|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Spammers arm junk mail with multiple weapons By Brett Winterford, ZDNet Australia July 04, 2007 URL: http://www.zdnet.com.au/news/security/soa/Spammers-arm-junk-mail-with-multiple-weapons/0,130061744,339279541,00.htm
Opportunistic spammers are increasingly posting additional threats, such as links to malware, within the body of their unsolicited e-mail messages, according to new findings by Internet security company Marshal Software. The practice, which Marshal has dubbed "Piggyback Spam", was only prevalent in around 2-3 percent of spam until the last seven days, before it shot up to around 15 percent of total spam. Marshal has provided a few working examples. In the first, an image-based spam message flogging pharmaceuticals also included a separate offer pertaining to a new software application which tracks the location of any mobile phone user. The link to a free download of this software points to a malicious file that could hand control of the computer over to spammers. Spammers, says Bradley Anstis, director of product management for Marshal, are clumsily attempting to be more efficient by arming a single e-mail with a wider array of threats. "They are not just sending you an unsolicited message but also expanding the botnet so that they can start sending more spam from your machine," he said. A second example is a spam e-mail which includes an additional message from somebody claiming to be a lonely and bored 25-year-old girl, offering pictures of herself via a Web link. The Web link, as you might expect, is actually an executable malicious file. Anstis said there are still plenty of e-mail users that would be double-duped -- first by opening an unsolicited message, and second by clicking on an unrelated link within it. "We can't assume that all users realise when a message is spam," he said. "People are still falling for these messages." Paul Ducklin, head of technology for antivirus vendor Sophos, said the attacker's desperation might actually work against them. "There is a silver lining here, because e-mails with multiple threats can be blocked if even one of these threats is recognised," he says. "Sometimes, when cybercriminals try too hard, we paradoxically win more easily because there is more dangerous behaviour to spot."
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |