New Worm Infects Through Explorer Flaw

LOS ANGELES – A new version of the Bugbear.e virus emerged on the Internet this week, infecting computers by exploiting a flaw in Windows-based Internet Explorer.

The worm uses an HTML email that exploits the flaw in browsers to cause its dangerous executable file to silently run without the user clicking on it.

The email messages that carry Bugbear.e are blank, use fake "from" addresses and can have one of many subject lines, including "Click on this!", "25 merchants and rising” and "15 FREE Bonus!" It carries an attachment with a name that's randomly chosen from a file found on the infected computer and has either a .zip or .htm ending. Clicking on the attachment also will cause infection by the virus.

As of Wednesday, there is no available fix or "patch" for Bugbear.e, which first appeared on Monday. But antivirus companies have rolled out software updates that can block Bugbear.e and other variants that also have emerged.

The virus isn't prevalent on the Internet, though its auto-execution feature could help it gain ground, according to Network Associates Inc.'s virus-response center, which also warned of a medium-risk virus known as "Netsky.s," which first emerged Sunday.

Such attacks are somewhat common in Trojan horses but worms like Bugbear.e unnerve security experts because large numbers of computers could be vulnerable to attack and quick defenses would be harder to come by.

Bugbear.e's use of a flaw with no available patch illustrates how the gap between the knowledge of a vulnerability and the release of malicious code that brings us ever closer to a zero-day network worm, an attack using a flaw that security experts don't yet know about.

Microsoft wasn't immediately able to comment on the flaw or when a fix might be available, but its support site, support.Microsoft.com, has additional information available.

The flaw that Bugbear.e exploits was disclosed in February and has since been used by several Trojan horses, which are dropped onto PCs by malicious websites. The virus essentially advances the delivery of a Trojan by using email to push PC users into viewing malicious web content.

Bugbear.e finds sensitive personal information and sends it to the attacker, including cookies, text from open windows and data captured by a program that logs keystrokes to grab passwords and credit card numbers.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

California, Florida Reps File Latest Bill to Repeal Section 230

Two members of Congress on Thursday introduced new legislation to repeal Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

Admaze Introduces Flat-Rate Media Buying for Publishers, Advertisers

Adult ad network and agency Admaze has introduced a flat-rate media buying model for publishers and advertisers.

Centro Launches Lifetime Revenue Share Affiliate Program 'CentroPulse'

Centro has launched CentroPulse, its new lifetime revenue share affiliate program for performance marketers, adult traffic affiliates, established webmasters, and sub-affiliate network operators.

Fanstage Launches Telegram Sales Solution

Fanstage has launched its new platform, allowing creators to sell PPV content directly from their Telegram DMs.

Second Bill Proposed to Shield US Sites From 'Foreign Censorship'

For the second time in recent weeks, a Republican congressman has introduced legislation to bar U.S. courts from helping to enforce foreign laws restricting speech that would domestically be protected under the First Amendment, potentially including foreign age verification laws.

SextPanther Launches in EU, UK

SextPanther has expanded its territory to include the U.K. and E.U.

Segpay Expands to Australia, Names Sam O'Connell Managing Director

Segpay has expanded its territory to include Australia and named Sam O’Connell as managing director of its Australian operation.

Ondato Joins ASACP as Corporate Sponsor

Age and identity verification company Ondato has signed on as the latest corporate sponsor for Association of Sites Advocating Child Protection (ASACP).

2026 XBIZ Amsterdam Conference Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for XBIZ Amsterdam, set to take place Sept. 10-13 at Passenger Terminal Amsterdam.

Ukrainian Legislators Revive Porn Decriminalization Push

The Verkhovna Rada, Ukraine’s parliament, is once again considering a bill that would decriminalize the creation and distribution of pornography in that country — an activity that currently carries a prison sentence of three to five years.

Show More