Messaging Pipeline | Trojan Horse | PayPal Password-stealing Trojan Mass Mailed
Free Newsletter GlossaryContact UsAbout Us
One To One Collaboration Servers & Security Business

February 27, 2006

PayPal Password-stealing Trojan Mass Mailed



Courtesy of

Several million copies of a password-stealing were spammed to Internet users late last week, a security company said Monday, and workers returning to the office who open the attachment risk a computer kidnapping.

U.K.-based BlackSpider Technologies said that it had already intercepted more than 3.2 million messages with an attached Trojan, and claimed that it took 52 hours for the first anti-virus vendor to issue a signature that detected and deleted the malware.

, as Sophos dubbed it (Symantec named it "PWSteal.Tarno.s"), comes with the subject head of "Notification: Your Account Temporally Limited," and targets PayPal users. The associated e-mail claims that PayPal has detected unusual activity on the recipient's PayPal account. If the user opens the attached file, Clagger.h silently installs.

Not only does Clagger.h set a so the attacker can later add more malicious code to the PC, but it lurks in the background and nabs usernames and passwords from any window or Web page with text strings ranging from "cash" and "bank" to "log" and "id."

"This Trojan horse has been aggressively seeded, using spam technology, to distribute malicious code to as many vulnerable computers as possible, in the shortest amount of time," said Graham Cluley, a Sophos senior technology consultant, in a statement.

Astute users will be waved off by a gaffe in the spam's subject heading.

"A simple spelling mistake in the subject line should alert innocent recipients that this isn't a genuine message from PayPal," he added. In the message, the word "Temporarily" is misspelled as "Temporally," although its conceivable that the hacker was trying to tell users that their PayPal password was limited by . Or not.

"People should always think carefully before running unsolicited code on their computer," Cluley advised.

E-mail This Story
Print This Story





Get the latest Messaging news, product info, and trends every week.


Related Content

  Right-click and choose Copy to extract RSS Feed URL  Messaging Pipeline's Main RSS Feed
  Right-click and choose Copy to extract RSS Feed URL  Messaging Pipeline's Blog RSS Feed




Editorial and vendor perspectives






Editor's Picks
The Six Flavors Of Windows Vista
Microsoft plans to release a full six-pack of Vista versions, one for every taste. Which Vista will be right for you?

Hope is Not Enough When It Comes To Compliance

Three Ways To Authenticate E-Mail And Stop Spam

Wikis In The Workplace

Review: Google Desktop 3

Vendors are now talking about how collaboration can be improved by integrating video with messaging applications. They're even talking about adding live TV to mobile phones. How far do you go before it becomes a bandwidth and business productivity drain?
Video is a great idea
    13%
Video is fine but there needs to be size limits
    25%
It's never used for anything really productive
    38%
I draw the line at live TV
    25%


In search of messaging products? Check out our brand new Product Finder for a directory of groupware and collaboration tools, security products, archiving solutions, and more.



MESSAGING PIPELINE MARKETPLACE (sponsored links)

With business growth back on the agenda, the role of the CIO is changing from manager of technology to C-suite collaborator in enabling innovation that matters for the business. Read an executive summary and register to download the full IBM paper.


Maximize your investment with one of the top custom Unicenterư education & implementation teams in the nation. Get the knowledge, integration & expertise you expect from your Unicenterư technologies to deliver a true integrated enterprise solution.


Increasing .NET and J2EE application complexity is making effective application management more vital for business success, and at the same time, more difficult to achieve. By automating problem resolution processes, businesses can benefit greatly.


Automatic Job Scheduling/Batch Processing Software for Windows platforms. Download 30 day Trial Version Today!


ER/Studio delivers next-generation data modeling. Multiple, distinct physical models based on a single logical model give you the tools you need to manage complex database environments and critical metadata in an intuitive user interface.






Sponsored Links:      
 |   |   |   |   |   | 
 |   |   |   | 
 |   |   |   |   | 
Messaging Pipeline  |   |   |   | 
 |   |   |   |   | 
© 2006 | MESSAGING PIPELINE All rights reserved. | |