Attackers have begun spamming e-mail lures in an attempt to attract users to infected websites. These e-mail messages contain excerpts from actual BBC news stories and offer a link to 'Read More'. Users who follow this link are taken to a website that is a spoofed copy of the BBC news story from the e-mail. This website exploits the unpatched createTextRange vulnerability and is currently being used to download and install a keylogger. This keylogger monitors activity on various financial websites and uploads captured information back to the attacker.
Friday, March 31, 2006
BBC Virus?
Websense� - Security Labs Alert: IE Zero-Day Lures Discovered:
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment