Viruses have begun using the data geo information!




Anti-virus vendors Sophos and Websense today separately issued warnings, in which they reported the discovery of a new type of malicious codes, which are built geo information technology, determining the location of users. This is a new version of previously known worm Waledac, which uses a number of methods of social engineering for greater credibility.

The new version of the worm is sent to the spam messages, reporting on the alleged large explosion in a city. As a reference to the news is a link to the site of the alleged agency Reuters. Unusual approach of hackers is that, depending on the city from which the user looks at the letter, it appears differently.

For example, if a user receives a message from Moscow from hackers, he, passing by reference, see the information that the explosion reportedly took place in Moscow, if the user is located in London and received the same letter, a copy of his reports, that the explosion took place in London, etc.

For geolokatsionnoy information on fake Web page, use the database GEO-IP, the user defines the nearest village.

Once the user lands on the site of the alleged agency Reuters, was all the more nakatannomu scenario - he proposed to watch a video of the explosion by pressing the corresponding key system displays a message that the user on the computer lacks any video or flash player and then offers to download it. As you can see, it is suggested, in reality not a codec, and the next Trojan to steal data.

No comments:

Post a Comment