IT Reseller Magazine
Article Search: Go To: Keyword 
 
   

FREE Subscription to IT Reseller Magazine






Internet Security
Internet control, email and network protection


Hackers exploit crisis in Burma to spread Trojan horse
01 October 2007  Sophos

Email links to Dalai Lama's genuine website, but attachment is malicious
 
Taking advantage of international concern regarding the daily demonstrations in Burma, IT security and control firm Sophos has cautioned computer users to be wary of a malicious email which claims to be a message of support for monks and other protesters in Burma from the Dalai Lama. In reality, however, it carries a malicious attack designed to infect the recipient's PC.

The email reads as follows:

Dear Friends & Colleagues, Please find enclosed a massage from His Holiness the Dalai Lama in support of the recent pro-democracy demonstrations taking place in Burma. This is for your information and can be distributed as you see fit.

Best wishes.

Tenzin Taklha
Joint Secretary

Office of His Holiness the Dalai Lama

When users open the attached document (filename: hhdl burma_001.doc), it attempts to exploit a Word vulnerability which in turn tries to drop a Trojan horse onto the victim's PC. Sophos proactively detects the malicious document as Exp/1Table-B and the Trojan it tries to install as Agent-CGU.

Sophos experts note that to add even more credibility to the message and to encourage a greater number of victims to open the attachment, a link to official website of the Dalai Lama was included.



The email links to the genuine Dalai Lama website in an attempt to look more credible.

"The Burmese regime is said to have tried to stop news from coming out of the country by shutting down internet cafes and controlling computer users' access to the net. People around the world are hungry to hear about the latest situation in the country and support the pro-democracy movement, and may be tempted to read this so-called letter from the Dalai Lama," said Graham Cluley, senior technology consultant at Sophos. "Using topical news stories to trick unwary computer users into opening and downloading malicious code is one of the oldest tricks in the book, but it's obviously still working or the hackers wouldn't waste their time on it. We should all use our common sense and question the legitimacy of emails sent out of the blue."

Sophos recommends companies protect themselves with a consolidated solution which can control network access and defend against the threats of spam, hackers, spyware and viruses.


The latest in a long line of political malware

Sophos experts note that this is not the first time that viruses and Trojan horses have been connected with political events:

W32/Deadcode-A
Displayed a nationalistic message associated with a Serbian politican.


W32/Mirsa-A
Spread a message in support of the "Fathers 4 Justice" campaign.


W32/Maslan-C
Disguised as pictures of a nude glamour model, this virus launched a series of denial-of-service attacks on websites run by Chechen rebel separatists.


W32/Zafi-C
Attacked the website of the newly appointed Hungarian Prime Minister.

W32/Zafi-B
Calls for the introduction of the death penalty in Hungary.

W32/Cycle-A
Complained about the quality of life in Iran.


W32/Zafi-A
Displays a message calling for Hungarian patriotism, timed to coincide with the country joining the European Union.

W32/Quaters-A
Launches a scathing attack on British Prime Minister Tony Blair and attempts to knock the Downing Street website off the internet.

W32/Colevo-A
Redirects the web browsers of infected computers to a variety of pictures of Evo Morales, leader of the Bolivian coca leaf growers' union and runner-up in 2002's presidential elections.

W32/Vote-A
Calls for a vote on whether America should go to war against the followers of Islam.

W32/Yaha-Q
Apparently written in response to attacks on Indian websites, this worm not only attempts to launch a denial of service attack against five Pakistani websites, but also contains a number of inflammatory messages directed at Pakistani hackers.

W32/Yaha-E
Launches a denial-of-service attack against a Pakistani government website.

Mawanella worm (also known as VBS/VBSWG-Z)
Displays a message describing the burning down of two mosques and one hundred Muslim-owned shops in Mawanella, Sri Lanka.

Injustice worm (also known as VBS/Staple-A)
Opens a number of pro-Palestinian websites and describes the alleged murder of a 12-year-old Palestinian child at the hands of Israeli soldiers. In addition, the worm spams itself to members of the Israeli government.

W32/Caric-A
Poses as a cartoon screensaver of former US President Bill Clinton playing the saxophone. An item of female underwear emerges from the bottom of the instrument.

 


Other Internet Security News Security White Papers
Verizon Business and Motorola join forces to help safeguard retailers’ wireless networks from hackers
Retailers are increasingly using in-store local area wireless networks for a variety of key functions, including staying in close touch with sales personnel who are serving customers. But all too often, these networks are vulnerable to a variety of security threats such as attacks by hackers and the use of unauthorised devices.
BullGuard to hold 2010 Full Disclosure Briefing for resellers
BullGuard Internet Security 9.0 unveiled to the channel
A third of workers will steal data to help a friend find a job, says study
The recession is creating camaraderie among workforces, at the expense of their employers, is the finding of a transatlantic survey.
Industrialisation of Hacking Will Dominate The Next Decade
Imperva delineates five key security trends UK Organisations will face during the next ten years
Managed Service Providers believe most RMM systems end up being 'shelfware'
GFI Software has announced the findings from industry research on Remote Monitoring & Management (RMM) software for Managed Service Providers (MSPs), Value Added Resellers (VARs) and IT support organizations.
Mobile laptop usage soaring - but what about company data security?
The apparently amusing tale of how New York coffee shops - apparently fed up with laptop users hogging their table space and using up electricity for hours on end - has a much darker message, says Sean Glynn, Director at Credant Technologies.

More >>

Understanding the value of outsourcing network security services
This white paper will examine the many new challenges that are facing today’s network owners, the pros and cons of using in-house resources and outsourcing for your network assessment and day-to-day monitoring, as well as guidelines to help select and maximize the value of outside resources.
GFI warns one anti-virus engine is not enough to protect your business
Although 99% of large British companies use anti-virus products, 43% were still infected by viruses (UK ISBS Survey 2006)
CONTENT FILTERING SOLUTIONS TECHNOLOGY REPORT APRIL 2006
Source: West Coast Labs/Netintelligence
The Trend of Threats Today: 2005 Annual Roundup and 2006 Forecast
Trend Micro
The report that follows is not only an account and analysis of 2005 threat
incidents. It also serves as a forecast of what the future holds in 2006 and
onwards. Through Trend Micro‘s extensive research and analysis of the 2005
incidents, this paper documents how threats evolved into the multi-purpose
threat regime – thus providing corporate and home users information on what
to do to ensure they remain protected against future threats. Download free white paper.
If you can't beat it, manage it
David Caughtry of Computerlinks looks at the challenges facing IT managers with the growing use of Instant Messaging in the workplace.
Are you becoming a one-stop security shop?
David Ellis, director of e-security at Unipalm discusses best practice security management and the evolution of protection technology.

More >>

advertisements


 



Related Articles


Let the news come to you!
Subscribe to our weekly newsletter and the digital edition of IT Reseller Magazine!

Email Address:   



© Copyright 2006, IBC - Interactive Business Communications

Help | Contact Us | PrivacyRSS Feeds | Site Map | Advertise
YourTechTV.com Only Technology Videos