Advertisement
Promo

Security threats Toolkit

Latest Bagle causes concern

Dan Ilet ZDNet.co.uk

Published: 01 Mar 2005 13:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus companies have found a new type of Trojan horse that is being massmailed around the world by spammers.

The malware, dubbed BagleDl-L, is said to damage security applications and attempts to connect with a number of Web sites. According to F-Secure and Sophos, these Web sites currently contain no malicious code, but both companies believe this could soon change.

"Any Trojan horse which turns off your antivirus or firewall can open you up to further attack, even by very old viruses," said Graham Cluley, senior technology consultant for Sophos. "This Trojan horse is aiming to take advantage of people's reflex reaction when they receive an executable file via email. Users who want to install software on their computer should be receiving it from their IT department, not from friends at other companies or potentially dangerous spam mailings."

For the Trojans to work, a certain amount of social engineering is required as the emails contain a ZIP-file attachment which must be opened to display the programs "doc_01.exe" or "prs_03.exe", which must also be run manually to infect a computer.

Unlike mass-mailing worms the Trojan does not self-propagate, but the security companies have highlighted it because a high number of emails containing it have been detected.

The detection of BagleDl-L comes just days after Send-Safe.com, which offered spamming tools, was kicked off Internet service provider MCI's network. Send-Safe is said to use PCs that have been compromised by Trojan horses to propagate spam.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
95 out of 216 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters