The Register® — Biting the hand that feeds IT

Feeds

Malware authors unleash bird flu-themed Trojan

Sick twist to social engineering

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Today brings further proof that no human disaster these days arises without been exploited by internet ne'er-do-wells. Hot on the heels of a spam campaign punting Tamiflu, the drug believed most effective at protecting humans from the potentially-lethal H5N1 strain of the bird flu virus, comes a piece of malware designed to tap into topical concerns about the disease.

The Naiva-A Trojan masquerades as a Word document containing information about the bird flu epidemic in order to dupe unwitting Windows users into opening the maliciously constructed file. Once executed, the malware uses two Word macros to run and install a second item of malicious code, Ranky-FY, onto infected PCs. Ranky-FY gives hackers the ability to control compromised PCs.

Infectious code normally arrives in user's email in-boxes at an attachment in spam email messages with subject lines such as "Outbreak in North America" or "What is avian influenza (bird flu)?" both of which refer to a disease experts fear could become a pandemic, and spread further around the world following deaths in Asia.

The malware is not spreading widely and therefore poses only a modest threat. Anti-virus firms say the Trojan attack mounted by the Naiva-A Trojan illustrates the dangers of opening attachments in unsolicited emails. "Unfortunately, we were expecting something like this. This is not the first time, and won’t be the last, that writers of malicious code have taken advantage of people’s misfortune and anxieties to spread their Trojans or worms," said Luis Corrons, director of PandaLabs. "Fortunately, in the case of this threat, it does not seem to be extremely dangerous, due to the means of infection it uses. However, we must not underestimate it, given the success rate of social engineering techniques to spread malware." ®

Agentless Backup is Not a Myth

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?