Cyber-criminals launch PDF malware offensive

PDFex storms into the charts

Robert Jaques

PDF malware "smashed" into October's virus charts, a security firm reported today.

Sophos said that the new PDFex Trojan has been widely spammed out in emails with an infected Adobe Acrobat PDF attachment, and has reached third position in the malware chart.

Advertisement

The Trojan was launched during the last few days of October, taking advantage of an unpatched Windows vulnerability to infect PCs.

"PDFex only started to circulate at the very end of the month, but still managed to account for over 13 per cent of all emailed malware during October," said Carole Theriault, senior security consultant at Sophos.

"It was heavily spammed out between 26 and 28 October, and accounted for a staggering two thirds of all malware spread via email."

PDFs have long been used in business as a means of sharing information, so the social engineering trick of using a PDF puts insufficiently protected businesses at risk, according to Sophos.

"Adobe has issued an update to its Acrobat software that fixes the problem, and eyes are now turned to Microsoft to patch the underlying flaw in Windows which could affect other vulnerable applications such as Skype and Firefox," warned Theriault.

She added that, although criminals are currently using PDF files to try and infect innocent PCs with malware, there is little evidence of spammers continuing to use PDF files.

The research also indicates a slight decrease in the percentage of infected email. Overall in October, one in every 1,000 emails carried malicious email attachments, compared to one in every 833 during September.

However, web attacks continue to pose a "significant threat", Sophos warned. Mal/Iframe was responsible for almost seven out of every 10 infections found on the web by the security firm.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation