All the latest UK technology news, reviews and analysis

Symantec warns of new Bredolab attacks

by Phil Muncaster

18 Feb 2010

Be the first to comment

  • Tweet this
Spam
The latest Bredolab attack arrives in spam from webmail accounts

Symantec Hosted Services is warning of a targeted attack against seven different companies, using the infamous Bredolab malware in an attempt to steal corporate data.

Cyber criminals are increasingly targeting specific staff in certain organisations with a view to gaining access to potentially lucrative intellectual property or other sensitive data.

However, this new campaign is notable because Bredolab is usually "spammed out in vast quantities" rather than used in specific targeted attacks, according to Tony Millington, malware operations engineer at Symantec Hosted Services.

Millington said in a blog post that the new attack could also be a first for Bredolab in that it is being used to steal data, rather than turn the infected PC into part of a botnet or install fake security software.

"The malicious file in the email is indeed a variant of the Bredolab virus. It has exactly the same characteristics, except that the files it subsequently downloads are not the usual Bredolab fare," wrote Millington.

"They are, in fact, data stealers, and very few anti-virus companies identify the downloaded files at the time of writing."

The Bredolab payload in these attacks is typically a .scr file attachment in an email sent from a webmail account. The emails have been sent from IP addresses across the globe, and use webmail accounts to hide the malicious attachment under a veil of legitimacy, according to Millington.

"The fact that it's coming from all over the world strongly indicates that some form of botnet is being used to connect to the webmail service to send these malicious emails," he said.

"At the moment we are not certain which botnet, but it's highly likely to be linked to Cutwail, as virtually all the other Bredolab attacks we have seen originate from Cutwail."

This attack was aimed at organisations in the public and education sectors.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

east midlands

Our client, a highly successful and currently market...

To send to more than one email address, simply separate each address with a comma.