main
Report a problem

Trojan Hidden on Job Search Sites Steals Personal Data

Daniel Fleshbourne   on 20 August 2007 - 14:01 · 2 comments & 3252 views

Advertisement (Why?)
SecureWorks researchers have uncovered a cache of stolen data from 46,000 victims of a variant of the Prg Trojan that has been used to swipe personal information from unsuspecting visitors to job sites. Experts at the Atlanta-based security company said the information includes bank and credit card account numbers, social security numbers and passwords. The victims were infected—and in numerous cases re-infected—by ads on popular, online job sites, including Monster.com during the past three months.

The hackers behind the attack are running ads on the sites and injecting those ads with the Trojan. When an user views or clicks on one of the malicious ads, their PC is infected and all the information entered into their browser, such as financial information entered before it reaches SSL protected sites, is captured and sent off to the hacker's server, according to SecureWorks researcher Don Jackson.

View: the full story
News source: eWeek

Post a comment · Send to friend Comments · There are 2 additional comments
#1 RudyJ on 20 Aug 2007 - 14:09
#2 kaborka on 20 Aug 2007 - 17:07
How does simply viewing the ad insert the malware? Is this due to the past buffer overflow exploit in the graphics library that renders images? That was patched months ago. What's the actual vector for this "infection"?

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)