Trojan horse
Small.bdq Trojan sent to highly targeted group of UK businesses

Big danger from Small Trojan

Virus targets specific companies with malicious executable

Robert Jaques

Over 120,000 emails containing a downloader Trojan named Small.bdq have been sent to a highly targeted group of UK businesses since 9.10pm on 15 July, security experts warned today.

According to email security company BlackSpider Technologies, the Trojan is distinguished by its targeting specific companies across Europe during 10-minute periods, probably using spammers' directory lists.

Advertisement

The targeted businesses vary in size and industry sector, and the attack is continuing into Monday morning. BlackSpider reported on a similar attack on 8 July.

The window of exposure before the first of BlackSpider's antivirus vendors issued a patch was 12 hours and 30 minutes, during which time an estimated 58,000 copies of the Trojan were sent out.

Subject lines vary and include: 'Security', 'Support', 'Update', 'Mail', 'Networking' and 'Security Update'.

The email claims to be from an individual's IT team warning that their system has been compromised and is distributing spam. The content is as follows:

"Security alert
Dear cygan@alfa.com user
Your e-mail account was used to send a huge amount of unsolicited spam messages during the recent week. If you could please take 5-10 minutes out of your online experience and confirm the attached document so you will not run into any future problems with the online service.
If you choose to ignore our request, you leave us no choice but to cancel your membership.
Virtually yours, Network Administrator Team."

The attachment is a 2.8KB packed executable MEW file with the filename 'zam.exe'. The attachment is too small to replicate or cause any damage itself, but the executable downloads harmful content from a URL.

John Cheney, chief executive at BlackSpider, said: "We have been warning businesses that malware writers' motivations are evolving from simply wanting the kudos of creating a mass mailer to financial gain. This latest Small Trojan demonstrates this shift.

"As well as bulk distribution, we noticed specific customers of varying sizes and industries being targeted during 10-minute windows.

"The effects of the Trojan have not yet been revealed but businesses should be aware that its purpose may well be to uncover sensitive corporate information, perhaps via a key-logging tool."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Trojan horse

'Spam report' Trojan spreading fast

Email purports to be from the IT department

Trojan horse

Trojan masquerades as Microsoft patch

Beware updates bearing URLs

Sick Trojan exploits London bombings

Promised eyewitness videos carry nasty payload

Trojan attacks double in June

Dramatic surge in malware as virus writers focus on fortune over fame

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation