* Patches from VMWare, Debian, Mandriva, Gentoo * Beware MonaRonaDona antivirus scam, researchers warn * Criminals automate security testing, and other interesting reading
A new virus making the rounds is designed to get users to download fake antivirus software, resulting in a further infestation. The MonaRonaDona virus uses social engineering techniques to spread. If that’s not enough of a headache, the Storm worm – relatively dormant since Valentine’s Day – is making a comeback, this time with an e-greeting card theme. And it’s not just desktop users that need to worry, F-Secure this week detected a new Trojan targeting Windows Mobile users.
Today’s malware news:
Beware MonaRonaDona antivirus scam, researchers warn
If your computer gets infected with a Trojan called the “MonaRonaDona virus,” be careful with what you use to wipe it off your computer, says antimalware software provider Kaspersky Lab. MonaRonaDona is part of an elaborate scam to sell fake antivirus software, Kaspersky researchers say. Network World, 03/03/08.
Symantec: “MonaRonaDona” – The Pure Social Engineering Scam
F-Secure detects Windows Mobile Trojan
F-Secure Security Laboratory has spotted a new Window Mobile Trojan — InfoJack, detected as Trojan: WinCE/InfoJack. This is a new kind of worm for mobile devices. According to F-Secure, there have long been malicious downloaders on PCs, but this is the first to be discovered for mobile devices. PC World, 03/03/08.
‘Mebroot’ proves to be a tough rootkit to crack
A rootkit uncovered in the wild in December is proving to be a real headache to detect, according to Finnish security company F-Secure. IDG News Service, 03/04/08.
F-Secure: MBR Rootkit, A New Breed of Malware
We haven’t seen new Storm sites since the spam run they did over Valentine’s Day – until early (Monday) morning. Right now they are sending a wide variety of mails regarding ecards. F-Secure blog, 03/03/08.
Today’s bug patches and security alerts:
VMWare patches flaws in ESX server
Multiple integer overflow vulnerabilities have been found in the ‘e2fsprogs’ code found in side VMWare’s ESX 2.5.5 and 2.5.4 servers. Patches are available.
**********
Three new fixes from Debian:
Evolution (format string attack, code execution)
**********
Three new updates from Mandriva:
**********
Nine new patches from Gentoo:
Win32 binary codecs (multiple flaws)
Paramiko (information disclosure)
SWORD (shell command execution)
SplitVT (privilege escalation)
Mantis (cross scripting attack)
Audacity (non-secure temp files, symlink attack)
Adobe Acrobat Reader (multiple flaws)
**********
From the interesting reading department:
Symantec State of Spam Report for March
Social engineering was the driving force behind spammers during the month of February. While overall spam volume hovered steadily at 78.5% of email and tactics remained relatively the same, the use of events, big brands, and public figures drove spam campaigns during the month. Symantec Security Response blog, 03/05/08.
Criminals automate security testing
Cybercriminals are starting to resemble the legitimate software industry to such an extent that they even pre-test malware applications for effectiveness before rolling them out. TechWorld, 03/04/08.
While there are various ways for attackers to trick users into disclosing their authentication credentials, phishing remains one of the most popular. Symantec Security Response blog, 03/03/08.




