Malware Attack Exploits Patched IE7 Vulnerability
A critical security flaw in Microsoft's Web browser IE7 has created an opportunity for hackers to remotely execute malicious software on the targeted system, including the possibility of a Trojan that could update itself, said antivirus firm Trend Micro.
According to Trend Micro, hackers are exploiting the particular vulnerability, MS09-002, by e-mailing to target users a specially created Word document. The spammed file, which looks genuine, is in reality a malevolent .DOC file that carries an ActiveX component ready to open any site infused with malware. If the exploit proves successful, a backdoor would be downloaded on the victim's system with further installation of a malicious file that steals sensitive data. The malware subsequently transmits the entire stolen information to a certain website through port 443.
Moreover, it appears that the malicious software has been reverse-engineered since it was created after the announcement of the patch, according to the security specialists. It has been observed that the code gathers data from the contaminated PC, encrypts and forwards the same to some the Chinese server.
Zdrnja further said that at first, some confusion prevailed regarding the attack as majority of the antivirus agencies referred to Word documents. While the exploit attacked IE7, it had until now been delivered as a .DOC file to the computer users.
Jamz Yaneza, Threat Research Manager at Trend Micro, states that the launch of the malicious software might have been coincided with the 50th anniversary of Tibetan uprising this year (2009), when politically characterized messages based on social engineering were sent to victims to lure them to view malicious attachments, as reported by CRN on February 17, 2009.
Meanwhile, the brief time gap between patch and malware means IT administrators would have to rush to update company servers, said security specialists.
Related article: Malware Authors Turn More Insidious
» SPAMfighter News - 26-02-2009
We are happy to see you are reading our IT Security News.
We do believe, that the foundation for a good work environment starts with fast, secure and high performing computers. If you agree, then you should take a look at our Business Solutions to Spam Filter & Antivirus for even the latest version of Exchange Servers - your colleagues will appreciate it!