Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Spam Reports

January 30th, 2012, 15:12 GMT · By

Drive-by Spam Emails Infect Computers Without Links or Attachments

SHARE:

Adjust text size:

eleven logo
Enlarge picture
Up until now, most malicious emails that were designed to spread a virus or a Trojan required some user interaction, but new variants discovered by German security experts automatically infect a device when the email is opened in the email client.

Many security savvy users know that, as long as you don’t click on a link or open an attachment that comes with a suspicious looking email, you should be safe.

Unfortunately, this is about to change since researchers from eleven Research Team came across this improved variant which consists of HTML emails that contain a JavaScript designed to automatically download malware when the message is opened.

This malicious technique is similar to the one utilized in drive-by downloads in which compromised websites are altered to serve malevolent elements to users that visit them.

This specific scenario involves emails that come from a spoofed Federal Deposit Insurance Corporation (FDIC) address, informing the recipient of a banking security update.

“Your Wire and ACH transactions have been temporarily suspended. Please open the attached document for more information,” reads the email.

The problem is that the attachment automatically loads inside the email, unleashing whatever may be hiding in it.

The good news is that there are a couple of safety measures that can be applied to mitigate these threats.

First of all, you must make sure that the email account is properly protected against spam and malware with all the filters updated.

Secondly, these schemes only work if the recipient’s email account is configured to display HTML content. By setting the account to display emails in pure-text format only, the HTML isn’t loaded and as long as the actual attachment remains unopened, the user’s computer remains unharmed.
FILED UNDER:
spam
malware
advisory


2,400 hits · 2 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Tumblr Offers Free iPhone 5 in Survey Scam

DMARC Anti-Phishing Standard to Protect Email Accounts

Cidrex Trojan Breaks CAPTCHA to Create Yahoo! Email Account

Facebook Avenges Scam Victims, Sues ClickJacking Suspect

MSNBC Work at Home News Report Used in Scam

READER COMMENTS:


Comment #1 by: An0n on 31 Jan 2012, 05:51 UTC reply to this comment

Any how many "joke" e-mails will come through correctly to the end user with no html?


Comment #2 by: Eddie Chipmeister on 31 Jan 2012, 15:31 UTC reply to this comment

What about auto-preview with applications such as Outlook ? Is this enough to trigger the javascript. I would guess at yes. !!

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM