pmcnamara
News Editor

Spoofed e-mail Trojan targets McAfee users

Opinion
Nov 2, 20062 mins

An apparently spoofed mass e-mailing containing a variant of the pesky password-stealing Trojan LdPinch may be putting McAfee customers at risk of being fooled this morning, according to a press release from Kaspersky Lab.

“Kaspersky Lab has intercepted a mass-mailing containing Trojan-Dropper.MSWord.Lafool.v,” says the release. “This mass mailing is unusual as messages appear to be sent from mcafee@europe.com and allegedly originated from McAfee, an antivirus company. Kaspersky Lab believes that McAfee is in no way involved in the distribution of this Trojan and that the email address used in the messages (mcafee@europe.com) is faked and used in order to cause recipients to open infected messages.”

Located on the West Coast, McAfee spokesmen have been unavailable for comment yet this morning as to whether the Lafool.y variant has caused any problems for its customers. (Update: McAfee responds.)

The e-mail carries a Word document entitled “McAfee, Inc. Reports.doc” and purports to be a paper detailing threats on the Internet. Instead, it carries the latest version of LdPinch, a Tojan that has kept vendor patch writers busy, as chronicled in Network World’s Virus and Bug Patch Alert Newsletters here and here and here. The Trojan is capable of stealing passwords to applications, as well as other important data.

Additional details about new variant are available at viruslist.com.