Extreme Phishing Abusing Google MapsBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Adware - Spyware : Extreme Phishing Abusing Google Maps
Posted by Max on 2007/2/21 14:53:28 (961 reads)
Adware - Spyware

Bank customers of at least two Australian banks have become victims of a phishing scam in which malicious payload discloses the physical location of attacked IP addresses using Google Maps. Bank of America and Germany's Deutsche Bank were also attacked.
Wow ..Would you think of that ? Read on.

The malware installs a Trojan capable of key-logging user activity, hijacking infected computers.

The phishing lure was sent as a false news report claiming the Australian prime minister had suffered a heart attack. It installs a trojan and backdoor code to log  all user input as well as compromising a Web server to allow the hacker to hijack the victim’s computer.


The hacker is then provided with details on the number of infected machines in each country, while the Google Maps server is used to translate IP information to pinpoint the machine’s physical location.

Websense Australia and New Zealand country manager, Joel Camissar, believes hackers could potentially use Google Maps as a tool in identity theft.

"The hackers could correlate user information acquired from the key-logger with knowledge of where a user is located from Google Maps to masquerade as them," Camissar says. "With this they could access bank accounts and social security numbers."

Camissar said there are around 750 infected desktops in Australia.

Westpac and the Commonwealth Bank were among those specifically targeted in Australia, while Bank of America and Germany's Deutsche Bank were also attacked. Westpac and the Commonwealth Bank were unavailable to comment at the time of publication.

Sophos senior technology consultant, Graham Cluley, says that users are directed to a 404 error page which downloads the code.

"Recipients of the e-mail are encouraged to click on a link to obtain the latest information on Howard's health; however, this link takes users to a Web page which downloads malicious code to their PC, and then displays the real '404 page not found' error page," Cluely says.

"The scammers have registered several domain names that appear to be associated with a newspaper, and have gone to great effort to make people think that they really are visiting the genuine site by pointing to a real error page. Everyone should be on their guard against this kind of e-mail con-trick, or risk having their PC infected," he adds.

Camissar was unsure whether Websense acquired the information through sample code provided by AusCERT or by accessing the hacker's servers.

ictworld




Other articles
2008/8/20 15:06:33 - FRAUDFacts Helps You Fight Identity Theft and Fraud for Life
2008/8/13 16:42:03 - 10 Million Zombies Are Spreading Spam and Malware Every Day
2008/8/11 9:03:35 - Nearly $8.5 Billion Lost by US Consumers because of Online Threats
2008/8/8 6:35:36 - EDS' Eight Tips for Consumers to Protect Themselves from Identity Theft
2008/8/4 11:16:32 - NovaShield, Inc. Launches NovaShield AntiMalware Version 2.0 With 90-Day Free Trial

The comments are owned by the poster. We aren't responsible for their content.