Spoofed Microsoft site promises Internet Explorer 7, but spreads trojan

By

Microsoft Internet Explorer users are being warned that one site claiming to host a new version of the web browser is not what it looks like.


Hackers have set up a malicious website that installs a trojan via a browser exploit, according to a news release from SurfControl.
The trojan "effectively creates a backdoor on the infected system," according to the Scotts Valley, Calif. anti-virus vendor.
To be victimised by the trojan, users must click on a link provided in the spoofed email, which appears to come from a Microsoft support address and offers users the chance to download Internet Explorer 7 (IE 7) Release Candidate 1.
Microsoft just this week released IE 7, promising strengthened defenses against phishing websites and other malicious attacks.
Susan Larson, vice president for global threat analysis and research at SurfControl, told SCMagazine.com today that the scam has a good chance of success because of its timeliness and the craftsmanship of the malicious site.
"It takes advantage of the current event of Microsoft IE 7 being released. It took advantage of that topical event, and it took advantage of Microsoft saying (users) needed an upgrade," she said. "The other thing is that it is a fairly well spoofed site, and it looks good, very Microsofty. It's a drive-by. Basically you click on the link and you're immediately starting to download the exploit."
Click here to email Frank Washkuch Jr 
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Palo Alto Networks in talks to buy CyberArk

Palo Alto Networks in talks to buy CyberArk

Gov to encourage vuln research, puts insurers and NFPs on notice

Gov to encourage vuln research, puts insurers and NFPs on notice

"Scattered Spider" evolves with new ransomware and social engineering tactics

"Scattered Spider" evolves with new ransomware and social engineering tactics

Allianz Life says majority of US customers' data stolen in hack

Allianz Life says majority of US customers' data stolen in hack

Log In

  |  Forgot your password?