Trojan horse targets Word users

A month-old flaw in Microsoft Word has opened up PCs to attack by a new Trojan horse, antivirus researchers have revealed.

Dubbed "Goga," the malicious code poses as a Word document saved in rich text format but actually reaches through the Net to run a Word macro -- a small program that runs within the application -- saved on a Russian Web site.

"While this is not a danger to the general public, it could be a danger to somebody if there is a direct mailing to them," said Jimmy Kuo, a researcher at security software maker Network Associates.

The Trojan horse appears as a text file in the rich text format, or RTF, attached to an email, according to British antivirus software company Kaspersky Labs, which first found the malicious program.

When opened, the RTF file will link back to a Word template file on a Russian Web site.

The file contains a macro, which will steal and upload information regarding the victim's log-in and password to the guest book of a second site.

An investigation of that site found only one record of any information, indicating the Trojan horse is not widespread.

By using a macro saved in a template hosted on another computer, the Trojan horse is able to fool Windows into letting the macro run, rather than flagging it as potentially dangerous code.

Outlined in a Microsoft advisory a month ago, the technique bypasses normal Windows security against such malicious programs.

"Normally, you could hit someone very easily only if their security settings were low," Kuo said.

"By using this technique, you can bypass the security level."

Kuo stressed that Goga doesn't appear to be a worm or a virus, as it doesn't spread from computer to computer.

He added, however, that the code does show that consumers can't trust attachments.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Darren Greenwood Has New Zealand's smiling assassin delivered?
    One year into its tenure, how has the new New Zealand Government performed on issues of technology and telecommunications?
  • Array The long-awaited separation of Telstra
    Blessed is he who shepherds the weak through the valley of Telstra, for he is truly his brother's keeper and the finder of lost DSLAMs.
  • Array Has Particls disintegrated?
    Brisbane-born start-up Particls promised a better way of organising information from the web. Now, however, it appears to have given up the battle, with both the Particls website and that of its parent company Faraday Media disappearing from the web.
  • More blogs »

Tags

Back to top

Featured