Malware on the desktop and mobile device

Opinion
Mar 6, 20083 mins

* Patches from VMWare, Debian, Mandriva, Gentoo * Beware MonaRonaDona antivirus scam, researchers warn * Criminals automate security testing, and other interesting reading

A new virus making the rounds is designed to get users to download fake antivirus software, resulting in a further infestation. The MonaRonaDona virus uses social engineering techniques to spread. If that’s not enough of a headache, the Storm worm – relatively dormant since Valentine’s Day – is making a comeback, this time with an e-greeting card theme. And it’s not just desktop users that need to worry, F-Secure this week detected a new Trojan targeting Windows Mobile users.

Today’s malware news:

Beware MonaRonaDona antivirus scam, researchers warn

If your computer gets infected with a Trojan called the “MonaRonaDona virus,” be careful with what you use to wipe it off your computer, says antimalware software provider Kaspersky Lab. MonaRonaDona is part of an elaborate scam to sell fake antivirus software, Kaspersky researchers say. Network World, 03/03/08.

Symantec: “MonaRonaDona” – The Pure Social Engineering Scam

F-Secure detects Windows Mobile Trojan

F-Secure Security Laboratory has spotted a new Window Mobile Trojan — InfoJack, detected as Trojan: WinCE/InfoJack. This is a new kind of worm for mobile devices. According to F-Secure, there have long been malicious downloaders on PCs, but this is the first to be discovered for mobile devices. PC World, 03/03/08.

‘Mebroot’ proves to be a tough rootkit to crack

A rootkit uncovered in the wild in December is proving to be a real headache to detect, according to Finnish security company F-Secure. IDG News Service, 03/04/08.

F-Secure: MBR Rootkit, A New Breed of Malware

Storm Reactivating

We haven’t seen new Storm sites since the spam run they did over Valentine’s Day – until early (Monday) morning. Right now they are sending a wide variety of mails regarding ecards. F-Secure blog, 03/03/08.

Today’s bug patches and security alerts:

VMWare patches flaws in ESX server

Multiple integer overflow vulnerabilities have been found in the ‘e2fsprogs’ code found in side VMWare’s ESX 2.5.5 and 2.5.4 servers. Patches are available.

**********

Three new fixes from Debian:

Evolution (format string attack, code execution)

libicu (multiple flaws)

iceape (multiple flaws)

**********

Three new updates from Mandriva:

tcl (denial of service)

OpenLDAP (multiple flaws)

wireshark (denial of service)

**********

Nine new patches from Gentoo:

lighttpd (multiple flaws)

Opera (multiple flaws)

Win32 binary codecs (multiple flaws)

Paramiko (information disclosure)

SWORD (shell command execution)

SplitVT (privilege escalation)

Mantis (cross scripting attack)

Audacity (non-secure temp files, symlink attack)

Firebird (multiple flaws)

Adobe Acrobat Reader (multiple flaws)

**********

From the interesting reading department:

Symantec State of Spam Report for March

Social engineering was the driving force behind spammers during the month of February. While overall spam volume hovered steadily at 78.5% of email and tactics remained relatively the same, the use of events, big brands, and public figures drove spam campaigns during the month. Symantec Security Response blog, 03/05/08.

Criminals automate security testing

Cybercriminals are starting to resemble the legitimate software industry to such an extent that they even pre-test malware applications for effectiveness before rolling them out. TechWorld, 03/04/08.

Do as I Say, Not as I Do

While there are various ways for attackers to trick users into disclosing their authentication credentials, phishing remains one of the most popular. Symantec Security Response blog, 03/03/08.