Redirectors in Compromised Sites Used in Spam Messages

Busy day in TrendLabs today, first the full analysis and news that ZeuS and SALITY are exploiting the Windows Shortcut vulnerability, and now we’ve identified a ton of compromised web sites leading to an “online pharmacy”. We’re currently seeing a wave of fake pharma spam emails which do not directly advertise the URL of [...]

A Look at ZBOT 2.0 Information Theft

TSPY_ZBOT.CQJ is one of the new ZeuS/ZBOT 2.0 variants spotted earlier this year. Let’s take a look at one of the methods it uses to steal users’ banking credentials. These new ZBOT variants intercept the information users enter into a bank’s Web page by inserting predefined JavaScript code into the said page. At present, [...]

Redirectors in Compromised Sites Used in Spam Mails

Busy day in TrendLabs today, first the full analysis and news that ZeuS and SALITY are exploiting the Windows Shortcut vulnerability, and now we’ve identified a ton of compromised web sites leading to an “online pharmacy”. We’re currently seeing a wave of fake pharma spam emails which do not directly advertise the URL of [...]

ZeuS/ZBOT and SALITY Jump on the LNK Exploit Bandwagon

As reported last week, exploits targeting the Windows shortcut zero-day vulnerability have risen in number. It is also now being used to spread ZBOT variants via malicious attachments to spammed messages, now blocked by Trend Micro products, with the subject Microsoft Windows Security Advisory and the following message: The message claims to come from Microsoft [...]

Avoiding the Whack-a-Mole Anti-Phishing Tactic

Imagine playing a whack-a-mole game where the mole moves to a different hole in the amount of time it takes one to raise and lower a mallet. Instead of just six holes, however, there are millions. Few would want to play such a game. People would rightfully conclude that random attempts to hit the mole [...]