Email that states it’s from the FTC’s “Fraud Department” has virus attached
(ALISO VIEJO, CA) November 8, 2007 eEye Digital Security®, a leading developer of unified client security and vulnerability management tools, today announced that its endpoint security product Blink version 3.0 and higher will automatically protect systems against a fraudulent email currently being circulated that claims to be from the Federal Trade Commission (FTC).
The spoof references a false “complaint” against the email’s recipient. The unauthorized email includes links and an attachment that downloads a virus. The attack uses a malicious payload that can bypass most Host-based Intrusion Protection systems that rely on buffer overflow protection.
“Traditional anti-virus and buffer overflow protection products cannot protect against this type of attack,” said Morey Haber, VP of Product Management for eEye Digital Security. “For those people who opened the email and then proceeded to click on the links, Blink Identity Theft, Intrusion Prevention, or Anti-Malware protection layer would have provided automatic protection for the user from being compromised by the infected website.”
Released on November 1st, Blink 3.5 carries advanced features designed specifically for the growing landscape of attacks such as the FTC spoof email. Current users of Blink 3.0 are also protected against this type of attack, due to Blink’s System Protection layers.
Blink is an award-winning endpoint security client that uses protocol analysis to detect and block zero-day attacks that bypass standard signature-checking methods. Operating systems, databases, and applications are protected from the most recent threats without the need for system patches or new virus signatures.
Home users can download a free copy of Blink Personal edition by clicking: http://www.eeye.com/html/consumer/products/blink/download
In a written statement the FTC wrote, “It is likely that anyone who has opened the email’s attachment or clicked on the links has downloaded the virus on their computer, and should run an anti-virus program. The virus appears to install a ‘key logger’ that could potentially grab passwords and account numbers.”
According to a report filed by NBC24.com, the FTC just last week released a statistical survey of fraud in the United States showing 30.2 million adults, or 13.5 percent of the adult population, were victims of fraud during the year studied.
Next week, eEye Digital Security will announce its PCI Compliance Reporter, a series of report templates designed to ensure that organizations comply with some 12 Payment Card Industry Data Security Standard (PCI DSS) requirements for protection against credit card fraud and identity theft.
About the FTC
The FTC works for the consumer to prevent fraudulent, deceptive, and unfair business practices and to provide information to help spot, stop, and avoid them. To assist with investigations, recipients should forward suspect emails to spam@uce.gov. More information about bogus emails, phishing, and virus protection is available at www.OnGuardOnline.gov. For free information on a variety of consumer topics, click http://ftc.gov/bcp/consumer.shtm or contact the Office of Public Affairs at (202) 326-2180.
About eEye Digital Security
eEye Digital Security® is pioneering a new class of security products:integrated threat management. This next-generation of security detects vulnerabilities and threats, prevents intrusions, protects all of an enterprise’s key computing resources, from endpoints to network assets to web sites and web applications, all while providing a centralized point of security management and network visibility.eEye’s research team is consistently the first to identify new threats in the wild, and our products leverage that research to deliver on the goal of making network security as easy to use and reliable as networking itself. Founded in 1998 and headquartered in Orange County, California, eEye Digital Security protects more than 9,000 corporate and government organizations worldwide, including half of the Fortune 100. For more information, please visit www.eeye.com
Primary Agency Contact
Victor Cruz
MediaPR
(508) 655-4397 eEye@mediapr.net
EMEA Agency Contact
Ralph Klöwer
INTERFACE Relations
+49 (0) 89-552 688-66 r.kloewer@interface.pr.de
Corporate Contact
Stacy Newman
eEye Digital Security
(949) 900-4131 press@eEye.com
