Saturday, June 30, 2007

USB-chomping Windows worm targets Harry Potter fans

June 29, 2007 (PC Advisor) -- Sophos warned Harry Potter fans not to open an e-mail that claims to contain the final installment of the boy wizard book series.

Security companies intercepted an e-mail promising a copy of 'Harry Potter and the Deathly Hallows' -- which is not due for release until July 21. But rather than getting a preview of the book, impatient Muggles who click the file will find their PC infected by the W32/Hairy-A worm, which copies itself to any USB drives it finds attached to the system.

"The W32/Hairy-A worm automatically infects a PC when users plug in USB drives, which carry a file posing as a copy of 'Harry Potter and the Deathly Hallows.doc'," said Sophos.

Instead of the full text of JK Rowling's highly anticipated book, the file includes the phrase: 'Harry Potter is dead.'

After infecting Windows computers, the worm creates a number of new users, namely: Harry Potter, Hermione Granger and Ron Weasley.

There is a real danger that muggles will blindly allow their USB flash drives to auto-run and become infected by this worm," said Graham Cluley, senior technology consultant for Sophos. "Using such social engineering at this time is a trick dastardly enough for Lord Voldemort himself."

source: http://www.infosyssec.net

No comments: