Seen more as a prank than an actual threat, a Trojan horse for the Apple iPhone, first reported on Saturday, has already come and gone reports CNET News. Still, users should be on the look out for a package called "iPhone firmware 1.1.3 prep," described as something you need to install before updating to the new 1.1.3 firmware. Billed as an "important system update," the code does little more than cause annoyance. According to various sources, once the Trojan is installed it simply displays the word "shoes."
However, the Trojan also overwrites several legitimate applications, including Erica's Utilities, Launcher, Doom, and OpenSSH, meaning that if you uninstall the Trojan, you will need to reinstall these applications later. This appears to be a consequence of poor programming.
The risk to iPhone users is now considered negligible since the host sites have all been taken down.
As antivirus vendor F-Secure concluded in its blog, "This time it was an 11-year-old kid playing with XML files who created the Trojan. Next time it might be someone else with more skills and with specific target."
Wednesday, January 9, 2008
First iPhone Trojan Horse Reported
Sunday, December 30, 2007
Trojan Capitalizes on Bhutto Assassination
Whatever else malware creators might be, they're quick to take advantage of any event that might enable a new attack vector. The Storm Worm has already morphed twice in the past week, attacking with both a Christmas and a New Year's theme. Now, less than two days after the assassination of Benazir Bhutto, former Prime Minister of Pakistan and leader of the Pakistan People's Party, there's a new malicious Javascript in town. The script in question isn't brand-new, but its creators have quickly adapted it to prey on surfers interested in additional details regarding Bhutto's death.
According to Trend Micro researchers, certain sites purporting to contain information on the assassination have malicious Javascript embedded within them. End users wanting more information on the event can conceivably be directed to one of these infected sites, where the script (identified by Trend Micro as JS_AGENT.AEVE) runs and downloads a Trojan (TROJ_SMALL.LDZ). This new Trojan then downloads and installs WORM_HITAPOP.O and TROJ_AGENT.AFFR.
While the authors of this particular gem are obviously trying to exploit Bhutto's murder, Trend Micro found evidence that the malicious Javascript is actually present on a number of sites, including Autoworld, Vino, MSN, and BlogSpot. The number of infected sites that specifically discuss the assassination is small compared to the total number of sites that appear to be infected—103 vs. 4,240—but the ratio will undoubtedly shift if the topic proves to be an effective attack vector. Trend Micro has stated that its customers are already protected from the exploit; other vendors will probably be quick to follow with patches as they are needed.
Source
Labels: Antivirus, Benazir Bhutto, Trend Micro, trojan
Friday, December 21, 2007
Trojan Attacks Adsense Code
FRANKFURT (Reuters) - Advertisements placed by Google in Web pages are being hijacked by so-called trojan software that replaces the intended text with ads from a different provider, Romanian antivirus company BitDefender says.The trojan redirects queries meant to be sent to Google servers to a rogue server, which displays ads from a third party instead of ads from Google, BitDefender said in a statement.
Google said on Wednesday: "We have cancelled customer accounts that display ads redirecting users to malicious sites or that advertise a product violating our software principles."
"We actively work to detect and remove sites that serve malware in both our ad network and in our search results. We have manual and automated processes in place to detect and enforce these policies."
The trojan, named after the mythic Trojan Horse because of its ability to enter computer systems undetected, attacks Google's AdSense service, which targets advertisements to match Web page content.
"This is a serious situation that damages users and Webmasters alike," said BitDefender virus analyst Attila Balazs.
"Users are affected because the advertisements and/or the linked sites may contain malicious code," he said. "Webmasters are affected because the trojan takes away viewers and thus a possible money source from their Websites."
BitDefender on its Web site (www.bitdefender.com) describes the trojan, which it identifies as Trojan.Qhost.WU, as spreading at a "low" level and causing "medium" damage.
Source Read the rest...