Unsuspecting internauts are lured to websites hosting BlackHole Exploit Kit

Mar 19, 2013 12:50 GMT  ·  By

I have seen several reports about bogus CNN emails currently being used to spread malware. In each case, the story from the malicious emails is related to the newly-elected Pope Francis.

The emails identified by Spyware Sucks are entitled “Opinion: New pope tries to shake off the past – CNN.com.” They appear to come from [email protected] and they urge recipients to click on a link.

The notifications identified by Dynamoo’s Blog bear the subject “Opinion: New Pope Sued For Not Wearing Seat Belt In Popemobile - CNN.com” They appear to originate from the same email address and they lure victims to a malicious payload hosted on various servers from the US, South Africa, Hungary and Malaysia.

The variants discovered by security firm Symantec are entitled “Opinion: Can New-Pope Benedict be Sued for the [expletive] Abuse Cases?” and “Opinion: New Pope, Vatican officials sued over alleged [expletive] abuse!”

Symantec reports that the links from the bogus messages point to websites that host the BlackHole exploit kit, which probes the victims’ devices for software vulnerabilities in an attempt to push malware.

I advise you to always avoid emails such as these since cybercriminals will often create outrageous stories to trick internauts.

Fake CNN emails (3 Images)

Fake CNN emails
Fake CNN emailsFake CNN emails
Open gallery