





Outbreak Alert
Most Active New Threats
| Name | Type | Discovered |
| Infostealer.Shiz!gen | Trojan | 09/02/2012 |
| W32.Pilleuz!gen31 | Worm | 08/02/2012 |
| Backdoor.Cycbot!gen10 | Trojan | 08/02/2012 |
| Trojan.Zbot!gen30 | Trojan Virus | 06/02/2012 |
| Infostealer.Offsupload | Trojan | 06/02/2012 |
| W32.Begmian | Worm | 05/02/2012 |
| Android.Bmaster | Trojan | 03/02/2012 |
| Trojan.Zeroaccess!gen8 | Trojan | 02/02/2012 |
| W32.Pilleuz!gen30 | Worm | 01/02/2012 |
| Trojan.Zatvex!gen4 | Trojan | 01/02/2012 |
Internet Threat Meter
The Internet Threat Meter provides a quick visual indicator of how likely each common online activities is likely to encounter some form of threat from a malicious attacker.
- Hover over each activity for a short explanation of the current risk level
- Click on an activity to visit a page with more detail on that activity and the risk level

Email
LOW RISK:
Use Basic Caution
Malicious code and fraudulent messages often circulate via email. Never open unsolicited attachments or hyperlinks, and always verify the source of any messages that ask you for sensitive information.
Web Activities
MEDIUM RISK:
Use Extra Caution
Microsoft Updates for February 2012 have been released. Please ensure that latest updates are applied.
Instant Messaging
LOW RISK:
Use Basic Caution
Currently there are no widespread outbreaks of malicious code circulating via instant messaging. In the past, however, some malicious code did take advantage of IM. Always use normal security precautions whenever you use IM.
File Sharing
LOW RISK:
Use Basic Caution
Although attackers often use this medium to distribute trojan applications and malicious code, no high-profile threats are currently affecting the medium. Always use caution when downloading files, especially from sources you don’t know or trust.
Security Response Blog
Revamped Fake Android Market for SMS Fraud
Joji Hamada @ Fri, 10 Feb 2012 18:48:23We have continued monitoring the massive campaign involving SMS Fraud on the mobile platform for a ...
Is Waledac Spam Dirtying the Russian 2012 Elections?
Symantec Security Response @ Fri, 10 Feb 2012 11:50:09Recently there have been several reports about the re-emergence of a botnet variant (Kelihos), which Symantec ...
New Targeted Attack Using Office Exploit Found In The Wild
Joji Hamada @ Thu, 9 Feb 2012 12:14:29Contribution: Takayoshi Nakayama read more ...
Infostealer.Offsupload: 20,000+ Archives Containing Stolen Data Uploaded to Third Party File-Sharing Site
Stephen Doherty @ Thu, 9 Feb 2012 01:39:09Upwards of 20,000 stolen archives have been uploaded to a third party file-sharing site from hosts ...
Android.Bmaster: A Million-Dollar Mobile Botnet
Cathal Mullaney @ Wed, 8 Feb 2012 21:14:37Thanks to Eric Chien for his assistance with this research. Introduction read more ...
Russian Spammers Eye World Content Show
Samir Patil @ Wed, 8 Feb 2012 17:17:38Thanks to Anand Muralidharan for their assistance with this research. Televison channels across the world are ...
Twitter Feed





Threat Spotlight
Trojan.Clampi is a Trojan horse that attempts to steal login credentials related to online banking and other financially related websites. The threat is typically installed by way of drive-by download and once it compromises a computer, it downloads several modules. One of these modules is used to spread Clampi through network shares.Trojan.Clampi is able to bypass firewalls to relay the stolen information to a remote attacker and also uses a SOCKS proxy to allow the remote attacker to then login to banking and other financially related websites anonymously with the stolen credentials.
More information on Trojan.Clampi is available in the threat family writeup.
