Cyber-criminals launch PDF malware offensive

PDFex storms into the charts

Written by Robert Jaques

PDF malware "smashed" into October's virus charts, a security firm reported today.

Sophos said that the new PDFex Trojan has been widely spammed out in emails with an infected Adobe Acrobat PDF attachment, and has reached third position in the malware chart.

The Trojan was launched during the last few days of October, taking advantage of an unpatched Windows vulnerability to infect PCs.

"PDFex only started to circulate at the very end of the month, but still managed to account for over 13 per cent of all emailed malware during October," said Carole Theriault, senior security consultant at Sophos.

"It was heavily spammed out between 26 and 28 October, and accounted for a staggering two thirds of all malware spread via email."

PDFs have long been used in business as a means of sharing information, so the social engineering trick of using a PDF puts insufficiently protected businesses at risk, according to Sophos.

"Adobe has issued an update to its Acrobat software that fixes the problem, and eyes are now turned to Microsoft to patch the underlying flaw in Windows which could affect other vulnerable applications such as Skype and Firefox," warned Theriault.

She added that, although criminals are currently using PDF files to try and infect innocent PCs with malware, there is little evidence of spammers continuing to use PDF files.

The research also indicates a slight decrease in the percentage of infected email. Overall in October, one in every 1,000 emails carried malicious email attachments, compared to one in every 833 during September.

However, web attacks continue to pose a "significant threat", Sophos warned. Mal/Iframe was responsible for almost seven out of every 10 infections found on the web by the security firm.

See also:

reader comments

related articles

Trojan horse

Mac Trojan attack gathers steam

OS X attack being served up with PC malware 01 Nov 2007

 

Hackers can 'wreak havoc' with zero byte scripts

An oldie but a goldie 31 Oct 2007

Analysts predict bonanza for mobile anti-malware

Vendors urged to hook up with operators in bid to boost sales 30 Oct 2007

Trojan attacks jump 500 per cent

Microsoft report warns of sharp hike in cyber attacks 23 Oct 2007

Attackers target PDF vulnerability

Beware the bill or invoice pdf 24 Oct 2007

Attackers feast on Real Player flaw

Real promises to patch hole as soon as possible 22 Oct 2007

Angelina Jolie 'nudes' fuel malware spike

Oldest trick in the spammers' book 01 Oct 2007

New malware-infected site found every five seconds

Experts warn of 'dramatic rise' in web-based threats 22 Apr 2008

Halloween 'skeleton' spam hides Storm Trojan

Don't let your PC be turned into a zombie 31 Oct 2007

latest news

Red Hat a good fit for Qumranet

Open source behemoth opens up Windows opportunities with acquisition of virtualisation specialist 05 Sep 2008

Infor praises partners

Software vendor outlines its channel vision at second annual EMEA partner summit in Marbella 05 Sep 2008

Version One and Accurate launch university push

Software vendors link arms to create integrated document and financial management offering for universities 05 Sep 2008

Most commented stories

poll

Stormy times ahead for PBX?

Stormy times ahead for PBX?

Will the credit crunch affect PBX takeup?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories