All the latest UK technology news, reviews and analysis

Symantec warns of sophisticated World Cup malware

by Phil Muncaster

11 Jun 2010

Be the first to comment

  • Tweet this
worm
Malware writers are targeting users with World Cup themed malicious emails

Symantec Hosted Services (SHS) is warning of yet more targeted World Cup-based malware attacks using increasingly sophisticated methods to infect victims and compromise corporate systems.

Tony Millington, malware operations engineer at SHS, explained in a blog post that the firm had intercepted 45 targeted malware emails headed for various Brazilian companies.

"This social engineering attack exploits the excitement surrounding the 2010 World Cup in South Africa to prompt recipients to take actions which may compromise their systems and corporate information," he wrote.

"One particularly interesting element of this targeted attack is the use of two attack modes: a PDF attachment and a malicious link."

The email claims legitimacy by purporting to come from a well known sportswear manufacturer, and includes a malicious PDF attachment and a link back to the server which can result in downloaded malware. This tactic effectively doubles the chance of success for the cyber criminals, Millington explained.

"The inclusion of two methods of attack means that, even if the PDF is removed as suspicious by an anti-virus gateway, the malicious link remains in the body of the email and may still be delivered to the recipient," he said.

"This is because many email filtering systems are configured to simply remove or clean viral attachments, and will often allow the 'cleaned' email to be delivered to the recipient, in this case with the malicious link still intact."

The malware in question is an off-the-shelf information stealing botnet virus called SpyEye, which exploits a PDF flaw to enable hackers to take full control of the infected computer, said SHS.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Support Analyst

IT Support Analyst (initial 6 month fixed term) Cirencester...

Java Developer - Grad / Web / Mobile - Manchester

Java Developer - Graduate / Budding Superstar opportunity...

Solutions Consultant - JEE, PHP, Project Lead - Midlands

Solution Consultant - JEE, Support, Project Lead, SQL...

C++ Developer - Financial Vendor

C++ Developer - C++, STL, Boost, Delphi, Concurrency...

To send to more than one email address, simply separate each address with a comma.