There seems to be some confusion regarding the actual way the code is hidden in the file. Can you be more specific about this?

As we said in our first press release, the actual code, which can be dangerous, is stored in the ID3 tag of the MP3 file. This tag usually contains comments about a song, but in this Trojan horse, executable code is stored in this tag. As mentioned above, the cfrg resource indicates where in the file the code is stored.

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive