This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

FBI warns business travellers of hotel Wi-Fi malware scam

by Alastair Stevenson

09 May 2012

View Comments

  • Tweet this
Will you have to rekey account details

The Federal Bureau of Investigation (FBI) has discovered a new malware threat masquerading as an official software update that attempts to install itself through hotel internet Wi-Fi connections.

The department's Internet Crime Complaints Centre (IC3) reported discovering the malware on Tuesday and warned it is particularly dangerous for business travellers as it could help steal corporate data.

"Recent analysis from the FBI and other government agencies demonstrates that malicious actors are targeting travellers abroad through pop-up windows while establishing an internet connection in their hotel rooms," read IC3's statement.

"The FBI recommends that all government, private industry, and academic personnel who travel abroad take extra caution before updating software products on their hotel internet connection."

The centre gave no further details about the malware's capabilities or which hotel chains' networks it has discovered the malware running on.

At the time of publishing neither the FBI nor IC3 have responded to V3's request for clarification.

Trend Micro security researcher Rik Ferguson said the attack method being used by the criminals was not new, but could certainly be successful.

"It is not unusual to find that your computer may be running an out-of-date version of one application or another that is necessary to view a particular web page at a given time. For this reason it provides perfect cover for distribution of malware," he told V3.

"Combining this tried and tested technique with the hotel wireless login scenario increases the credibility of the attack and makes it more likely to be successful. Users are on an unfamiliar network, with often unfamiliar access and login methods and the unexpected is often mistaken for normal behaviour."

The discovery follows on from recent research by Imperva suggesting hackers are evolving new ways to target companies' corporate data.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

54%

11%

9%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Senior Web Designer -Adobe Photoshop / HTML / CSS / InDesign

Senior Web Designer -Adobe Photoshop / HTML / CSS / InDesign...

C# Winforms / Desktop Developer - C# / WPF / SQL Server

C# Winforms / Desktop Developer - C# / WPF / SQL Server...

Microstrategy Consultant

Sopra Group are looking for Microstrategy Consultants...

Technical Architect - £55K - C# / ASP.NET / WCF / WPF - Bedford

Technical Architect - £55K - C# / ASP.NET / WCF / Agile...

To send to more than one email address, simply separate each address with a comma.