Sophos reports that the subject line of the spam email makes it look like the bloody photos are coming from the AFP news agency, but the attached Bloody Photos_Gadhafi_Death.rar file is actually a worm that spreads using IRC.
It opens a backdoor into the affected machine and allows attackers to access it remotely and to make the machine part of an IRC-controlled botnet.
As always, users are advised not open unsolicited emails, attachments or links contained in them, especially when they supposedly offer insight into a hot news topic. Visiting legitimate news sites is a much better option if you are interested in the latest happenings.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.