You are here: silicon.com > Software > Malware

Malware

PM 'heart attack' email dupes bank customers

Trojan dines out on social engineering Down Under...

Tags: phishing, scam, trojan, phishing scam

By Steven Deare

Published: 20 February 2007 08:55 GMT

Hackers may have captured the login details of around 2,500 banking customers by circulating a Trojan email claiming Australia's Prime Minister has suffered a heart attack, according to a security company.

Entitled "John Howard, the current Prime Minister of Australia has survived a heart attack", the email claims Howard suffered the heart attack while staying at his official residence in Sydney and is fighting for his life in hospital.

The email then provides a link purporting to be an online news report. Users that click the link however are directed to a standard "404 error" page which downloads a Trojan to their computer.

Joel Camissar, Websense country manager for Australia and New Zealand, said the Trojan monitored infected users' internet activity. This included logging keystrokes, he said - which could include banking login details.

Websense, which has been tracking the scam, has identified one of the servers used in the hacking attempts and is recording compromised IP addresses, as well as other data stored by the server, according to Camissar.

He said 2,500 users around the world have been infected by the Trojan, with around 30 per cent - or 750 people - from Australia. Customers of banks across Europe and the US may have had their passwords captured, said Camissar, adding that customers of Australia's Commonwealth and Westpac banks may specifically have had their account details captured.

Both banks have denied the Trojan has infected their systems. A spokesperson for Westpac said its systems have not been compromised and the bank is unaware of any fraud losses as a result. While a Commonwealth Bank spokesperson said its website has not been infected by the Trojan.

However, as Camissar explained, the website is not the issue: "The Commonwealth Bank website hasn't been compromised but the Trojan horse monitors user sites visited and sends back the [bank site] username and password to the server computer."

Websense is working with law enforcement authorities to find the scammers, said Camissar.

Steven Deare writes for ZDNet Australia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
UNIX Systems Administrator / Trading Floor Support Banking Sector, Consultancy, London City

For further details please view our website at www.net2s.co.uk Apply: If you would like to apply for the position of UNIX Systems Administrator / ...

Integration Engineer

If you want to put yourself forward to join us, click on the link below which will take you through to our website where you can build your profile ...

Business Analyst JDA Arthur

Youll be taken through to our dedicated recruitment website where youll be able to find out more about Claires, the role and apply ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: