Advertisement
Promo

Security threats Toolkit

Hotlan Trojan defeats captcha

Matt Loney ZDNet.co.uk

Published: 06 Jul 2007 12:14 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new Trojan horse that sends spam through Hotmail and Yahoo email accounts has antivirus companies worried that the commonly used "captcha" system, used to prove new members are real people, may have been compromised.

Captcha systems typically use a selection of alphanumeric characters that have been distorted and presented in a graphic with other elements designed to confuse character-recognition software. The idea is that, as only a person can read it and type in the correct sequence, spam bots and other malware can be stopped from automatically setting up accounts.

The new threat was highlighted on Thursday by BitDefender Labs, which has dubbed it Trojan.Spammer.HotLan.A.

"The Trojan uses automatically generated accounts, suggesting that spammers have found a way to bypass the captcha systems," the company said in a statement.

Every active copy of the Trojan accesses an account, then pulls encrypted spam emails from a website, decrypts them and sends them to (presumably valid) addresses taken from yet another website, BitDefender continued.

Viorel Canja, head of BitDefender's antivirus labs, said there are "only" about 500 or so new accounts being created in this attack every hour, and 15,000-plus Hotmail accounts had already been used.

Yahoo could not be immediately contacted for comment.

The spam email currently being distributed is trying to lead users to a site that advertises pharmacy products. Common spammer techniques are used in the email body, added BitDefender.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
45 out of 49 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters