Yes, the phishers are at it again and have sent out email purporting
to be from Westpac which invites customers to visit a website which
accepts donations for Australia's paraplegic olympics team.
The interesting thing about this phish is that the actual bonafide
donation page is displayed -- not a clone, and if anyone enters there
CC details to make a donation, that information *will* be delivered to
the charity concerned.
However, the original page has been cunningly framed by the phishers
and the other (near invisible) frame in this set attempts to exploit a
vulnerability in unpatched copies of Interent Explorer (of course) to
load a trojan that logs your keystrokes (and goodness knows what
else).
Please tell all your friends and family. Visiting the phisher's
website using a vulnerable browser, even if they don't actually enter
anything into the form, may mean that their keystrokes are logged from
that point on -- thus exposing credit card numbers and banking logins.
There's more info on today's Aardvark.
--
you can contact me via
http://aardvark.co.nz/contact/