A new malware attack uses search engine optimization-driven subject lines to tempt you into opening an HTML attachment. The attachment includes Javascript that can install a back door in your browser, even if the browser is not open.