Haiti: Earthquake Unearths Malware

After the earthquake that hit Haiti last week, January 12, the Internet was flooded with requests for financial donations, although it may be noted that not all of which were true to their stated intentions. Martin Roesler, Trend Micro Director of Threat Research, warns users of the internet to be very careful when following [...]

Trend Micro To Help Proactively Protect Against Zero-Day Attacks like the recent IE Explorer Exploit

The recent attacks on Google and other large organizations (currently being referred to by others as Aurora, Google Attacks, Hydraq) were a set of carefully orchestrated, sophisticated and highly complex attacks. They comprised malicious threats to all three communication vectors – email, web and files, plus most notably, a zero-day vulnerability in Internet Explorer. [...]

New IE Zero-Day Exploit Attacks Continue

Trend Micro has identified new malware samples that exploit the still-unpatched Internet Explorer (IE) vulnerability.  These samples have been detected as JS_ELECOM.C and HTML_COMLE.CXC Further analysis by TrendLabs threat experts found that the new scripts are versions of JS_DLOADER.FIS (the only difference being the encryption techniques used), which was widely used in the recent [...]

SASFIS Fizzles in the Background

The number of systems infected by various SASFIS Trojan variants has been increasing since the end of 2009, affecting networks across the globe. SASFIS variants have recently been spotted in relation to spoofed messages supposedly from Facebook. SASFIS infections usually result in tons of other malware infections, as this particular family makes systems susceptible to [...]

Phishing in the Guise of Enhancing Security

Trend Micro fraud analysts recently came across spammed messages targeting customers of the Fifth Third Bank. The messages urged recipients to log in to a temporary link, http://www.53.com.{BLOCKED}.com.pl/wpserver/cmportal/cblogin.php?session=667882698791972326077742654898739&email=p2t2all@tacobell.com, in order to download and install a digital certificate that would supposedly reinforce the bank’s security. Clicking the link, however, led users to a phishing page that [...]