Monthly Archives: March 2009

DHL tracking number emails contain malware

Image (1) dhl-attack.jpg for post 12019

Once again the bad guys are hard at work, spamming out dangerous emails. This morning it's emails which claim to come from DHL, saying they were not able to deliver a postal package you sent on 14th of March because Read more…

Share

Skype Me/Spam Me?

Image (3) trojan250.png for post 2790

I've been a Yahoo and MSN'er for years, but over the weekend I decided to give Skype a go, as a simple means of saving money on International phone calls to my parents. Hard times, credit crunch, you know how Read more…

Share

Chinese mobile firm punishes staff for SMS spamming

Image (1) china-mobile.jpg for post 12018

Mobile phone spam sent via SMS text message is a huge problem in China. According to statistics from the Internet Society of China (ISC), an astonishing 353.8 billion spam text messages are sent every year in the country. I calculate Read more…

Share

I've been banned by the BBC!

Image (1) bbc-ban-3.jpg for post 12017

Mark Perrow, the executive producer of the controversial BBC Click documentary about botnets, published his justification for the programme on the BBC website. It's well worth reading if you're interested in understanding the BBC's opinion, and checking out other people's Read more…

Share

Ecard identity thief escapes jail

Image (1) hallmark-blue-mountain-logo.jpg for post 12016

Chances are that you're no stranger to receiving electronic greeting cards (ecards) in your inbox which claim to have been delivered by the likes of Blue Mountain and Hallmark. Sadly, cybercriminals know that many internet users find the thought of Read more…

Share

Mac malware authors still plugging away

Image (1) maccinema.jpg for post 20005

Last week, SophosLabs received several reports of some new Mac malware (Intego and Threat Researcher). So I asked around for samples (sample exchange) and was able to write detection on for OSX/RSPlug-F (and updated it for a minor variant). Like Read more…

Share

Competition in the detection stakes and the welfare model

Image (1) dog_eat_dog.png for post 20004

Members of the Anti-Virus software vendor community regularly exchange malware samples (secure PGP, of course) with each other. This fact is difficult for several visitors, eg customers, partners, etc, to SophosLabs to fathom. In a "dog-eat-dog" capitalist global economy why Read more…

Share

Antique Chair and a fake anti-virus

Image (1) antique-chair-1.jpg for post 20003

I was having a look at some of the sites serving up Fake Anti-Virus malware, and came across this interesting content on one of the pages: Whoever wrote that really has antique chairs on the brain, they seem to keep Read more…

Share

Suspected Pentagon hacker "Wolfenstein" arrested

Image (1) pentagon.jpg for post 12015

According to media reports, a 23-year-old man has been arrested in Romania, suspected of hacking into US Department of Defense systems in 2006. According to investigators, Eduard Lucian Mandru, of Iaşi, Romania, is not just a student at the local Read more…

Share

Heroes

Default image

As I'm sure you're by now aware, a security researcher named Charlie Miller was able to pwn Safari in 10 seconds at CanSecWest yesterday! A truly spectacular feat! I'm not even sure how he was able to type so fast! Read more…

Share

Natasha Richardson's death exploited by hackers

Image (1) natasha-richardson-malware.jpg for post 12014

Cybercriminals don't waste any time these days jumping on the coat-tails of breaking news stories in their attempt to infect as many computer users as possible. This time it's the tragic death of award-winning English actress Natasha Richardson, who died Read more…

Share

Has Australian list of banned websites been leaked?

Image (1) blacklist.jpg for post 13827

A list of some 2400 websites, said to have been deemed unsuitable by the Australian Communications and Media Authority (ACMA) for containing illegal content related to child abuse, rape and other criminal activities, has been published on the internet. The Read more…

Share

Drive-by download kit: Not so LuckySploit 

Image (2) googleroosevelt.jpg for post 2947

Over the past few months SophosLabs have been seeing a relatively new kit being used by attackers in drive-by downloads to infect victims with malware. The kit is known as LuckySploit, and in this blog I will take a brief Read more…

Share

Virtumundo Goes Auto

Default image

The behaviour of most autorun worms is generally predictable.  They copy themselves to the system folder, create an autorun file, spread to any available removable storage devices or network shares and change registry entries to enable themselves to run automatically. Read more…

Share

Michael Jackson quiz: we have a winner!

Image (1) michael-jackson1.jpg for post 13824

Last week I told you about some dodgy goings-on that had been spotted on Michael Jackson's website, and liberally sprinkled my blog post with titles of songs by the llama-loving moon-walking oxygen-tent-inhabiting phenomenon. In no particular order, here are the Read more…

Share

Stop staff plugging their body parts into your PCs

Image (1) usb-finger.jpg for post 13820

When is a thumb drive, not a thumb drive? When it's a finger drive! Finnish software engineer Jerry Jalava lost one half of his left ring finger in a motorcycle accident last year. The inventive computer programmer from Helsinki had Read more…

Share

More details on the Diebold ATM Trojan horse case

Image (1) atm-update.jpg for post 13815

Yesterday, Vanja Svajcer of SophosLabs described how he had discovered malware which appeared to be designed to steal information from users of Diebold ATM cash machines. I also published some discussion here on the Clu-blog about how the Trojan horses Read more…

Share

From Russia with money

Image (1) hi_mydear.png for post 19999

Today we started seeing a new malware campaign arriving on our spamtraps: The message appears to have been generated through a translator as the text is quite broken grammatically. If I decipher the message correctly, it purports to be from Read more…

Share

Is there malware lurking in your ATM?

Default image

Sophos Principal Virus Research Vanja Svacjer has posted a fascinating blog today about his discovery of malware which appears to target Diebold cash machines. You can read the full details in Vanja's blog post, but I thought it might be Read more…

Share

Credit card skimming malware targeting ATMs

Image (1) fbchat250.jpg for post 3143

From time to time, because they know I work for SophosLabs, my friends ask me about different malware types and forward me warnings of alleged malware outbreaks, which often turn out to be just standard hoax emails. If anybody asked Read more…

Share