New spam campaign discovered

Jul 27, 2007 10:14 GMT  ·  By

Security company Sophos discovered a new spam campaign started on the Internet that invites the users to download a screensaver for their computer. The message entitled "Life Is Beautiful" actually contains a Trojan horse that attempts to install two rootkits on the infected computers. "Good evening, man! Cool screensaver in your attachment! Wanna more? Welcome to our site. Best regards," the message reads. According to Sophos, "bsaver.zip", the attachment of the email, contains the Troj/Agent-FZB Trojan horse which tries to install two dangerous rootkits on the affected computer.

"If you receive an unsolicited email with an encouragement to run the 'cool screensaver' attached then alarm bells should instantly be ringing in your head," said Graham Cluley, senior technology consultant at Sophos. "Hackers are using a mixture of social engineering and stealth-mode rootkits to try and take advantage of Windows users who forget to think before they click."

As you probably know, you're advised to keep the antivirus solution up-to-date with the latest virus definitions and avoid opening untrusted messages delivered into your inbox. Also, you should download Anti-Rootkit utilities that would help you protect the computer against the threats delivered by this new spam campaign.

"Rootkits are software frequently used by third parties - usually a hacker - to hide other software and processes using advanced stealth techniques. Malicious code, such as spyware and keyloggers, can be invisibly cloaked from detection by conventional security products or the operating system making them hard to detect," explained Cluley. "Hackers use rootkit technology to maintain access to a compromised computer without the user's knowledge, so it's important to be properly defended from these sort of threats."

If you're looking for a security solution to protect the data stored on your computer, you can check the special security category listed on Softpedia, available on this link.