Botnet hijack: Inside the Torpig malware operation

Security researchers at University of California, Santa Barbara have broken into the nerve center of the Torpig botnet (also called Sinowal or Mebroot) to find a 10-day stash of 10,000 bank accounts and credit card numbers worth hundreds of thousands of dollars. During the botnet hijack, the researchers exploited a weakness in the way [...]

Koobface Tries CAPTCHA Breaking

Early this week, we’ve encountered a new Koobface spam campaign which involved links that eventually led users to this Youtube copycat web page.

The scheme uses the old flash player trick (see Figure 1) where the user is told that they need to download the latest version of Adobe Flash Player to view a [...]

Porn Sites Lead to MBR Rootkit

Websites related to pornography that appear to be compromised were found by Trend Micro engineers loading malicious JavaScript which redirects users onto malicious domains that ultimately lead to the download of an MBR rootkit (TROJ_SNOWAL.A)onto the affected system.

The malicious JavaScripts are now detected as the following:

JS_IFRAME.APQ JS_IFRAME.ABG JS_IFRAME.QD JS_PSYME.CRT JS_IFRAME.APU JS_IFRAME.APW

The [...]

Swine Flu Spam Attempt to Infect Japanese Users

Another swine flu-related spam run was recently reported, this time targeting Japanese users. Aside from using the swine flu as its social engineering method, which has already been used in earlier spam runs, this spam run also uses a technique where the sender of the message appears to use the .yahoo.co.jp domain. This serves [...] [...]