Posted on April 1st, 2008 at 2:11 pm by Avatar
The Sans Institute has been monitoring activity of a Trojan that has been using seemingly valid PDF files as a propagation method. Thought the risk is very low and no major incident has been seen, it may be signs of a new frontier malware authors are trying out. The Trojan installs itself as you open the infected Trojan and then opens the PDF as if nothing happened. The SANS institute has issued warnings that even though there are no major incidents of attacks, people should update their Adobe readers to the latest versions. They also advise users to turn off Adobe’s JavaScript facility. More detailed explanation of the incident from the Sans Institute Storm Center Diary entry.