Unusual banking trojan found today

Tuesday, April 1st, 2008

We've seen tons of banking trojans lately, but now we've run into something quite unique. This new banking trojan was found today from a drive-by-download site. We've added detection for it as Win32.Pril.A It not only infects the MBR of the machine, but also reflashes the boot code in the Flash BIOS, ...

Slide.com Hosting Malware

Monday, March 31st, 2008

Websense Security Labs has been tracking the use of Slide.com as a hosting site for malware for several months. The popular Web 2.0 social networking Web site, ranked 252 by Alexa (Alexa Ranking), is both the largest Facebook application developer and a free and easy place to host malware. Having tracked the various ways malware is hosted on ...

Researchers dive into memory dumps

Monday, March 31st, 2008

Building on earlier research into cold-boot attacks on computer memory, two consultants showed off their prototype tools for grabbing passwords from untended computers, during a session at the CanSecWest conference last week. The consultants -- Sherri Davidoff and Tom Liston, both of security firm Intelguardians -- found that numerous Windows and ...

Stormy April Fool’s Day

Monday, March 31st, 2008

A wave of April Fool's Day related Storm mails have just been sent out. Similar as the other times with a link that points to an IP address.

Shedding (Black)Light on the Master Boot Record

Monday, March 31st, 2008

A while ago we blogged about the MBR rootkit, which has been getting attention from all the security vendors. We're glad to inform you that the latest version of the F-Secure BlackLight standalone rootkit scanner now detects MBR rootkit infections. BlackLight has stood the test of time ever since it was ...