Members
  • Total Members: 12818
  • Latest: martin
Stats
  • Total Posts: 28535
  • Total Topics: 8240
  • Online Today: 980
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)












Author Topic: Zeus spyware pretends to be Royal Mail PDF (Zbot trojan)  (Read 2219 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum


Zeus spyware Trojan variants have begun using PDF files to package exploits.

Thousands of spammed messages containing exploit-ridden attachments posing as delivery notices from the Royal Mail have been intercepted by net security firm Websense this week.

The PDF attachment contains an embedded executable containing the Zeus payload. Users get a warning before this executable is run, but long experience shows that many user will simply click through such warnings.

Once infected, compromised machines 'phone home' to hacker controlled servers in China.

Other Zeus variants using the same attack strategy also spotted this week come disguised as a billing invoice, warns M86 Security Labs.

Zeus (aka Zbot) is a family of information stealing, customised crimeware tools on sale on the digital underground and widely linked to bank fraud scams. The latest attack is a more sophisticated variant on previous attacks featuring malware-laced email attachments or (more inferquently) drive-by download attacks.

The techniques used by the latest Zeus attacks are similar to the launch embedded executable from PDF security shortcoming of multiple PDF reader packages first explained by security researcher Didier Stevens late last month: http://blog.didierstevens.com/2010/03/29/escape-from-pdf

Websense's advisory, which contains screenshots of the malware-laced spam emails and a detailed explanation of how the attack works, can be found here: http://securitylabs.websense.com/content/Alerts/3593.aspx?cmpid=slalert

(ElReg.)

Samker's Computer Forum - SCforum.info





 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising