Google Search

Showing posts with label spammed. Show all posts
Showing posts with label spammed. Show all posts

Monday, June 3, 2013

Fake Zendesk security notice spammed out, directs traffic to Canadian drug websites

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I'm always on the lookout for breaking news about companies who might have had their systems hacked, so when I received the following email earlier today my interest was piqued.

Its subject line was "An important notice about security".

Fake security notice, pretending to be related to Zendesk breach

We recently learned that the vendor we use to answer support requests and other emails (Zendesk) experienced a security breach.

We're sending you this email because we received or answered a message from you using Zendesk. Unfortunately your name, email address and subject line of your message were improperly accessed during their security breach. To help keep your account secure, please:

* Don't share your password. We will never send you an email asking for your password. If you get an email like this, please let us know right away.

* Beware of suspicious emails. If you get any emails that look like they're from our Support Team but don't feel right, please let us know - especially if they include details about your support request.

* Use a strong password. If your password is weak, you can create a new one [LINK]

We're really sorry this happened, and we'll keep working with law enforcement and our vendors to ensure your information is protected.

Support Team

In a nutshell, the email claims to be from an online company which is using the Zendesk customer service portal to help it answer queries from customers.

ZendeskYou may even remember that Zendesk was hacked in February, and companies such as Tumblr, Twitter and Pinterest contacted some of their users to warn them that email addresses were possibly exposed.

What's different this time is that the body of the email doesn't really make clear *what* company is contacting me. Which seems strange.

Yes, the email mentions Zendesk - but just *who* is the company that was using Zendesk and has suffered as a result of the breach at Zendesk?

With no clear details in the email, the only way to find out is to click on the links... right?

Well, if you do that, you'll find your browser taken on a journey which ultimately (via some temporary redirects) leads you to a Canadian pharmacy website, trying to sell you Viagra and Cialis:

Canadian Pharmacy website

In short, the whole email is a campaign - using the disguise of an important security notice (complete with sensible advice to use strong passwords, and be wary of unsolicited emails!) to trick you into clicking on the link.

These cybercriminals certainly have some gall.

Of course, whoever is behind this campaign could easily change the redirects to point to a more malicious webpage, or a phishing site if they wished. Which would make it even worse.

Interestingly, this isn't the only way in which the spammers have been promoting this particular online drugs store.

Paul Baccas in SophosLabs uncovered for me that in the last 24 hours we have also had reports from customers who have received bogus Facebook notifications pointing to the same site.

Facebook-related spam message

We all probably know someone who is so addicted to Facebook, and stalking their friends' online activity, that they wouldn't hesitate from clicking on a link which they believed had come from the social network.

Remember to always practice safe computing online, including the rule about always being suspicious of unsolicited emails.

If you're not careful, you might not only be visiting spammers' websites - you could also potentially be putting your computer and its sensitive data in danger.

Follow @gcluley

View the original article here

Saturday, March 23, 2013

Arsenal Lotto scam spammed out via PowerPoint file

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

ArsenalThe scammers must be getting more and more desperate to get their claws on our money.

Their criminal business model is messed up somewhat by anti-spam filters blocking their fraudulent messages from reaching potential victims.

What's a bad guy to do?

Well, they could do what this scammer has done - wrap their scam email up into a format that anti-spam software might not look at so closely.

Subject: Please quote your !
From: Arsenal
Attached file: Arsenal.ppt

Message body:
Please find attachement

The scammer doesn't give away much information in the email itself, but only the attachment (a PowerPoint file) and you'll read that Arsenal Football Club have awarded you a £2,350,000 prize in their lottery.

Arsenal lotto scam - click for larger version

All you have to do is contact their representative in China, a Dr Cheng Dingxiang, with your personal information (presumably he will request your bank information soon and an administration fee) and before you know it riches will be yours!

Clearly the scammers are getting desperate.

Hopefully no-one IT-savvy would fall for such a scam - and be instantly suspicious that the communication arrived not only via email, but within a PowerPoint file as well.

But always remember that there may be vulnerable people out there who *do* fall for scams like this, and are at risk of ending up out of pocket as a result. Always be on the lookout to help vulnerable friends and family avoid scams like this - however ridiculous they may appear to you.

You might want recommend to your friends and family that they grab a copy of the Sophos Threatsaurus, where we explain the facts about threats to your computers and to your data in simple, easy-to-follow language.

Here'a one-minute video that tells you more:

Follow @gcluley


View the original article here

Friday, July 20, 2012

You pig! Malware-laced emails spammed out posing as incriminating photos

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A widespread malware attack has been spammed out, posing as incriminating photos of the recipient which could get them in trouble with their partner.

The emails, which have the subject line "You pig!", are designed to infect Windows users and carry a malware attachment posing as a digital photograph.

Malicious email

Subject: You pig!

Message body:
You should be stoping ignoring me or i will send this photos to your spouse!!!

Attached file: DCIM.zip

The emails can claim to come from a variety of different places, including LinkedIn, UPS and Hotmail.

Although the malware-laden emails are poorly spelt, it wouldn't be a surprise at all to hear that many people would be tricked by the aggressive tone to open the attachment. Unfortunately, the contents of the ZIP file are designed to infect Windows computers with a Trojan horse.

The subject line "You pig!" is certainly enough to make many people stop in their tracks, and wonder what has just arrived in their inbox.

SPAM®It strikes me that even those who rightly suspect the email is spam, might be bemused enough (considering the main ingredient of what Hormel Foods nearly called flappertanknibbles) to open the messages and explore further.

Sophos detects the malware inside the ZIP files as Troj/Agent-WXL and the ZIP files themselves as Troj/BredoZp-KP. If you are a user of a product from other vendors check that your software is up-to-date and intercepting the malware.

http://twitter.com/gcluley

View the original article here

Thursday, August 25, 2011

Trojans spammed out in malicious wave of fake DHL emails

Facebook logoOver 30,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest internet and Facebook security threats. X

Twitter logoHi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats. X

DHLThere is a significant wave of malicious emails being spammed out presently, posing as notification messages from DHL.

If you make the mistake of opening the attached ZIP file you will be putting your computer at risk of infection by a Trojan horse.

There's nothing new, of course, about cybercriminals disguising their attacks as notifications from DHL.

This attack, though, is particularly aggressive and - as you can see in the examples below - uses a variety of different DHL-related subject lines, attachment names and message bodies:

Malicious DHL email

HELLO!

Dear Client, Recipient's address is wrong

Print out the invoice copy attached and collect the package at our department

Best wishes , DHL Customer Services

Malicious DHL email

ATTENTION!
DEAR CLIENT , We were not able to deliver the postal package

Please print out the invoice copy attached and collect the package at our department

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

DEAR CUSTOMER, Recipient's address is wrong
PLEASE PRINT OUT THE INVOICE COPY ATTACHED AND COLLECT THE PACKAGE AT OUR DEPARTMENT

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

Dear User , Delivery Confirmation: FAILED
Please print out the invoice copy attached and collect the package at our department
With respect to you, DHL Team

Here are just some of the different disguises we saw in a snapshot of less than one minute in a small selection of our spam traps:

Malicious DHL email subject lines

Sophos products intercept the attack, detecting the ZIP file as Troj/Invo-Zip and the Trojan horse contained within as Mac/EncPk-NS.

Dangerous emails claiming to come from courier companies are nothing new - it has become one of the most commonly-used methods by which hackers socially engineer unsuspecting users into opening a malicious attachment or clicking on a dangerous link.

Make sure that you and your friends are wise to the trick - and think before you click.

Follow @gcluley

View the original article here