November 04, 2004

No-Click Phishing On The Way

Slashdot | No-Click Phishing On The Way

An anonymous reader writes "MessageLabs has discovered a pretty nasty - though fairly crude - phishing scam which doesn't even require recipients to click on a link in order to hand over personal data. Simply opening the email is enough to activate a script which 'lies in wait for its victim' according to one report. The script rewrites the host files of the machine and directs users to a fake web page the next time they legitimately attempt to access an online banking page. ... However, this will only affect users who have Windows Scripting Host enabled and certain ActiveX controls, according to MessageLabs."

November 4, 2004 at 12:11 AM in Phishing & identity theft | Permalink | TrackBack (11) | Top of page | Blog Home