Latest news
Over the last few days, there have been a lot of e-mails in circulation exploiting the URLSpoof vulnerability, aimed at tricking users into divulging confidential information, such as account numbers, user names, passwords or other secret codes. These false messages claim to have been sent from banks -like Citibank or Barclays- and tell users that due to an error, they should go to a web page to check their data. However, the web page that they access via the malicious link will channel any information entered to the attacker who will then be able to use it for fraudulent purposes.
Downloader.AC, on the other hand, is sent in spam, and has the subject: "PAYPAL.COM NEW YEAR OFFER", and includes an attachment: "PAYPAL.EXE". When the file is run, the Trojan connects to a web page and downloads a file called "Temp", which it runs and saves in the hard disk root directory.
The second Trojan we're looking at today is Bookmark.C, which carries out a series of actions on the affected computer, such as changing the home page in Internet Explorer and adding links to pornographic websites to the favorites folder. It also redirects the default search page in Internet Explorer and, in some computers, it displays an error message saying it couldn't find a file.
Finally, Agent.A is a Trojan which goes memory resident and listens on port 46204 and another generated at random. It tries to update itself by connecting to web pages, which actually don't exist.


Spotlight

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

Application vulnerabilities still a top security concern
Posted on 16 May 2013. | Respondents to a new (ISC)2 study identified application vulnerabilities as their top security concern. A significant gap persists between software developers’ priorities and security professionals’ concerns.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






