New Worm Infects Through Explorer Flaw

LOS ANGELES – A new version of the Bugbear.e virus emerged on the Internet this week, infecting computers by exploiting a flaw in Windows-based Internet Explorer.

The worm uses an HTML email that exploits the flaw in browsers to cause its dangerous executable file to silently run without the user clicking on it.

The email messages that carry Bugbear.e are blank, use fake "from" addresses and can have one of many subject lines, including "Click on this!", "25 merchants and rising” and "15 FREE Bonus!" It carries an attachment with a name that's randomly chosen from a file found on the infected computer and has either a .zip or .htm ending. Clicking on the attachment also will cause infection by the virus.

As of Wednesday, there is no available fix or "patch" for Bugbear.e, which first appeared on Monday. But antivirus companies have rolled out software updates that can block Bugbear.e and other variants that also have emerged.

The virus isn't prevalent on the Internet, though its auto-execution feature could help it gain ground, according to Network Associates Inc.'s virus-response center, which also warned of a medium-risk virus known as "Netsky.s," which first emerged Sunday.

Such attacks are somewhat common in Trojan horses but worms like Bugbear.e unnerve security experts because large numbers of computers could be vulnerable to attack and quick defenses would be harder to come by.

Bugbear.e's use of a flaw with no available patch illustrates how the gap between the knowledge of a vulnerability and the release of malicious code that brings us ever closer to a zero-day network worm, an attack using a flaw that security experts don't yet know about.

Microsoft wasn't immediately able to comment on the flaw or when a fix might be available, but its support site, support.Microsoft.com, has additional information available.

The flaw that Bugbear.e exploits was disclosed in February and has since been used by several Trojan horses, which are dropped onto PCs by malicious websites. The virus essentially advances the delivery of a Trojan by using email to push PC users into viewing malicious web content.

Bugbear.e finds sensitive personal information and sends it to the attacker, including cookies, text from open windows and data captured by a program that logs keystrokes to grab passwords and credit card numbers.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Fast-Tracked Arizona Bill Includes Consent 'Catch-22' for Adult Sites

A bill advancing rapidly through the Arizona state legislature would impose new requirements for adult content uploaded online, including seemingly contradictory provisions that could effectively make it impossible for adult sites to operate in the state.

VirtualRealPorn Launches New WebXR Site

VirtualRealPorn has officially launched its new site, powered by Web Extended Reality (WebXR).

'MyAsianGFs' Launches Through Paysite.com

MyAsianGFs.com has officially launched through Paysite.com.

Corey Silverstein to Host Webinar on North Carolina Age Verification Thursday

Adult industry attorney Corey D. Silverstein has announced his latest "Legal Impact" webinar, titled "North Carolina AV Law — Content Creation Issues," to livestream Thursday at 4 p.m. (EST).

Ofcom Fines 8579 LLC $1.8 Million for AV Noncompliance

U.K. media regulator Ofcom on Monday imposed a fine of 1.35 million pounds (more than $1.8 million) against adult site operator 8579 LLC for failing to implement age checks as required for compliance with the Online Safety Act.

Pearl Industry Network Launches 'TrustLink' Creator Verification Platform

Trade group Pearl Industry Network (PiN) has launched TrustLink, its free creator verification platform.

FSC Updates Complaint in Tennessee AV Case, AG Motions to Dismiss

The Free Speech Coalition this week filed an amended complaint in its lawsuit challenging the Protect Tennessee Minors Act as unconstitutional, in response to which the Tennessee attorney general motioned for dismissal of the case.

Cherie DeVille Joins Woodhull Freedom Foundation 'Free Speech' Panel

Multi-XMAs winner Cherie DeVille will join the upcoming Woodhull Freedom Foundation panel series "Fact Checked by Woodhull," addressing free speech on Feb. 26.

Wisconsin AV Bill Moves Ahead, Minus Anti-VPN Provisions

The Wisconsin state Senate on Wednesday advanced a bill that would require adult websites to verify the ages of users, but approved an amendment striking proposed language that would have required sites to block virtual private network traffic.

Pineapple Support Introduces 'Wellbeing by PS' Service

Pineapple Support has debuted its new Wellbeing by PS service, providing mental health support packages for companies and agencies.

Show More