« Fast Food Restaurants Serving Up Identity Theft | Main | Senator Feinstein Introduces More ID Theft Legislation »

Another Undetectable Account Hijacking Trojan

As if we needed a reminder that it’s not safe to drop our guard against computer viruses, check out this story. PC World Recently highlighted research by security firm Secure Works that had identified a Trojan horse that was largely missed by 30 of the leading anti-virus scanners.

Which probably explains why it was able to infect more than 5,000 personal computers and steal personal information on 10,000 account holders worth an estimated $2 million on the black market.

And who detected the stealth attack? Not a security sleuth, a global crime lab or even a piece of anti virus software, but a user who discovered that a number of web sites he regularly accessed had been hijacked. Investigators discovered that his computer had been infected with a previously unknown Trojan horse now nicknamed Gozi, and had probably infected his computer in the same way it infected thousands of others – because users had failed to update their Internet Explorer browser with fixes for known exploits.

Two lessons can be learned – many attacks are still simple exploits of careless users who still don’t take their personally security seriously enough to do even an occasional browser update that takes just a few minutes; and just as we think anti-virus vendors have got us covered, the bad guys trump them (and us all) with an undetectable attack that can create a huge payoff.

Posted on Tuesday, March 27, 2007 at 03:56PM by Registered CommenterNeal O'Farrell in | CommentsPost a Comment

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>