My Photo

Adsense


Add to Google Reader or Homepage

Subscribe in Bloglines

Subscribe in one go

  • Subscribe to RSS Feed

Your email address:


Powered by FeedBlitz

Google reader

Software worth checking out

  • ActiveWords
    Do everything without leaving the keyboard
  • Anagram
    Translates copied text into Contact, Calendar, Task, and Note items for Outlook, Palm etc
  • BlogJet
    Weblog client for Windows that allows you to manage your blog without opening a browser.
  • ConnectedText
    Intriguing Wiki-based organiser
  • Copernic Desktop Search
    Great alternative to Google's or Microsoft's offering for searching your PC. Simple and unobtrusive
  • Courier Email
    Great email program
  • DtSearch
    Text Retrieval / Full Text Search Engine
  • ExplorerPlus
    Organize and manage all your system files and folders
  • Gmail
    Webmail that really works. Great for catching spam too.
  • Google Deskbar
    Search with Google from any application without lifting your fingers from the keyboard.
  • Google Earth
    Zip around the planet and see things differently
  • Google Reader
    Best online RSS reader I think there is out there
  • Google Talk
    Chat online and make free internet calls
  • Jot+
    store all of your notes and information in an easy-to-use outline
  • Mindjet
    The mindmapper of choice.
  • MSGTAG - MessageTag
    Email receipt alert
  • MyInfo
    free-form information organizer
  • NoteTab
    Great text and HTML editor
  • PersonalBrain
    If you've ever wanted to organise your information in a way that's different, try this. Worth spending time on mastering
  • Process Explorer
    Not too geeky way to figure out what software is slowing down your computer. Just keep it running for a while and the culprit will become obvious.
  • Safari
    Surprisingly fast browser -- and for Windows too.
  • Skype
    Dump those phone bills
  • SpaceMonger
    Keep track of the free space on your computer via treemaps
  • Stick
    Post-It note-like tabs to store text, folders etc that cling to the edge of your screen
  • SuperNotecard
    Great for authors and writers organizing their thoughts
  • TaskTracker
    Lists recent documents by type for easy access
  • Text Monkey
    Easily clean copied text
  • Trillian IM Clients
    Gathers all your instant messaging accounts in one window
  • UltraMon
    Increase productivity and unlock the full potential of multiple monitors.
  • Vyooh DiskView
    Visually see disk space usage in Windows Explorer
Blog Widget by LinkWithin

« Phishing, And Some Advice | Main | More On Korgo »

May 31, 2004

A Phishing Worm

Welcome to the phishing worm.

Korgo, a new worm that appeared last week, scans for random machines to infect and attack, using a vulnerability in Windows called the LSASS flaw which was discovered in April, according to Internet Week. Korgo, also known as Padobot, then sits on users' computers waiting for instructions from home. Most such bots would open up the victim's computer for relaying spam, launching Denial of Service attacks, or for infecting other machines.

Korgo seems to go one step further. According to F-Secure, Korgo "seems to be stealing user information very aggressively through keylogging techniques." Mikko writes on his blog (sorry, no permanent link available): "The Korgo network worm keeps spreading actively, and it's aggressively stealing user information from infected machines. It does this via a keylogger which specifically collects user logins for online banks (the ones which do not use one-time passwords). It also logs everything the user types to any web form - this will collect lots of credit card numbers, passwords etc."

This would, if true, mean that users don't need to receive an email, visit an infected site, or unwittingly download anything for their passwords to be stolen. That would seem to take phishing to the next level in that it doesn't involve email, either as a form of transmission or as a lure. Roger Thompson of PestPatrol agrees it's probably the first: "There have been bots that phish, but I don't think any have specifically targeted banks".

For some reason McAfee and the others are rating Korgo as a low threat, and make no mention of its keylogging abilities that I can find. I've asked F-Secure for more information, including which banks are targetted. I'm also not sure whether there have been previous worms that capture banking passwords. What does seem clear is that the worm is Russian in origin. F-Secure says it believes the HangUP Team, a team of Russian hackers, is the worm's 'probable creator'.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341c5af153ef00d83504c46f53ef

Listed below are links to weblogs that reference A Phishing Worm:

Comments

The comments to this entry are closed.

Loose Wire search

Eco-Safe

Rank

  • Wikio - Top Blogs - Technology
Blog powered by TypePad
Member since 12/2003

Facebook

ten mov.es

tenminut.es