IE7 used as phishing lure


Spam campaign tries to hook users with new browser version.

A spam campaign has been spotted using the latest version of

Microsoft

‘s web browser,

Internet Explorer 7

, as bait.

The spammed mails contain spoofed sender information trying to fool recipients into believing they originate from

Microsoft

tech support, and offer free downloads of the latest beta version of the browser.

However, when links in the mails are followed to a convincing spoof of a

Microsfot

download site, a version of the Win32/Small trojan is installed to vulnerable machines using drive-by download exploits. The trojan then proceeds to open backdoors, giving remote attackers access to the infected machine.

An advisory from

Surfcontrol

can be found

here

.

Posted on 19 October 2006 by

Virus Bulletin


Posted

in

by

Tags:

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *