Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts

Wednesday, January 9, 2008

First iPhone Trojan Horse Reported

Seen more as a prank than an actual threat, a Trojan horse for the Apple iPhone, first reported on Saturday, has already come and gone reports CNET News. Still, users should be on the look out for a package called "iPhone firmware 1.1.3 prep," described as something you need to install before updating to the new 1.1.3 firmware. Billed as an "important system update," the code does little more than cause annoyance. According to various sources, once the Trojan is installed it simply displays the word "shoes."

However, the Trojan also overwrites several legitimate applications, including Erica's Utilities, Launcher, Doom, and OpenSSH, meaning that if you uninstall the Trojan, you will need to reinstall these applications later. This appears to be a consequence of poor programming.

The risk to iPhone users is now considered negligible since the host sites have all been taken down.

As antivirus vendor F-Secure concluded in its blog, "This time it was an 11-year-old kid playing with XML files who created the Trojan. Next time it might be someone else with more skills and with specific target."

Read the rest...

Digg Technorati del.icio.us Stumbleupon Reddit Blinklist Furl Spurl Yahoo Simpy

Sunday, December 30, 2007

Trojan Capitalizes on Bhutto Assassination

Whatever else malware creators might be, they're quick to take advantage of any event that might enable a new attack vector. The Storm Worm has already morphed twice in the past week, attacking with both a Christmas and a New Year's theme. Now, less than two days after the assassination of Benazir Bhutto, former Prime Minister of Pakistan and leader of the Pakistan People's Party, there's a new malicious Javascript in town. The script in question isn't brand-new, but its creators have quickly adapted it to prey on surfers interested in additional details regarding Bhutto's death.

According to Trend Micro researchers, certain sites purporting to contain information on the assassination have malicious Javascript embedded within them. End users wanting more information on the event can conceivably be directed to one of these infected sites, where the script (identified by Trend Micro as JS_AGENT.AEVE) runs and downloads a Trojan (TROJ_SMALL.LDZ). This new Trojan then downloads and installs WORM_HITAPOP.O and TROJ_AGENT.AFFR.

While the authors of this particular gem are obviously trying to exploit Bhutto's murder, Trend Micro found evidence that the malicious Javascript is actually present on a number of sites, including Autoworld, Vino, MSN, and BlogSpot. The number of infected sites that specifically discuss the assassination is small compared to the total number of sites that appear to be infected—103 vs. 4,240—but the ratio will undoubtedly shift if the topic proves to be an effective attack vector. Trend Micro has stated that its customers are already protected from the exploit; other vendors will probably be quick to follow with patches as they are needed.

Source

Read the rest...

Digg Technorati del.icio.us Stumbleupon Reddit Blinklist Furl Spurl Yahoo Simpy

Friday, December 21, 2007

Trojan Attacks Adsense Code

FRANKFURT (Reuters) - Advertisements placed by Google in Web pages are being hijacked by so-called trojan software that replaces the intended text with ads from a different provider, Romanian antivirus company BitDefender says.

The trojan redirects queries meant to be sent to Google servers to a rogue server, which displays ads from a third party instead of ads from Google, BitDefender said in a statement.

Google said on Wednesday: "We have cancelled customer accounts that display ads redirecting users to malicious sites or that advertise a product violating our software principles."

"We actively work to detect and remove sites that serve malware in both our ad network and in our search results. We have manual and automated processes in place to detect and enforce these policies."

The trojan, named after the mythic Trojan Horse because of its ability to enter computer systems undetected, attacks Google's AdSense service, which targets advertisements to match Web page content.

"This is a serious situation that damages users and Webmasters alike," said BitDefender virus analyst Attila Balazs.

"Users are affected because the advertisements and/or the linked sites may contain malicious code," he said. "Webmasters are affected because the trojan takes away viewers and thus a possible money source from their Websites."

BitDefender on its Web site (www.bitdefender.com) describes the trojan, which it identifies as Trojan.Qhost.WU, as spreading at a "low" level and causing "medium" damage.

Source

Read the rest...

Digg Technorati del.icio.us Stumbleupon Reddit Blinklist Furl Spurl Yahoo Simpy