Storms in July – who would have thought it?

So, even now 17 months down the line the ‘Storm Worm’ still is morphing and reinventing itself to keep itself alive and ‘out there’. The chronology of ‘storm’ is interesting as it shows just how the intersection of social engineering, and news events, allow the bad-guys to continue to use and repurpose this attack. More of this in a future blog.

The tactic that is being used this time round is to hide the Storm malware within fake news stories about the FBI and Facebook.  As usual, you are directed to a fake web site, a site is hosted on an infected Storm web proxy. If you follow the lure and click the link you will end up with an executable named “fbi_facebook.exe”. This is the malware.  The web site you link to not only hosts the download attachment, but the site also launches a set of browser exploits at you.

comments

Leave a Reply