Simple clear advice in plain English

Latest phishing scam silent but violent

Just open an email and you could be the next victim, warns security firm

Security experts are warning of a new phishing technique designed to capture online banking details without requiring users to click on a website link.

According to security firm MessageLabs, all potential victims have to do is simply open an email, which then silently runs a script that attempts to rewrite the host files of targeted machines.

The next time the user attempts legitimately to access their online bank they will be automatically redirected to a fraudulent website, enabling their log-in details to be stolen.

The risk is currently low, according to MessageLabs, which has only intercepted copies of emails targeting three Brazilian banks.

However, Mark Murtah, head of emerging threats at security company Websense, expects the threat to increase as phishers use more sophisticated techniques.

"There is a growing awareness among computer users about the dangers of phishing, so they are more suspicious," he said.

"The phishers know this, so we are beginning to see increasingly sophisticated scams that are very hard to detect.

"Something as innocent as using the auto-preview function in an email client is enough to download malicious code or silent key-loggers. And antivirus software will not necessarily pick up the fact someone has been infected."

Computer users can defend themselves against this if they ensure that Windows Scripting Host is disabled.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Phishing for your money takes a new twist

Fraudsters are trying to recruit UK computer users as money launderers

Security shield illustration

How to use the Command Prompt

Lurking under Windows is the little-known world of the command line. We explain how to use this to fix faults and make your PC much more secure

facebook-who-is-stalking-who

Ramnit targets Facebook users

Social networking site warns users not to click on suspicious links

Question & Answer

Q.Can I log on to Facebook after I've moved from Googlemail...

> Read the answer

Q.How do I store musician and other information about...

> Read the answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Best deals on the web

img

Sony Vaio VPCF23P1E/B

£679.98- Buy it now

img

Dell Vostro 1540 (n0215401)

£249.00- Buy it now

img

Apple MacBook Pro (MC724LL/A)

£719.20- Buy it now

Great benefits for subscribers!

Most popular articles

soca

RnBxclusive users busy deleting download history says SOCA

Since law-enforcement agency has taken down a site alleged to illegally host RnB music, downloaders have been busy trying to delete their online footprints

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

Virtual drive

A set of files seen by Windows as a separate hard disk.

Great shopping deals from Computeractive