ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Phone phishing attack hits US

Tom Espiner ZDNet.co.uk

Published: 23 Jun 2006 17:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Criminals have launched a blended attack which attempts to lure users to a malicious Web site via text message.

IT managers have been warned to alert their staff to the attack, which uses social engineering techniques to try to trick users to the phishing site, according to security vendor Websense.

Users are sent an SMS text message to their mobile phone, thanking them for subscribing to a fictitious dating service. The message states that they will be automatically charged a subscription fee of $2.00 per day, which will be added to their phone bill, until their subscription is cancelled at the online site.

The same message has also been spammed to the comments section of numerous bulletin boards.

Once victims visit the site to unsubscribe, they are prompted to download a Trojan horse program which is a variant of a program Websense calls "Dumador". Once installed, the program turns the computer into a zombie, allowing it to be remotely controlled by the hackers.

Once machines have been compromised, they become part of a bot network, which can then be used to launch distributed denial of service attacks, install keylogging software and store account information.

"This is definitely the first time we've seen this specific approach," said Ross Paul, a senior product development manager at Websense. "Basically they're taking a social engineering attack vector with a lot of users," Paul added.

The attack began on Thursday in the US, and according to Websense was first detected by Sunbelt Software, a security software vendor. The attack has so far been focused solely on the US, but may spread to the UK.

Websense said it had been monitoring the attacks, but couldn't divulge the identity of those responsible, or say whether it was collaborating with the authorities in this specific case.

"In general, these kinds of attack are perpetrated by organised rings of people. In some cases we know their nicknames, which we share with law enforcement. We regularly share information with the police when that makes sense," Paul said.

Websense could not say exactly how many users had been affected by the attack. Monitoring botnet activity is "very difficult to do", due to the cross-border nature of the networks, according to Paul.

The Dumador Trojan allows hackers to use HTTP to control the bots and trigger them to upload information. The most popular method of bot control is through Internet Relay Chat (IRC).

IT managers were advised to educate staff on the growing sophistication of social engineering attacks.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
448 out of 548 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Pre-sales Consultant-NAS Storage, De-duplication,VTLs, NFS, CiFS iSCSI

Pre-sales Consultant-NAS Storage, De-duplication,VTLs, NFS, CiFS FCP iSCSI, HBA Server Conneectivity, Veritas Netbackup, Disaster Recovery, Windows, ...

Application Management Support Technician Java/J2EE Support, Unix

Tridion, Interwoven) EDUCATION AND CERTIFICATION REQUIREMENTS -Sun Java Certification and/or other vendor certifications BENEFITS: Holiday ...

Application Developer Middleware

Candidates may be re-engineering complex application components and integrating software packages; alternatively, they may be helping clients to ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment