Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
Teksavvy
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code
p2pnet - rss feed: http://p2pnet.net/p2p.rss | p2pnet celebrities: http://p2pnet.net/celeb.rss | Mobile? http://p2pnet.net/index-wml.php

New trojan threat: extortion

p2pnet.net News:- A new trojan-based attack that encodes files on infected machines and then drops a ransom note has been identified.

Websense Security Labs says when someone visits a malicious website that exploits a “previous vulnerability in Microsoft Internet Explorer,” they pick up the initial infection which allows applications to be run remotely.

“The malicious website uses the Windows help subsystem and a CHM file to download and run a Trojan Horse (download-aag),” says the post.

“The downloader then connects, via HTTP, to another malicious website. This website hosts the application that encodes files on the user’s local hard disk and on any mapped drives on the machine. The malicious code also drops a message onto the system with instructions on how to buy the tool needed to decode the files.

“This message includes the email address of a third party to contact for instructions, and the user is directed to deposit money into an online E-Gold account.”

Even though this type of attack, “is not widespread at this point, Internet users should be aware of the threat,” ZDNet UK quotes Symantec spokesman Oliver Friedrichs as saying, “It is certainly concerning. This is the first time that we have seen cryptography used in this type of attack to hold your information hostage.”

Attackers could use email, a Web site or other means to distribute the Trojan.Pgpcoder and launch a widespread extortion campaign, Symantec’s Friedrichs said,” adds the story.

See:-
Websense Security Labs - Malicious Website / Malicious Code:, May 23, 2005
ZDNet UK - Trojans used for online extortion, May 25, 2005


HOME

3 Responses to “New trojan threat: extortion”

  1. Reader's Write Says:

    This tactic has been used in the past. Only now, it is in the form od an automatically executing exploit. This is yet another reason not to use crap produced my Micro$oft.

  2. Reader's Write Says:

    “previous vulnerability in Microsoft Internet Explorer,”

    Doesn’t this mean that if you have applied the updates you have nothing to worry about?

  3. Reader's Write Says:

    It means: GET FIREFOX ;)

Leave a Reply

    Advertisments
MP3rocket