Online phishing uses new bait

One click sends unwary users to fake websites

Written by Rodney Jack

A new phishing attack is being used to hook unwary web users, the Anti-Phishing Working Group (APWG) has warned.

When a phishing victim clicks on a link in an email pretending to come from their bank or another company, they are sent to a fake website which will then try to steal bank account details or other information.

Advertisement

The APWG said this new method does not make use of the Internet Explorer flaw used in previous attacks, but extends a similar visual effect to multiple browser platforms.

The new trick uses software that detects the user's browser and applies custom JavaScript to replace the look and feel of the web address bar with an appropriately designed working fake, to fool people into thinking they are visiting a legitimate site.

"When a user clicks the link in the email they have no way of knowing they've been taken to a fake site," an APWG spokesman told vnunet.com.

"If you were to type in a new web address in the fake address bar, it will load the new requested page."

The second issue with a fake address bar is the possibility for a 'man in the middle' attack, where every subsequent website visited, and any passwords or credit card numbers entered, could be sent to the phisher until the browser window is closed.

"We've seen about 30 unique attacks using this basic source code since 25 February 2004," said the APWG spokesman.

"This is the first evolution that is programmed to automatically detect the browser type and selectively replace the address bar with a look and feel that matches, and functions.

"This variation was first seen on 31 March and, as yet, we haven't seen it repeated. But we expect this won't be the last."

The spokesman added that phishing seems to be following the same pattern as viruses and worms, where one group develops the original version and others re-purpose successful code and enhance it further.

Phishing attacks are increasing in frequency and sophistication. February recorded the busiest month with 282 email attacks, a 60 per cent rise on January's record total, according to the APWG.

And the group warned: "Even veteran users are having a really hard time telling real from fake without diving into the source code of a message or web page.

"Consumer education will only work to a point - and that point is diminishing."

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Ministry of Defence

MoD data loss total could hit 1.7 million

New figures far higher than initial estimates   More...

Sun Microsystems

Sun Sparc server shatters seven standards

T5440 sets new benchmark records   More...

Gary McKinnon

Home Office turns down latest McKinnon appeal

Home Secretary informs lawyers of arrangements for US extradition   More...

Network cables

Network Instruments touts nanosecond apps troubleshooting

Observer 13 offers upgraded performance and forensic network analysis   More...

Primary Navigation