Cyber-criminals clone Google Italy site

By

'Evil twin' site attempts to infect visitors with trojans.

Cyber-criminals clone Google Italy site
'Evil twin' site attempts to infect visitors with trojans.

Cyber-criminals have created an "evil twin" website which aims to dupe unsuspecting visitors into believing that they are visiting the Google Italy site. 

IT security firm SurfControl said today that it is currently tracking the malicious website, which attempts to install ActiveX controls on a visitor's PC.

The site uses 'typo-squatting' to ensnare victims, a technique that mimics a legitimate domain using a slightly different spelling. It has been configured to deliver a fraudulent Google Italy page that looks identical to the original.

ActiveX is installed automatically if Internet Explorer security settings allow installation of ActiveX controls. Otherwise, the end user will have to accept the installation for the infection to occur.

If the ActiveX control is accepted, a trojan redirects the homepage to a website featuring adult content.

In addition to browser hijacking, the website installs a key-logging Trojan that monitors keystrokes and sends information to a remote location.

SurfControl has also witnessed incidents of infected machines attempting to send spam email that could have malicious intent.
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

First npm worm "Shai-Hulud" released in supply chain attack

First npm worm "Shai-Hulud" released in supply chain attack

"VoidProxy" PhishKit targets Google and Microsoft users

"VoidProxy" PhishKit targets Google and Microsoft users

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Log In

  |  Forgot your password?