Tech Daily

News | Analysis | Comment | Features | Reviews

Major attack targets Microsoft Outlook Web Access

Websense warns of highly targeted assault

Iain Thomson in San Francisco, V3.co.uk 16 Oct 2009

Websense has warned that a major attack has been detected against Microsoft's Outlook Web Access service.

The internet monitoring firm said that it is seeing around 30,000 emails a day which urge users to visit a web site and download a security update file, which in fact contains malware.

The email message reads: 'We are informing you that, because of the security upgrade of the mailing service, your mailbox settings were changed. In order to apply the new set of settings click on the following link.'

What makes the attack unusual is a high level of personalisation. The page that loads when the recipient clicks on the link is very convincing because it uses the victim's email address and domain name.

"We have seen customisation like this before, but it is not very common. As the angle is Outlook Web Access, a corporate/enterprise system, it is very likely that the targets are primarily corporations," said Websense.

"Websense Security Labs has seen a rise in banking Trojans targeting corporations because, not only do those accounts have more money in them, they can typically also do international wire transfers directly from the online banking system."

The malware makes the PC part of the Zbot botnet and allows full remote control by the botnet controller.

See also:

AdobeCompany releases 29 patches for Reader and Acrobat  14 Oct 2009
Password screenMajority were easy to pick, says security expert  07 Oct 2009
HackerLoss of vital networks would quickly cripple any nation, says ITU chief  07 Oct 2009
Security padlockSeries of events and programmes designed to educate businesses and consumers  02 Oct 2009

All Hacking
Tags: Microsoft, Websense, Outlook-web-access, Threats, Malware, Trojan, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

R E L A T E D   C O N T E N T