Subscribe to RSS feeds


Oct27
by Roderick Ordoñez (Technical Communications)

A nifty little program that Trend Micro detects as TROJ_CAPTCHAR.A disguises itself as a strip-tease game, wherein a scantily clad “Melissa” agrees to take off a little bit of her clothing. However, for her to strut her stuff, users must identify the letters hidden within a CAPTCHA. Input the letters correctly, press “go,” and “Melissa” reveals more of herself.

Screenshots below:

TROJ_CAPTCHAR.A screenshot

TROJ_CAPTCHAR.A screenshot

However, the “answers” are then sent to a remote server, where a malicious user eagerly awaits them. The strip-tease game is actually a ploy by ingenious malware authors to identify and match ambiguous CAPTCHA images from legitimate sites, using the unsuspecting user as the decoder of the said image.

Interesting enough, the CAPTCHAs in the example above were taken from the Yahoo! Web site, possible proof that someone may be building a huge base of Yahoo! accounts. For spam-related reasons perhaps? Although various methods of OCR (Optical Character Recognition) are already used to circumvent the CAPTCHA, this social engineering technique is new in that it uses people to unsuspectingly aid a malicious user.

The CAPTCHA, short for Completely Automated Public Turing test to tell Computers and Humans Apart, was born when bots started spreading over the Internet scene a few years ago. The system was aimed at preventing automated submissions/registrations of bots by prompting the user to validate himself as a human, usually requiring the user to input a sequence of alphanumeric characters contained in an image supposedly “unreadable” by a machine.

However, some people are really hooked up on defeating the CAPTCHA, and they are literally asking for public help, in a rather discreet—and, um, provocative—manner.




30 Responses to “CAPTCHA Wish Your Girlfriend Was Hot Like Me?”

  1. mein betrunkenes Gestotter » Verteiltes Rechnen Says:

    [...] dazu bei TrendMicro und Pandalabs. In Netzwelt [...]

  2. Dennis Stolze : Blog Says:

    [...] muss. Was liegt also näher, einem unbedarften Surfer Captchas vorzusetzen und lösen zu lassen? TrendMicro berichtet nun über einen neuen Trojaner, der es sich zu Nutze macht, dass viele Männer ihr Gehirn aussschalten, sobald sie nackte Frauen [...]

  3. Tom Smith's the OTHER blog Says:

    [...] CAPTCHA Wish Your Girlfriend Was Hot Like Me? (via Seth Godin) we can see a different approach altogether. Here the naughty hackers have decided [...]

  4. Security Tips » Melissa Strips For Captcha Translations Says:

    [...] file making the rounds doesn’t appear to directly threaten the PCs where it is launched. Trend Micro characterized the Melissa Strip program as a non-destructive Trojan they can detect with their [...]

  5. The Guerilla CISO » Blog Archive » Be a Slave to Nakedness and CAPTCHAs Says:

    [...] writeup about a cute piece of malware that uses humans to answer CAPTCHAs in exchange for a striptease.  Something about this I think is [...]

  6. flyingpenguin » Blog Archives » CAPTCHA Strippers Says:

    [...] Micro has a complete description of the Melissa attack, including pictures of the model in various states of [...]

  7. Business News Research » Cybercriminal Bets Users Will Trade Security For Sex — Security Says:

    [...] to take off a little bit of her clothing,” said security researcher Roderick Ordonez on the Trend Micro blog. “However, for her to strut her stuff, users must identify the letters hidden within a [...]

  8. Alanat News » Cybercriminal Bets Users Will Trade Security For Sex Says:

    [...] off a little bit of her clothing,” said security researcher Roderick Ordonez on the «blog.trendmicro.com». “However, for her to strut her stuff, users must identify the letters hidden within a [...]

  9. CAPTCHAs: SPAMMERs as Social Engineers at thinkbeta.com Says:

    [...] The program presents a partial picture of “Melissa,” who invites you to see more by deciphering a CAPTCHA. Answer correctly and you get a peek at another piece of Melissa and a new CAPTCHA to solve, and so forth. Raimund Genes, chief technology officer at Trend Micro says the technique could gain some traction because “the average male e-mail user would want to see more.” But really … can the prospect of uncovering one pinup be so enticing as to warrant jumping through all those hoops? I mean, if you really want to see dirty pictures online, I’m told they’re not hard to find. Still, full marks to the malware community for creativity. Here’s how CAPTCHA’s work from here: [...]

  10. Blogger News Network / One of the oldest social engineering techniques (sex) still seems to work! Says:

    [...] post from the Trend Labs Malware Blog with some rather revealing graphics, here. Let Others Know About This PostThese icons link to social bookmarking sites where readers can [...]

  11. Would you like to know more? » Blog Archive » Ingenious Spam Says:

    [...] comes a story about a spam Trojan that entices users to play a simple game in order to disrobe a lady on-screen. As you’d expect, there are no shortage of takers out there. Except what players are actually [...]

  12. Lifestyle business » Blog Archive » СтрипCAPTCHA Says:

    [...] Источник: TrendLabs blog [...]

  13. Hacking al alcance motivacional de las masas « Enciso’s Blog Says:

    [...] decifradas, parece ser que ya están listos para hacer spamming. La historia la pueden encontrar aquí y [...]

  14. Hacking al alcance motivacional de las masas « PaQueSepas Says:

    [...] decifradas, parece ser que ya están listos para hacer spamming. La historia la pueden encontrar aquí y [...]

  15. links for 2007-11-03 « Netweb Says:

    [...] CAPTCHA Wish Your Girlfriend Was Hot Like Me? - TrendLabs | Malware Blog - by Trend Micro (tags: captcha internet funny malware security yahoo) Posted in Internet. [...]

  16. Cómo los spammers descifran los CAPTCHAs « Says:

    [...] CAPTCHA Wish Your Girlfriend Was Hot Like Me? | Vía: Seth [...]

  17. chmod007.com » Troca justa? Says:

    [...] garotas rebolando e tirando suas roupas? Pois é, mas esse software era pago. Então criaram a Melissa, trata-se de um software parecido, que é instalado na sua máquina como uma praga qualquer, porém [...]

  18. Virtual Strippers to Boost Productivity ? | PuTech Naman! | Yet Another Technology Blog… Says:

    [...] Micro says that there’s a new Trojan called TROJ_CAPTCHAR.A which takes advantage of unsuspecting users to decode CAPTCHA images: TROJ_CAPTCHAR.A disguises [...]

  19.   Batiburrillo links IV by Tecnorantes Says:

    [...] el blog de Trendmicro comentan la ultima ocurrencia de los hackers para saltarse los captcha.Nada como una mujer ligerita [...]

  20. Jack Of All Blogs → Blog Archive » CAPTCHA and Social Engineering Says:

    [...] images above were hotlinked from Trend Micro (thanks guys!) who have issued a warning about this kind of social engineering [...]

  21. matthewgruman.com » Fooling the CAPTCHAS Says:

    [...] information here, here, here, [...]

  22. Melissa Strip Captcha Breaker Trojan… un troyano que parece que muchos no van a poder resistirse : Says:

    [...] Digamos que este es el Troyano más “sexy” que nunca hemos visto… el troyano se llama Melissa Strip, identificado por Trend Micro como TROJ_CAPTCHAR.A y Trj/RompeCaptchas. [...]

  23. V0lTr4n Bl0G » Blog Archive » Melissa Strip Captcha Breaker Trojan… un troyano que parece que muchos no van a poder resistirse Says:

    [...] Digamos que este es el Troyano más “sexy” que nunca hemos visto… el troyano se llama Melissa Strip, identificado por Trend Micro como TROJ_CAPTCHAR.A y Trj/RompeCaptchas. [...]

  24. Melissa Strip Captcha Breaker Trojan at BTT | Blog The Tech Says:

    [...] such a tempting Trojan before. The Trojan named Melissa Strip, identified as TROJ_CAPTCHAR.A by TrendMicro and Trj/RompeCaptchas.A by Panda, starts by asking the user if he wants to play a game where she [...]

  25. Cybercriminal Bets Users Will Trade Security For Sex Says:

    [...] off a little bit of her clothing,” said security researcher Roderick Ordonez on the «blog.trendmicro.com». “However, for her to strut her stuff, users must identify the letters hidden within a [...]

  26. XKOD | El troyano irresistible: Melissa Strip Captcha Breaker Says:

    [...] Más información : Trend Micro [...]

  27. Rauschkinda.at blog Says:

    [...] auf einen Sachverhalt von Oktober 2007 hinzuweisen: A new way of social engineering (siehe auch hier und hier) lsst CAPTCHAs (tolles Akronym, btw) von Menschen lsen. Hat gewissermaen auch was mit [...]

  28. Daemon Life » Blog Archive » Alan Turing e lo Spam Says:

    [...] più strane di ingegneria sociale sono state usate dagli spammers per aggirare il test: dal virus “Melissa”, una finestra con una ragazza che effettua uno striptease ad ogni captcha risolto, fino [...]

  29. Troyano Melissa Strip Captcha Breaker al ataque » El blog de KnxDT Says:

    [...] Vía: Trend Micro [...]

  30. CAPTCHA-Hacking « Maikls Notizbuch Says:

    [...] CAPTCHA Wish your girlfriend was hot like me - Blogeintrag bei TrendMicro A new way of social engineering - Blogeintrag bei PandaLabs [...]



© Copyright 2008 Trend Micro Inc. All rights reserved. Legal Notice