Hurricane Katrina Inspires Malware Attack

LOS ANGELES – Proving that some spammers will stop at nothing, a new malware attack has been spotted that tries to fool users with bogus links to breaking news stories about Hurricane Katrina. Users who click on the fake links find themselves on a site hosting Trojan malware.

According to security firm SophosLabs, the site exploits Internet Explorer vulnerabilities to install any number of Trojans, including Cgab-A, Borobot-P, Borobot-Q, Borodldr-H and Inor-R.

Websense Security Labs reports that the Katrina-inspired email scam also has the capability to download a second malicious file, which also is a Trojan. The second Trojan fools users into receiving a free scan for the Zotob worm, when in fact the program infects the users’ computer and allows hackers to take control of the PC.

The malware site is reportedly hosted in Poland. Typical subject lines contain lures such as: "g7 80 percent of our city underwater" or "q1 Katrina killed as many as 80 people."

Other similar malware attacks taking advantage of worldwide disasters came on the heels of last year’s tsunami, which struck Indonesia, and the recent terrorist train bombings in London.

Internet security firms have put out additional warnings to users in the wake of the Hurricane Katrina disaster to be wary of emails soliciting donations for flood victims. The SANS Internet Storm Center has warned that fake fundraising foundations can easily steal user names and passwords and install malicious software on their PCs.

"The hurricane is a dreadful natural disaster, and it's sickening to think that hackers are prepared to exploit the horrendous situation in an attempt to break into computers for the purposes of spamming, extortion and theft,” Graham Cluley of Sophos said. "Everyone should ensure they have defenses in place to properly protect against the very latest malware attacks."

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Utah Governor Signs 'Porn Tax' and VPN Rule Into Law

Governor Spencer Cox on Friday signed into law a bill to tax adult websites and make them liable if minors circumvent geolocation.

BranditScan Launches 'White Glove' Subscription Tier

BranditScan has launched its new White Glove subscription tier for creators.

German Court: Regulator Can't Block Creator's IG Account, Only Posts

A German court has ruled that while a regional media regulatory agency may block specific Instagram posts that include material deemed harmful to minors, it cannot ban an entire Instagram account due to such a post.

Brazil Lays Out Preliminary Guidelines for New AV Requirements

President Luiz Inácio Lula da Silva on Wednesday signed a decree establishing guidelines for new regulations requiring adult websites to age-verify users located in Brazil.

Senate Committee Debates Section 230 Reform

The U.S. Senate Committee on Commerce, Science, and Transportation held a hearing Wednesday on potential changes to Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

Pearl Industry Network Offers Free Creator Memberships

Industry trade group Pearl Industry Network (PiN) has launched its free creator membership initiative.

Sam Bird Acquires Fanblast

Sam Bird, former co-director of global talent agency Surge, has acquired creator monetization tool Fanblast and named himself CEO.

'SheHerGirls' Launches Through Paysite.com

The braintrust behind PoleVixens has officially launched a new membership site, SheHerGirls, also through Paysite.com.

FTC Invites Public Comment on 'Click to Cancel' Rulemaking

The Federal Trade Commission (FTC) announced this week that it is seeking public comment on whether it should amend its Negative Option Rule to better address deceptive or unfair practices.

Aylo Rebuts Indiana AV Suit Claims Over VPN Access

Aylo this week asked a Marion Superior Court judge to dismiss Indiana’s lawsuit alleging that the company violated the state’s age verification law by failing to prevent access by users who employ VPNs and similar means to avoid geolocation.

Show More