New Mytob worm phishing for victims
AV vendors are warning users that the latest W32/Mytob-DA variant is on the prowl, this time masquerading as an e-mail message from their own security administrator that will allow their machines to be remotely controlled.
According to U.K.-based MessageLabs, the malware spoofs the sender's address to replicate the recipient's domain; the message asks the user to follow the URL to confirm his/her e-mail account to prevent it from being suspended. The Web link is also spoofed to appear to connect to the target company's Web site. If clicked, the Web link in the e-mail message will download a file named Confirm_Sheet.com, which will enable infected machines to be remotely controlled.