Bogus U.S. Airways registration confirmation leads to info-stealing malware
Posted on 10.01.2013
Bookmark and Share
A new email spam campaign impersonating U.S. Airways is hitting inboxes, warns Webroot, and the airline's customers would do well to be on the lookout for the following "booking confirmation" email (click on the screenshot to enlarge it):



There are obvious spelling mistakes that should alert users to the bogus nature of the email, but a lot of people - "blinded" by the legitimate looking graphics - don't regularly check for those.

The offered links take the victims to compromised sites that host the Blackhole exploit kit, and once it does its thing, they are unknowingly served with a variant of the Cridex information-stealing Trojan, currently detected by a little over half of the AV solutions employed by VirusTotal.

This is not the first email spam campaign impersonating an airline, and it won't be the last. Fake flight reservations and e-ticket verification emails are sent out every day, as the cost of doing it is small and easily recouped - in fact, the amount is surpassed many times - when even an extremely small percent of recipients fall for the scheme and get their computers infected.





Spotlight

Attackers use reflection techniques for larger DDoS attacks

Posted on 17 April 2014.  |  Instead of using a network of zombie computers, newer DDoS toolkits abuse Internet protocols that are available on open or vulnerable servers and devices. This approach can lead to the Internet becoming a ready-to-use botnet for malicious actors.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Apr 18th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //