New DNS Hijacking Trojan targeting Commonwealth Bank Customers
'Sophos' security firm bewares of a different kind of phishing threat which is targeting Australian Commonwealth bank customers, using a DNS hijacking Trojan to hack login information.
According to the researchers, the attack begins with phishing emails targeting a genuine Commonwealth Bank pattern, which contains the company's logo, copyright notice and additional identification details. The fake email also contains the heading as "Update your Commonwealth Bank" and says that the email has been sent to inform the recipient that his/her account will be ceased within a period of 48 hours because of Account Inactivity, as reported by Sophos lab blogs on 15 September, 2010.
Also, the users are informed that particular details related with their account are needed to be confirmed, so that they can continue operating it. The purpose of the text is to spread rumours in order to scare users. Starting with "Customer ID: 000-5432-654386-PSI", the emails looks authentic and depends on the reality that maximum customers are not able to remember their personal ID number.