Sidebar: Trojan Horse Spreads via Mass Spam Mailing
IDG News Service - Antivirus and e-mail security companies last week sent out warnings about a new Trojan horse program that they claim is being mass distributed on the Internet by means of spam.
The program, called Backdoor-CGT, is a new form of a Trojan horse that's installed when users of Microsoft's Outlook e-mail program follow a Web link embedded in an e-mail message. The Trojan horse was believed to have infected thousands of systems even though antivirus software and up-to-date versions of Outlook are immune to attack, said Maksym Schipka, senior antivirus researcher at MessageLabs Ltd. in Gloucester, England.
MessageLabs received more than 3,600 e-mail messages with links to the Trojan horse during a two-hour period, the result of a spam distribution that was more than 10 times the normal amount for such a program, he said. Trojan horse programs give remote attackers access to or control over machines on which they run, and they often run unnoticed by users or pose as legitimate applications.
The Backdoor-CGT program uses a "multistage" attack to place malicious code on victims' computers. After clicking on an e-mail link embedded in the spam message, victims go to a series of Web sites, each of which carries out one stage in the attack.
The attack takes advantage of a now-patched flaw in Outlook called the "IFRAME" exploit to hide the Web site redirections from the user and silently download and install the Backdoor-CGT program, Schipka said.
McAfee also released an advisory about the new Trojan horse, which is also known as "SS," but rated it a "low" threat to users. McAfee has released software update files to detect the Trojan horse, according to the advisory.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Reducing the Cost and Complexity of Web Vulnerability Management
- Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.
Download this... - Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All Malware and Vulnerabilities White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Malware and Vulnerabilities Webcasts