Jump to content

Recommended Posts

  • ExTS Admin
Posted

Unauthorized email change lure still used in spam campaigns

 

One of the latest email spams to impersonate Twitter tries to trick users into opening a malicious attachment by passing it as an invitation to the micro blogging service. Meanwhile, Twitter email change scams are still going around and send unsuspecting victims to websites packed with exploits.

 

Security researchers from Vietnamese antivirus vendor Bkis warn of a malware distribution campaign sending out emails that masquerade as official communications from Twitter. The rogue messages have spoofed headers to look as if originating from invitations@twitter.com and claim to be automated invitations sent at a friend's request.

 

http://img.photobucket.com/albums/v708/starbuck50/Blog%20pics/twitterscam.png

 

"Twitter is a service for friends, family, and co-workers to communicate and stay connected through the exchange of quick, frequent answers to one simple question: What are you doing? To join or to see who invited you, check the attachment," the spam reads.

 

The attachment is called "Invitation Card.zip" and contains a computer worm detected by Bkis as W32.Ziktwitters.Worm. "This virus [...] downloads a lot of other malwares including FakeAV and constantly distributes advertising emails as well as phishing emails to other users," Nguyen Cong Cuong, senior security researcher at Bkis, explains.

 

The author of this particular malware also seems to have a sense of humor. The researcher points out the decryption code used in the executable is ironically Google's informal motto "Don't be evil".

 

According to a recent report, one such scam claims the email address associated with the Twitter account has been changed in order to lure users.

 

http://img.photobucket.com/albums/v708/starbuck50/Blog%20pics/twitterscam1.png

 

The spammed linked, which is spoofed to appear as pointing to a resource on twitter.com, actually redirects victims to a page loading an exploit cocktail. Before being attacked, the user is subjected to several tests to determine his browser, as well as the version of other potentially vulnerable software installed on his computer, like Java, Flash Player or Adobe Reader.

 

 

Source:

Twitter Invitation Email Scam Spreads Malware Downloader - Unauthorized email change lure still used in spam campaigns - Softpedia

Member of:

UNITE

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...