Beware of Malicious Olympic 2012 Android Apps

By Joe McManus

There are too many events happening at one time during the Olympics, which might tempt you to install an app for that. But be careful of what you install. Not all apps are what they appear to be. As an example let’s look at the app called “London Olympics Widget”.

More details:

(more…)

Spamvertised ‘PayPal has sent you a bank transfer’ themed emails lead to Black Hole exploit kit

Spamvertised ‘PayPal has sent you a bank transfer’ themed emails lead to Black Hole exploit kit

Sticking to their well proven social engineering tactics consisting of systematic rotation of the abused brands, cybercriminals are currently spamvertising millions of emails impersonating PayPal, in an attempt to trick end and corporate users into interacting with the malicious campaign.

Once the interaction takes place, users are exposed to the client-side exploits served by the Black Hole exploit kit, currently the market share leader within the cybercrime ecosystem.

More details:

(more…)

Russian spammers release Skype spamming tool

Russian spammers release Skype spamming tool

Taking advantage of DIY spamming tools and harvested databases of user names, cybercriminals have been systematically abusing multiple instant messaging services in an attempt to trick as many users as possible into interacting with their malicious campaign.

In this post, I’ll profile a newly released DIY Skype spamming tool, discuss its main features, and whether or not it can lead to an increase in the overall spam levels affecting Microsoft’s Skype.

More details:

(more…)

Cybercriminals target Twitter, spread thousands of exploits and malware serving tweets

Cybercriminals target Twitter, spread thousands of exploits and malware serving tweets

Twitter users, beware!

Over the past several days, cybercriminals have been persistently spamvertising thousands of exploits and malware serving links across the most popular micro blogging service. Upon clicking on the clicks, users are exposed to the exploits served by the Black Hole web malware exploitation kit.

What’s so special about this campaign? What’s the detection rate of the malware it drops? Where does it phone back once it’s executed? Have we seen additional malware phone back to the same command and control servers, indication a connection between these campaigns? Let’s find out.

More details:

(more…)

Spamvertised ‘Download your USPS Label’ themed emails serve malware

Spamvertised ‘Download your USPS Label’ themed emails serve malware

Cybercriminals are currently spamvertising millions of emails impersonating the United States Postal Service (USPS), in an attempt to trick end and corporate users into downloading and unpacking the malicious .zip attachment distributed by them.

What’s so special about this campaign? Where is the malicious sample phoning back to? Are there more malware samples that also phoned back to the same command control servers in the past? Let’s find out.

More details:

(more…)

Cybercriminals impersonate law enforcement, spamvertise malware-serving ‘Speeding Ticket’ themed emails

Cybercriminals impersonate law enforcement, spamvertise malware-serving ‘Speeding Ticket’ themed emails

Not fearing prosecution, cybercriminals regularly impersonate law enforcement online in an attempt to socially engineer  end users and corporate users into interacting with their malicious campaigns. From 419 scams, police ransomware, to law enforcement themed malware-serving email campaigns, cybercriminals continue abusing the international branches of various law enforcement agencies.

In this post, I’ll profile a currently spamvertised malware-serving campaign, indicating that the user has “violated red light traffic signal” and that he should download the fake camera recording of his vehicle attached to the email.

More details:

(more…)