New Worm Infects Through Explorer Flaw

LOS ANGELES – A new version of the Bugbear.e virus emerged on the Internet this week, infecting computers by exploiting a flaw in Windows-based Internet Explorer.

The worm uses an HTML email that exploits the flaw in browsers to cause its dangerous executable file to silently run without the user clicking on it.

The email messages that carry Bugbear.e are blank, use fake "from" addresses and can have one of many subject lines, including "Click on this!", "25 merchants and rising” and "15 FREE Bonus!" It carries an attachment with a name that's randomly chosen from a file found on the infected computer and has either a .zip or .htm ending. Clicking on the attachment also will cause infection by the virus.

As of Wednesday, there is no available fix or "patch" for Bugbear.e, which first appeared on Monday. But antivirus companies have rolled out software updates that can block Bugbear.e and other variants that also have emerged.

The virus isn't prevalent on the Internet, though its auto-execution feature could help it gain ground, according to Network Associates Inc.'s virus-response center, which also warned of a medium-risk virus known as "Netsky.s," which first emerged Sunday.

Such attacks are somewhat common in Trojan horses but worms like Bugbear.e unnerve security experts because large numbers of computers could be vulnerable to attack and quick defenses would be harder to come by.

Bugbear.e's use of a flaw with no available patch illustrates how the gap between the knowledge of a vulnerability and the release of malicious code that brings us ever closer to a zero-day network worm, an attack using a flaw that security experts don't yet know about.

Microsoft wasn't immediately able to comment on the flaw or when a fix might be available, but its support site, support.Microsoft.com, has additional information available.

The flaw that Bugbear.e exploits was disclosed in February and has since been used by several Trojan horses, which are dropped onto PCs by malicious websites. The virus essentially advances the delivery of a Trojan by using email to push PC users into viewing malicious web content.

Bugbear.e finds sensitive personal information and sends it to the attacker, including cookies, text from open windows and data captured by a program that logs keystrokes to grab passwords and credit card numbers.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Opinion: Why Device-Based Age Verification is the Key to Protecting Minors Online

Across the United States, state legislators on both sides of the aisle have attempted to tackle the crucial goal of preventing minors from accessing adult content.

TMZ: VMG's Mike Moz in Talks About 'Potential Collab' With Yeezy

Vixen Media Group’s Mike Moz told TMZ on Friday that the company has been discussing a potential collaboration with Kanye West’s brand Yeezy.

Age Verification: FSC's Mike Stabile Reports from the Front Lines

Two years into the religiously-inspired crusade to ban free access to adult material in the U.S. through carefully drafted "age verification" legislation, the constant onslaught of state-by-state proposals and laws — many of them copied from each other — can be hard to follow.

Written Erotica Platform 'Hevvn' Launches

Hevvn, a new platform aimed at erotica writers seeking to publish, promote and profit from their work, debuted Thursday.

Sssh.com's Angie Rowntree Speaks at Brown University

Sssh.com founder Angie Rowntree spoke at a Brown University class last week, discussing several topics related to adult filmmaking.

Online Industry Veteran Joe E. Passes Away

Online industry veteran Joe E has passed away, according to friends and industry associates.

Judge Acquits Backpage Defendants of Most Charges Before 2nd Retrial

A federal judge acquitted former co-owner of Backpage.com Michael Lacey and two co-defendants on most of the counts remaining from the protracted trial launched against the website operators by the Justice Department in 2018.

Adult Time Partners With Animation Studio 3DGspot

Adult Time has signed a deal to stream content from animation studio 3DGspot.

Georgia Gov. Brian Kemp Signs Age Verification Bill Into Law

Republican Gov. Brian Kemp this week signed into law a bill that includes provisions requiring age verification for viewing adult content in Georgia, mirroring legislation being sponsored around the country by anti-porn religious conservative activists.

AEBN Publishes Popular Searches by Country for February, March

AEBN has released the popular searches from its straight and gay theaters in more than three dozen countries during February and March.

Show More