Warning over 'blog-posting' Trojan

Storm Worm rides again...

By Dawn Kawamoto, 28 February 2007 08:55

NEWS

A variant of the Trojan horse attacks known as Storm Worm has emerged, targeting people who post blogs and notices to bulletin boards.

Storm Worm emerged in January and raged across the globe in the form of emails with attachments that, when opened, loaded malicious software onto victims' PCs, commandeering the machines so they could be used for further attacks.

The new Storm Worm variant attacks the machines of unsuspecting users when they open an email attachment, click on a malicious email link or visit a malicious site, said Dmitri Alperovitch, principal research scientist at Secure Computing.

But the twist comes when these people later post blogs or bulletin board notices. The software will insert into each of their postings a link to a malicious website, said Alperovitch, who rates the threat as "high".

He said: "We haven't seen the web channel used before. In the past, we've seen malicious links distributed to people in a user's address book and made to look like it's an instant message coming from them."

The danger in this most recent case, he added, is that the user is actually posting a legitimate blog or bulletin board notice, unaware that a malicious link has been slipped into the text of the posting.

Dawn Kawamoto writes for CNET News.com

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ