Surge in password-protected malware
By Guy Matthews,
There has been a surge in viruses sent in the form of an apparently trustworthy password-protected zip file attachment, security experts are warning.
Messaging security specialist Email Systems says more virus writers than ever before are delivering their malicious code as either an encrypted or password-protected email, causing even the security-savvy to fall victim unwittingly.
The first viruses hidden in supposedly safe zip attachments were identified six months ago, said Greg Miller, marketing director at Email Systems. He said the situation has worsened considerably in recent weeks with a significant increase in the number of such mails being propagated.
"This is another step change in the tactics of the virus industry," said Millar. "We've seen a drop off in viruses delivered by email in the last year or so. Now there's obviously been another fluctuation in what virus writers are up to. They are getting even cleverer, and hiding the viruses a little bit deeper."
The latest crop of virus-laden attachments are all the more convincing for appearing to have come through the IT manager's system of protection, said Miller. "People think if it has got through, it's safe to open," he said.
"This is a clever bit of code that exploits the trusting."
The new batch of virus laden emails typically contain the Trojan.Peacomm virus, also known as the Storm Trojan, which is around 77Kb in size and usually contained within either an encrypted email or a password-protected zip attachment to an email.
The emails sometimes contain a security warning, supposedly offering to protect the user from a threat. The phrase ATTN! is frequently prominent within the subject line of such emails, which also sometimes proclaim 'Worm Detected!', 'Virus Detected!', 'Spyware Alert!' or 'Warning!'
On receipt of such an email, users are prompted with a password and thereby are unwittingly able to release the virus on their machine. On release, the Storm Trojan virus is designed to retrieve additional malicious code from the internet.
"The huge rise in spam levels we saw before Christmas was about swamping people with sheer volume, hoping to catch them out that way," said Millar. "This is another change in an ever shifting range of methods."
During the last few weeks, he says, Email Systems has quarantined hundreds of thousands of such emails - a major increase from the tens of thousands witnessed last year.
You may also like...
advertisement
Latest Security Features
Q&A: The ID card commissioner talks cards and controversy
We spoke to ID card commissioner Sir John Pilling about his thoughts on the identity scheme and why we might all think he's a bit of prat down the line.
- So you've been hacked, now what?
- The problems facing Internet Explorer
- Year in Review: 2009 in your words
- Top 10 security predictions for 2010
- Year in Review: Top tech stories of 2009
- The worst IT disasters of 2009
- Five free security software suites
- How to stay safe shopping online
- Is it time to switch to IPv6?
Latest Security Reviews
Symantec Backup Exec 2010 review
Rating: ![]()
advertisement
Most popular
- App market will be worth $17.5 billion by 2012
- Report: Macs cost less to run than Windows PCs
- Why is Microsoft accelerating Service Pack 1?
- Q&A: Conrad Wolfram on communicating with apps in Web 3.0
- Open source developers ditch iPhone for Android
- Symantec Backup Exec 2010 review
- Head to Head: Office 2010 vs Open Office 3.1
- O2 condemns 'bullying' law firms for threatening file-sharers
- Google Nexus One review: A week with the superphone
- HTC Legend review
Latest News Videos in Security
Video: Why security is everybody's responsibility
Rik Ferguson, senior security advisor at Trend Micro says it's up to all of us to make security work.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





