|
Criminal emailers are increasingly exploiting MS04-013, an MHTML URL Processing vulnerability which allows a remote attacker to automatically and surreptitiously download and execute arbitrary code via miscreant websites or email. In many cases, the scammer uses a common phishing technique, composing an email that masquerades as correspondence from a legitimate financial institution. As with phishing scams, the email claims there is a problem with the user's account in an attempt to entice them to click the link and visit the spoofed website. Once on the site, the phishing scam ends and the malware takes over - a downloader Trojan is forced onto the victim's computer and executed, which in turn can be exploited to download other malicious code.
|