Google Search

Showing posts with label posing. Show all posts
Showing posts with label posing. Show all posts

Saturday, November 17, 2012

Malware attack strikes, posing as Skype password change notification

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Password lock icon. Image from ShutterstockIf Skype users didn't have enough to worry about this week security-wise (with a worm spreading across the system), there's now another threat to warn about.

Emails have been spammed out by cybercriminals, posing as messages from Skype, claiming that you have changed your password on the service.

Here's an example of one such email (click on it for a larger version):

Malicious Skype email. Click for larger version

If you look carefully, you may spot that the spammers made a clumsy spelling mistake:

Password successfully changed
Your new Skype password has been set.

You can now view your attached call history and inscturtions how to change your account settings.
If the changes described above are accurate, no further action is needed. If anything doesn't look right, follow the link below to make changes: Restore password
Talk soon,
The people at Skype

Perhaps surprisingly, the links really do point to the genuine Skype website at skype.com.

However, a file (Skype_Password_insctructions.zip) is attached to the email, and if you make the mistake of unzipping and executing its contents (Skype_Password_inscructions.pdf.exe) you run the risk of infecting your Windows computer.

The malware, which is detected by Sophos products as Troj/Backdr-HN, opens a backdoor onto your computer, giving remote hackers access to your system.

The danger is, of course, that users worried by the recent worm will be frightened that their Skype password has been changed without their consent, and open the attachment - and thus infect their PC.

As always, be on the lookout for unsolicited suspicious emails and always be wary of opening attachments which arrive out of the blue. In this case, the file is using the well-known "double extension trick" to dupe the unwary into believing that they might be clicking on a PDF rather than executable code.

Follow @gcluley

Thanks to SophosLabs researcher Julie Yeates for her assistance with this article.

Lock image from Shutterstock.


View the original article here

Friday, July 20, 2012

You pig! Malware-laced emails spammed out posing as incriminating photos

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A widespread malware attack has been spammed out, posing as incriminating photos of the recipient which could get them in trouble with their partner.

The emails, which have the subject line "You pig!", are designed to infect Windows users and carry a malware attachment posing as a digital photograph.

Malicious email

Subject: You pig!

Message body:
You should be stoping ignoring me or i will send this photos to your spouse!!!

Attached file: DCIM.zip

The emails can claim to come from a variety of different places, including LinkedIn, UPS and Hotmail.

Although the malware-laden emails are poorly spelt, it wouldn't be a surprise at all to hear that many people would be tricked by the aggressive tone to open the attachment. Unfortunately, the contents of the ZIP file are designed to infect Windows computers with a Trojan horse.

The subject line "You pig!" is certainly enough to make many people stop in their tracks, and wonder what has just arrived in their inbox.

SPAM®It strikes me that even those who rightly suspect the email is spam, might be bemused enough (considering the main ingredient of what Hormel Foods nearly called flappertanknibbles) to open the messages and explore further.

Sophos detects the malware inside the ZIP files as Troj/Agent-WXL and the ZIP files themselves as Troj/BredoZp-KP. If you are a user of a product from other vendors check that your software is up-to-date and intercepting the malware.

http://twitter.com/gcluley

View the original article here