Spam folder
The attacks are being sent out as spam messages which contain hyperlinks

Security experts warn of 'terror attack' spam

Bogus 'bomb scare' emails add unsuspecting users to Waledac botnet

Written by Shaun Nichols in San Francisco

A new malware scam is using fabricated reports of a terrorist attack to infect users. Researchers from several security firms, including McAfee and Sophos, said that the attacks are being sent out as spam messages which contain hyperlinks.

The attacks carry such headlines as 'Why did it happen in your city?' and 'At least 18 killed in your city'. The message itself contains little more than a short sentence and a link to a phoney news site.

The attack distinguishes itself, however, in the use of geolocation services which collect traffic data and insert the name of the recipient's city into the article, further increasing the chances that he or she will click on what appears to be a video file on the page.

However, rather than load a video, the page attempts to download an executable file on the target system. The file then infects the user with malware from the 'Waledac' botnet (also known as 'waled').

"They are using the city name of the user visiting the fake web site and inserting this name into the web site itself," said McAfee researcher Micha Pekrul in a blog post.

"So the 'breaking news' gets even more attention, because when an attack happens in your home town, everyone would be anxious and curious."

Neither tactic is particularly new. Malware writers have long taken to creating fake pages for news events, attacks and natural disasters, both real and fabricated, to spread their wares. Geolocating is also becoming a particularly effective tool in social engineering attacks.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

FacebookInternet

Latest malware attack spoofs Facebook page

'Dancing girl' brings nothing but trouble for users 13 Mar 2009

 

Security experts warn of 'staggering' rise in malware

Research shows economic slump prompting surge in online criminality 11 Mar 2009

Costs skyrocket in the battle against spam

Lost productivity costing the average company £130,000 a year, says McAfee 09 Mar 2009

Top 10 worst things about the web

A collection of online annoyances we all could do without 15 Mar 2009

Autorun infections re-emerging in the wild

New malware outbreak resembles first disk-based virus attacks 05 Mar 2009

A week in security: hentai malware writers nabbed

V3.co.uk rounds up the week's top security stories 29 May 2010

Security vendors scope out 2010 landscape

Rogue anti-virus and web apps could make news next year 16 Dec 2009

Facebook and college basketball in cyber-crime spotlight

Latest scams target social networkers and sports fans 19 Mar 2010

related white papers

today's top stories

Financial IT job market recovery continues

Recruitment growth suggests IT budgets are increasing 30 Jul 2010

Satellite broadband touted as digital divide clincher

KA-SAT launch promises 10Mbit/s service for hard-to-reach locations 29 Jul 2010

Ofcom slams ISPs for exaggerated broadband speed claims

New code of practice for ISPs planned by the regulator 27 Jul 2010

Aerohive offers traffic light Wi-Fi monitoring

Firm promises simple 'red, yellow or green' system with Client Health Score tool 27 Jul 2010

Flaw in top wireless security protocol WPA2 uncovered

Disgruntled insiders could hack corporate wireless LAN 26 Jul 2010

Advertisement

How to achieve business and financial-system implementation success
A look at how organisations - regardless of size - can work towards successful business software installations and factors that determine the outcome.

Case study: Specsavers put customer care into focus
How Specsavers captured customer feedback at point of sale and incorporated the results into its CRM system.

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

ICO to lean more heavily on public sector bodies

ICO to lean more heavily on public sector bodies

The ICO has said it will lean more heavily on public sector bodies to secure timely FOI responses, do you think this is:

View poll results

Latest audio and video articles

picture of Jason HartVideo

Ethical hacker reveals the security secrets behind cloud computing

Jason Hart, Senior VP at Cryptocard, shows Computing just how easy it is to illegally gain access to corporate cloud services to wreak havoc and steal money. 29 Jun 2010

gartner logoVideo

Part 1: 2010 trends in SOA and Application Development and Integration

Gartner analyst Paolo Malinverno explores trends in SOA 29 Jun 2010

Latest in-depth articles

Map of 3G coverageComment

The risks of selling off the 800MHz radio spectrum at the wrong price

It's a choice between revenue now or universal broadband later 30 Jul 2010

Luton Borough Council officesAnalysis

Local authority leads the way in digital backup technology

Luton Borough Council tells of the benefits of early adopter of VTL, data deduplication and virtualisation 27 Jul 2010

Primary Navigation