The Malicious Intent of the “Here You Have” Mail Worm, Part 2

Previously, we discussed the “Here You Have” mail attack and the associated malware, WORM_MEYLME.B. Today, let’s look into the backdoor payload, BKDR_BIFROSE.SMU. The “Here You Have” payload: A powerful backdoor Not all backdoor applications are created equal. As such, it can be said that the cybercriminals behind WORM_MEYLE.B deliberately opted to use a BIFROSE [...]

Backdoors in Twitter, Now in Arabic

Twitter is becoming a common medium to spread spam, malware and all kinds of badness. Just a few weeks ago, we wrote about FIFA and the Gaza attacks being used as social engineering leverage by Trojan creators, and there are no signs of them stopping any time soon. Over the past two weeks, several [...]

FIFA and Gaza Attack Tweets Dump Backdoors

What do the FIFA World Cup and Gaza attack have in common? They are both currently being used for social engineering by a couple of malware campaigns seen on Twitter. TrendLabsSMSenior Threat Researcher, Ivan Macalintal, spotted several malicious programs being distributed via the popular microblogging site. These malware campaigns take advantage of these noteworthy [...]

Spam Greets Users with a Backdoor

The only thing worse than receiving a spammed greeting card is a one that comes with malware. TrendLabs SM senior advanced threats researcher Loucif Kharouni recently acquired a sample spam in the form of an online greeting card. The said card urges recipients to check out the greeting card by clicking the image. Users who [...]

1.5 million Facebook accounts offered for sale – FAQ

In their latest “Weekly Threat report”, VeriSign’s iDefense Intelligence Operations Team has profiled the underground market proposition of someone claiming to have 1.5 million compromised Facebook accounts available for sale.The pricing method is based on the number of contacts per compromised account, presumably with the idea to allow easier spreading of related malicious content across [...]