Category Archives: Phishing Trojans

Phishing Scheme Targets E-Payment Rule-Maker, NACHA

By Andrew Brandt

Coming on the heels of similar fraud schemes that targeted victims using the names of such familiar institutions as the FDIC, IRS, and HMRC, scammers are trying to get people to infect their own computer using a different organization’s name—one that is probably unfamiliar to most people. NACHA is a not-for-profit association that [...]

Lazy Phishers Just Email the Phishing Web Page to You, Now

By Andrew Brandt

It was a particularly busy weekend for spammers, especially the creepy, evil ones who are trying to steal information (as opposed to the merely scungy pill vendors and their ilk). Webroot’s Threat Research team has recently seen a glut of phishing messages which, like most, purport to come from banks and ask you to update your [...]

IRS Tax “Warning” Fraud Crosses the Pond, Targets the UK

By Andrew Brandt

For several months, we’ve been seeing spam and phishing Web sites which purport to be IRS notifications of delinquent non-payment of income taxes. Who can blame the fraudsters — almost no three letter agency of the US government inspires more dread and fear than good old Internal Revenue.
In the UK, the counterpart to [...]

Shields Up During National Cyber Security Awareness Month

By Mike Kronenberg

Be suspicious. About email swindles, bogus security products and online scams. I’m not kidding around. You need to pay attention and be diligent, because cyberthreats are lurking everywhere.
What got me thinking about this was President Obama’s proclamation of October as National Cyber Security Awareness Month. He said that all users — not just [...]

Trojan Decodes Captchas Using Stolen Commercial Tools

By Andrew Brandt

A new Trojan quietly circulating in the wild uses components from a commercial optical character recognition (OCR) application to decode captchas, those jumbled-text images meant to help a website discern human activity from automated bots.
The OCR-using captcha breaking tool is just one component of the Trojan. Its main purpose appears to be to [...]

One Click, and the Exploit Kit’s Got You

By Andrew Brandt

After all the brouhaha surrounding the NYTimes.com website hosting ads which spawned rogue antivirus Fakealerts last weekend, I spent a considerable amount of time looking at so-called exploit kits this week. These are packages, made up of custom made Web pages (typically coded in the PHP scripting language), which perform a linchpin activity [...]

‘Koobfox’ variant digs for Firefox cookies

By Andrew Brandt

A new variant of the Koobface worm started striking out this week, with a twist: Where the older Koobface would steal and use the cookies saved by Internet Explorer which store social network logins in order to spread its infectious messages in the victim’s name, this new variant is pulling down a tool [...]

The WoW Catphishers are Biting

By Andrew Brandt

The body’s barely cold from last week’s BlizzCon, but the script kiddies who write phishing kits have been hard at work putting their best foot forward, crafting account-stealing code that targets gullible WoW players who want an early peek at the just-announced Cataclysm expansion. These Catphish pages, linked off of YouTube video postings [...]

How Phishers Target WoW Players

By Andrew Brandt, Curtis Fechner, and Grayson Milbourne

Yesterday, at the opening of our BlizzCon coverage, we showed you just how commonly phishers target WoW players by posting innocuous-looking links in message board or forums frequented by players. Today, we’ve produced a really short video that shows exactly how someone infects their computer with a phishing [...]

BlizzCon, Gamers, WoW Trojans, Oh My

By Curtis Fechner and Grayson Milbourne

Tomorrow morning, Blizzard Entertainment (the publisher of the wildly popular World of Warcraft franchise) will kick off another BlizzCon to show off their latest projects and directly interact with their fanbase. World of Warcraft will likely take center stage at the convention, which has become the venue of [...]