued a new command to its downloader component. This new command identifies a list of IP addresses to be used by the downloader component as Web or relay proxies to retrieve subsequent commands and components. In the old KOOBFACE architecture (see Figure 1), the downloader [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

New KOOBFACE Upgrade Makes It Takedown-Proof

Categories: New Viruses

More Zero-Day Exploits for Firefox and IE Flaws

Tue, 07/21/2009 - 14:57
Earlier today, Senior Threat Researcher Joseph Reyes spotted several malicious script files that exploited Mozilla Firefox and Microsoft Internet Explorer vulnerabilities: JS_DIREKTSHO.B exploits a vulnerability in Microsoft Video Streaming ActiveX control to download other possibly malicious files. JS_FOXFIR.A accesses a website to download JS_SHELLCODE.BV. In turn JS_SHELLCODE.BV exploits a vulnerability in Firefox 3.5 to download WORM_KILLAV.AKN. JS_SHELLCODE.BU exploits [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

More Zero-Day Exploits for Firefox and IE Flaws

Categories: New Viruses

Photos From Michael Jackson’s Memorial Mask Malware

Mon, 07/20/2009 - 03:17
The sudden death of Michael Jackson caused not only an outpouring emotions from his family, friends, and fans, but also a spread of spam mails that took advantage of this tragic event. Even after his memorial service last July 7, 2009, spammers are clearly not resting as they try to spread other malicious spam messages. We [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Photos From Michael Jackson’s Memorial Mask Malware

Categories: New Viruses
Syndicate content