Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

'Italian Job' Trojan infecting thousands of servers, end-user PCs

  • Email a Friend
  • Print Page
'Italian Job' Trojan infecting thousands of servers, end-user PCs
By Jim Carr
Jun 19, 2007 9:33 AM
Tags: 'Italian | Job' | Trojan | infecting | thousands | of | servers, | end-user | PCs
Called the "Italian Job" by Trend Micro researchers because a great majority of the infected pages are hosted in Italy, the Trojan downloads a keylogger designed to steal banking and other confidential information through a wide range of web-infection downloads.

David Perry, global director of education for Trend Micro, said the infection vector "was built from a kit sold commercially in Russia."

The original attack came "from Hong Kong, [but the hackers] set up a server in San Francisco that relays to one in Chicago," said Perry. "The infected websites are taken over to the point where they're owned by whomever the hackers are."

According to Trend Micro, tens of thousands of unaware users have already accessed compromised web pages, infecting their systems with the Trojan. The downloaded malware takes advantage of a vulnerability in so-called " iFrames " that are commonly used and exploited on websites.

Perry said the Trojan is "an automated tool that looks for not just one but any number of vulnerabilities" on systems visiting the infected pages.

The impacted web pages "have also been infected using vastly different methods, and not having our hands on the tool or automated process, we don't know what it's limited to," he added.

The fact that the perpetrators are stealing personal information points out that they "definitely have criminal intent" in mind, added Perry.

Trend Micro said it is working with the FBI to catch the perpetrators.

Both Trend Micro and Websense said users of their respective anti-virus products are protected against the exploit. Trend Micro said its HouseCall offers a free online scan that can detect the Trojan and repair infected systems.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers