All the latest UK technology news, reviews and analysis

Symantec warns of new Bredolab attacks

by Phil Muncaster

More from this author

18 Feb 2010

Be the first to comment

  • Tweet this
Spam
The latest Bredolab attack arrives in spam from webmail accounts

Symantec Hosted Services is warning of a targeted attack against seven different companies, using the infamous Bredolab malware in an attempt to steal corporate data.

Cyber criminals are increasingly targeting specific staff in certain organisations with a view to gaining access to potentially lucrative intellectual property or other sensitive data.

However, this new campaign is notable because Bredolab is usually "spammed out in vast quantities" rather than used in specific targeted attacks, according to Tony Millington, malware operations engineer at Symantec Hosted Services.

Millington said in a blog post that the new attack could also be a first for Bredolab in that it is being used to steal data, rather than turn the infected PC into part of a botnet or install fake security software.

"The malicious file in the email is indeed a variant of the Bredolab virus. It has exactly the same characteristics, except that the files it subsequently downloads are not the usual Bredolab fare," wrote Millington.

"They are, in fact, data stealers, and very few anti-virus companies identify the downloaded files at the time of writing."

The Bredolab payload in these attacks is typically a .scr file attachment in an email sent from a webmail account. The emails have been sent from IP addresses across the globe, and use webmail accounts to hide the malicious attachment under a veil of legitimacy, according to Millington.

"The fact that it's coming from all over the world strongly indicates that some form of botnet is being used to connect to the webmail service to send these malicious emails," he said.

"At the moment we are not certain which botnet, but it's highly likely to be linked to Cutwail, as virtually all the other Bredolab attacks we have seen originate from Cutwail."

This attack was aimed at organisations in the public and education sectors.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Project Co-ordinator (Junior or Graduate)

My client a leading company in the education and qualification...

Incident Manager - Investment Banking

Incident Manager - Investment banking Fantastic opportunity...

Senior Product Manager - Broadband

Senior Product Manager - Broadband Zen Internet...

Senior C# Developer

Senior C# Developer - Reigate: £60,000 to £80,000 + benefits...

To send to more than one email address, simply separate each address with a comma.