Warnings On New Phishing Threat - InformationWeek
IoT
IoT
News
News
11/3/2004
05:47 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Warnings On New Phishing Threat

New, "more insidious" phishing scam is triggered when unsuspecting users open an E-mail.

Opening the wrong E-mail may soon be enough to empty your bank account. In an effort to woo security-conscious computer users, "phishers" have come up with a new technique to harvest online banking details without requiring users to click on a Web link and enter personal information on a submission form.

This new form of attack, directed specifically at users of online banking, runs a script when a phishing E-mail message is opened, according to E-mail and virus security company MessageLabs Ltd. The script tries to rewrite the host files on the machine of the recipient. On subsequent attempts to access online banking services, victims will unknowingly be redirected to a fraudulent Web site designed to capture their log-in details.

Alex Shipp, senior antivirus technologist at MessageLabs, says such developments only make it harder to defend against phishing. Traditional phishing attacks rely on tricking the user into following a Web link and then entering personal information. "This one is much more insidious," he says.

Some 3% of those targeted by phishers reveal personal information, according to a study released in April by research firm Gartner.

Shipp adds that this new technique, which has only been detected in Brazil, is probably being tested for wider deployment. That's what happened with first-generation phishing attacks that were tested in Australia before being directed at users in the United States.

Only systems that have enabled Windows Script Host are vulnerable to this attack. WSH lets users run VBScript and JScript scripts within the Windows operating system. Sophos plc, an antivirus company, offers instructions on how to disable WSH.

"Most businesses these days probably have this disabled," Shipp says. "But home users are more vulnerable."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
2017 State of the Cloud Report
As the use of public cloud becomes a given, IT leaders must navigate the transition and advocate for management tools or architectures that allow them to realize the benefits they seek. Download this report to explore the issues and how to best leverage the cloud moving forward.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on InformationWeek.com for the week of November 6, 2016. We'll be talking with the InformationWeek.com editors and correspondents who brought you the top stories of the week to get the "story behind the story."
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll