Cybercriminals Continue to Spam Victims While Posing as Popular Companies

GFI Software today released its VIPRE® Report for June 2012, a collection of the 10 most prevalent threat detections encountered last month. In June, GFI threat researchers observed two fresh spam campaigns linking to Blackhole exploits which posed as confirmation emails from Twitter® and Amazon®. Delta Airlines® similarly had their brand misappropriated in a spam campaign meant to infect users with Sirefef and rogue antivirus software. GFI also hosted a free webinar which provided a detailed look at the Flame virus using data gathered from GFI’s own GFI Sandbox™ technology.

“Cybercriminals are ever focused on infecting as many victims’ machines or stealing as much personal information with as little effort as possible. By disguising the source of their spam as messages from companies or organisations with widespread appeal, they can increase the number of potential victims likely to fall for their scams,” said Christopher Boyd, senior threat researcher at GFI Software. “Any notices or ‘confirmation emails’ that arrive unexpectedly, no matter how legitimate it may appear, should be thoroughly inspected before the user takes any other action. If something seems out of place, users should trust their instincts and use common sense before clicking anything that could make the situation worse.”

Throughout the month of June, phony emails claiming to be Amazon order confirmations were sent to unsuspecting victims in the hopes of infecting them with malware. Users who clicked any of the links contained in the email were directed to a web page that contained Blackhole exploit code. The exploit scanned the user’s system for Adobe® Reader® and Adobe Flash® before loading a Java applet that redirected the victim to web pages that hosted specially-crafted PDF exploit files depending on the version of Adobe Reader found on the system.

Another fake email posing as a Twitter account confirmation linked victims to a Russian website which housed a Blackhole exploit kit. The site deployed exploits that targeted Adobe Reader and Adobe Flash vulnerabilities which were as old as six years. It’s important to note that both of these attack campaigns could have been avoided had victims kept their software fully patched and up to date.

A bogus spam email was also discovered disguising itself as a Delta Airlines e-ticket. Users who downloaded the attachment were met with an executable file that infected their system with Sirefef and Live Security Platinum, a rogue antivirus program. This fake AV program blocked the running of all other applications and deployed constant pop-ups and browser redirects to messages alerting the user of an infection and requesting payment to clean up the system.

Like this article?

Share on twitter
Share on Twitter
Share on linkedin
Share on Linkdin
Share on facebook
Share on Facebook
Share on email
Share via email

Other posts that might be of interest

man searching
Internet Marketing Articles

Can you find what you are looking for?

If you want to increase your sales, your business needs to make it easy to find everything. That means reviewing how your web search works. It suggests you might need to reconsider the navigation structure of your website. It might even mean you need to distribute your content away from your site and have it on a variety of different platforms.

Read More »
Empty football stadium with no supporters
Internet Psychology

How well supported are you at work?

Yesterday I was transported back in time. I haven’t discovered time travel. Instead, my mind quickly flipped back to a meeting about three years ago that involved the same group of people. I noticed how

Read More »
Man using digital technology
Internet Psychology

Are you obsessed with digital?

Being obsessed with digital could take you away from old-school technologies that do the job better. Yet, avoiding technological change can cost your business dearly. How can you get the balance right?

Read More »