19 Mar 2011
The US Computer Emergency Response Team (US-Cert) is warning users and administrators following the discovery of a potent new phishing operation.
The scam is targeting a number of institutions, including Bank of America, Lloyds, PayPal and TSB. The attacks appear as unsolicited emails carrying HTML attachments.
The attack is particularly dangerous in that it uses techniques to get around security filters designed to catch phishing sites.
"This attack is unlike common phishing attacks because it locally stores the malicious web page rather than directing users to a phishing site via a URL," the agency said.
"Many browsers use anti-phishing filters to help protect against phishing attacks; this method of attack is able to bypass this security mechanism."
The group advises consumers and administrators to use best practices for avoiding phishing attacks, such as not opening unsolicitied emails or suspicious email attachments.
The new attacks come on the heels of a shutdown that experts had hoped would cut down on spam loads. Microsoft spearheaded an effort with law enforcement which saw the infamous Rustock botnet taken down.
Other recent phishing attacks have targeted social network services such as Facebook.
Dave Marcus, head of research and communications for McAfee Labs, told V3.co.uk that people can avoid the recent scam and other phishing attacks by using best practices for security.
"Organisations and users should scan computers for vulnerabilities regularly, and ensure that security software is up-to-date," he said.
"End users should avoid opening emails from unknown sources and use safe browsing software."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Flash Developer- Actionscript 3.0, AJAX, JSON, computer...
Business Analyst - Risk platform - Equity Derivatives...
Java Developer - Algorithmic Trading - Global Trading...
Junior Middle Office Project Manager, Treasury, IB...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?