Jump to content
Fi8sVrs

Hackers use Ebola outbreak to trick users into downloading malware

Recommended Posts

  • Active Members
Posted

Bogus World Health Organisation emails loaded with malware

ebola-virus-virion-270x167.jpg

CYBER CRIMMINALS are taking advantage of the recent Ebola outbreak to trick unsuspecting web users into downloading malware sent in emails that purport to come from the World Health Organisation (WHO).

Uncovered by security researchers at Trustwave, the malware was flagged when it appeared that criminals had crafted bogus WHO emails encouraging people to open a .RAR attachment to find out how they can protect themselves against Ebola.

Trustwave said that once the attachment has been clicked on, it downloads malware onto the victim's machine.

The emails have been sent to a few hundred organisations by criminals who hope to gather information which they can later sell.

"Upon closer inspection, the RAR compressed file attachment is not a document file but an executable file of a DarkComet Remote Access Trojan," explained Trustwave.

"This Trojan makes use of its heavily obfuscated AutoIt-based script to run undetected by antivirus software.

"When run, it creates a randomly named folder in the Windows Application Data folder and drops all of its component files into that folder."

ebola-email-spam-message-540x334.png

Trustwave has seen only one version of the email, suggesting a low volume campaign.

"It isn't surprising to find cyber criminals continuing to piggyback on newsworthy and major events, disasters and outbreaks in order to lure potential victims and spread their malware," said the security firm.

Last week, the US Computer Readiness Team posted an advisory about protecting against scams and spam campaigns using Ebola as a social engineering theme.

The organisation once again advised people not to follow unsolicited web links or click on attachments in emails. µ

Via Hackers use Ebola outbreak to trick users into downloading malware- The Inquirer

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...