12 Oct 2006
Cyber-criminals have created an "evil twin" website which aims to dupe unsuspecting visitors into believing that they are visiting the Google Italy site.
IT security firm SurfControl said today that it is currently tracking the malicious website, which attempts to install ActiveX controls on a visitor's PC.
The site uses 'typo-squatting' to ensnare victims, a technique that mimics a legitimate domain using a slightly different spelling. It has been configured to deliver a fraudulent Google Italy page that looks identical to the original.
ActiveX is installed automatically if Internet Explorer security settings allow installation of ActiveX controls. Otherwise, the end user will have to accept the installation for the infection to occur.
If the ActiveX control is accepted, a Trojan redirects the homepage to a website featuring adult content.
In addition to browser hijacking, the website installs a key-logging Trojan that monitors keystrokes and sends information to a remote location.
SurfControl has also witnessed incidents of infected machines attempting to send spam email that could have malicious intent.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Desktop Deployment Support Analyst (Worksite, SQL...
Project Manager is required by Bank in Germany Suitable...
Mobile & Social Media Application Web Developer...
CCVP Consultant - Telecoms Cisco Certified Voice Professional...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?