Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » Webmail-creating Trojan targets Gmail
Closed Thread
Old 08-15-2007, 12:28 PM   #1 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,087

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Webmail-creating Trojan targets Gmail

A strain of malware capable of setting up bogus Hotmail and Yahoo! accounts in order to send spam has been adapted to also target Gmail accounts.
The HotLan Trojan creates automatically-generated webmail accounts, implying that spammers have discovered a means to defeat Captcha challenge-response systems. Captcha systems, which typically prevent accounts being created until a user correctly identifies letters depicted in an image, are designed to ensure requests are made by a human rather than an automated program.
document.write('\x3Cscript src="http://ad.uk.doubleclick.net/adj/reg.security.4159/spyware;'+RegExCats+GetVCs()+'pid='+RegId+';'+RegK W+'maid='+maid+';test='+test+';pf='+RegPF+';dcove= d;sz=336x280;tile=3;ord=' + rand + '?" type="text/javascript">\x3C\/script>');
Since the arrival of the first variant of the Trojan last month, more than 500,000 spam email accounts have been created, according to Romanian anti-virus firm BitDefender. A joint effort between the security teams of BitDefender and Yahoo! appears to have stymied attempts to generate and use Yahoo! accounts to send spam.
However, this has pushed the problem onto Hotmail and Gmail (a new target of a latter variant of the Trojan) rather than having the desired effect of bringing the creation of bogus accounts under control.
The use of compromised PCs to send spam has been going on for years. The HotLan Trojan follows a more complex routine. Each active copy of the Trojan attempts to set up a webmail account, sending off the captcha image in an encrypted form to a spammer-controlled website. Servers behind this site process the image and extract the solution to the captcha challenge, which is then posted in the appropriate field.
Once a webmail account is established, encrypted spam emails are sent from a website onto infected machines. The HotLan Trojan then decrypts these junk emails and sends them to (presumably valid) addresses taken from yet another website.
Junk mail sent using the malware have largely been used to spamvertise pharmacy sites. Multiple bogus accounts are created from each infected machine. The Trojan itself is not widespread, indicating a possible desire by its authors to keep a low profile, even though its effects on Hotmail (in particular) are serious.
"There were 514,000 Hotmail accounts created [by the Trojan], as well as about 49,000 at Google," said Viorel Canja, head of BitDefender Anti-Virus Lab. "However, it is worth noting that while most of the Hotmail accounts are operational, Gmail accounts get blocked pretty fast, usually about a couple of days after being created."

Webmail-creating Trojan targets Gmail | The Register
__________________
Osiris is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hotlan Trojan Focuses on Hotmail, Gmail Osiris Virus - Spyware Protection / Detection 0 08-11-2007 02:31 PM
Trojan creates bogus webmail accounts to punt drugs Osiris Virus - Spyware Protection / Detection 3 07-06-2007 03:26 PM