




Outbreak Alert
Most Active New Threats
| Name | Type | Discovered |
| Trojan.Febipos | Trojan | 13/05/2013 |
| Trojan.Ransomlock!g52 | Trojan | 12/05/2013 |
| W32.Pilleuz!gen38 | Worm | 10/05/2013 |
| W32.Phopifas!gen2 | Worm | 10/05/2013 |
| Packed.Generic.410 | Trojan | 10/05/2013 |
| Bloodhound.Exploit.495 | Trojan | 10/05/2013 |
| Trojan.Ransomlock!g51 | Trojan | 09/05/2013 |
| W32.Changeup!gen41 | Worm | 09/05/2013 |
| Trojan.Ransomlock.AE | Trojan | 09/05/2013 |
| Android.ZertSecurity | Trojan | 08/05/2013 |

Email
LOW RISK:
Use Basic Caution
Although no widespread attacks are currently targeting web users, take normal precautions while viewing sites because of ongoing threats such as script-based attacks and phishing attacks that use fake sites.
Web Activities
MEDIUM RISK:
Use Extra Caution
Microsoft Updates for May 2013 have been released. Please ensure that the latest updates are applied.
Instant Messaging
LOW RISK:
Use Basic Caution
Currently there are no widespread outbreaks of malicious code circulating via instant messaging. In the past, however, some malicious code did take advantage of IM. Always use normal security precautions whenever you use IM.
File Sharing
LOW RISK:
Use Basic Caution
Although attackers often use this medium to distribute trojan applications and malicious code, no high-profile threats are currently affecting the medium. Always use caution when downloading files, especially from sources you don’t know or trust.
Security Response Blog
Symantec Protection for Trojan.FakeSafe
Symantec Security Response @ Fri, 17 May 2013 11:30:57Today, Trend Micro published a report about a targeted attack campaign they’re calling SafeNet (the campaign’s ...
Symantec Protection for Targeted Attacks in South Asia
Symantec Security Response @ Fri, 17 May 2013 02:22:31ESET recently blogged about a targeted cyber/espionage attack that appears to be originating from India. Multiple ...
Spam Campaigns Take to Tumblr
Ben Nahorney @ Thu, 16 May 2013 13:15:01As the urban legend goes, the bank robber Willie Sutton was asked why he robbed banks. ...
Japanese One-Click Fraud on Google Play Leads to Data Stealing App
Joji Hamada @ Thu, 16 May 2013 10:07:30Since the beginning of the year, a Japanese one-click fraud campaign has continued to wreak havoc ...
Phishers Offer Rita Ora’s Video
Mathew Maniyara @ Thu, 16 May 2013 02:10:31Contributor: Avdhoot Patil Celebrity scandals are always popular and phishers are keen on incorporating them into ...
Increase in Pump and Dump Stock Spam
Anand Muralidharan @ Wed, 15 May 2013 12:45:35In the last few weeks we have observed a drastic increase in “penny stock” spam emails. ...
Twitter Feed





Threat Spotlight: Trojan.Ransomlock
Trojan.Ransomlock is a detection for Trojan horse programs that lock the desktop of a compromised computer making it unusable.
The threat may arrive on the compromised computer by various means, such as visiting malicious sites, by opening untrusted links or advertisement banners, or by installing software from untrusted sources.
These programs attempt to convince the user to pay money in order to have their computer unlocked and use a variety of different techniques in order to encourage the user to pay the ransom.
More information on Trojan.Ransomlock is available in the Trojan.Ransomlock writeup.
