Results 1 to 6 of 6
  1. #1
    Experienced User
    Overall activity: 0%

    Join Date
    Sep 2009
    Posts
    2,046
    Liked
    0 times
    Points
    28,383

    Spin LinkedIn Spam Attack Spreads ZeuS

    Researchers at Cisco Security Intelligence Operations on Monday detected a new spam attack in the form of a false LinkedIn connection request. According to Cisco, these messages "accounted for as much as 24 percent of all spam sent within a 15-minute interval." Those who fell for the trap and clicked the link saw a Web site with the message "PLEASE WAITING.... 4 SECONDS", after which the browser redirected to Google.

    During that short time, the malicious Web site infected the user's PC with the ZeuS data theft malware using a drive-by download, according to Cisco. ZeuS is a well-known threat commonly used by cyber-criminals to steal personal information, especially banking credentials.
    Source http://www.pcmag.com/article2/0,2817,2369774,00.asp?kc=PCRSS05079TX1K0000992

    Original VT analysis http://www.virustotal.com/file-scan/report.html?id=1dc848df1d294af28459e4c224e78361114bec79ae48564b27724b0613407e65-1285618236

  2. #2
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Wow... epically win for the malware writers, especially when most people use LinkedIn for a "professional Facebook" from what I can see.
    pacman -Syyu life not found in sync db

  3. #3
    Experienced User
    Overall activity: 0%

    Join Date
    Sep 2009
    Posts
    2,046
    Liked
    0 times
    Points
    28,383
    Quite realistic emails were used, see here. PCWorld contributor was really scamed and since his Kaspersky client was bypassed, he came to know he was infected with Zeus after reading Cisco email, see here. Brian Krebs has some more details, quite interesting i think, several PDF, Java and Windows Help and Support Center exploits being used to trigger Zeus installation.
    Last edited by noaccount; 09-29-2010 at 05:12 AM.

  4. #4
    Digital Knight
    Overall activity: 0%

    Join Date
    Feb 2010
    Location
    Troy, MO
    Posts
    1,239
    Liked
    1 times
    Points
    11,871
    I'm getting inundated. All types of email from messages, to open attached plans, etc.
    Quite discouraging.
    "Two things are infinite: the universe and human stupidity; and I'm not sure about the the universe." Einstein

  5. #5
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    ZeuS strikes again . Now LinkedIn is the target. Thanks for the news noaccount.
    I don't need to know everything, I just need to know where to find it, when I need it.

  6. #6
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Apart from it...these days facebook is the easiest dissemination platform.

    Awareness:

    Zeus is lovely! and lame.

    Create at least 5-10 facebook accounts, copy and paste infos ( consistent ) , cute chix on the profile pict, add many friends, a little study or surveillance of the target/victim/pool. Then one lucky multiple strike + java exploits/iframe/click-jacking. Doomsday scenario isn't it? To do it you'll only need an hour or two and a sweet escape right away. Be aware my friend. Always check the shared "LINKS".
    "Stars and the Sun"


 

 

Similar Threads

  1. Twitter phishing attack spreads via Direct Messages !!!
    By INDRANIL in forum Spyware/Viruses
    Replies: 0
    Last Post: 07-10-2011, 09:07 PM
  2. Firefox 4 crack spreads trojan
    By leofelix in forum Spyware/Viruses
    Replies: 9
    Last Post: 08-15-2010, 04:28 AM
  3. Raymond.cc ads spreads malware?
    By Gabethebabe in forum Spyware/Viruses
    Replies: 20
    Last Post: 06-03-2010, 04:29 PM
  4. Email phishing attack spreads to Gmail and Yahoo
    By ripper in forum Spyware/Viruses
    Replies: 10
    Last Post: 10-10-2009, 11:18 PM

Tags for this Thread

All times are GMT +8. The time now is 09:03 AM.