Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 20th, 2011, 09:44 GMT · By

FBI Warns Businesses of Malicious CV Emails Carrying Banking Trojan

SHARE:

Adjust text size:


IC3 warns companies about malicious job applications
Enlarge picture
The Internet Crime Complaint Center (IC3), a joint project between the FBI and the National White Collar Crime Center (NW3C), has issued a warning that cybercriminals are responding to job ads with fake emails carrying trojans hidden as CVs.

In order to outline the seriousness of this threat, the center presents a case investigated by the FBI, in which a company infected in this manner ended up loosing $150,000.

The business in question posted an employment offer online and received an application via email with a CV attached.

However, the attachment actually contained a version of the Bredolab trojan, a piece of malware known to be part of pay-per-install schemes.

This particular variant was used as a distribution platform for ZeuS, a notorious and sophisticated banking trojan used to steal millions from consumers and companies alike.

The FBI says the fraudsters used ZeuS to steal the online banking credentials of the person authorized to make financial transactions for the company and used them to access the firm's bank account.

They then modified the account settings to allow wire transfers and sent money to Ukraine and other US banks.

According to data from security vendor SonicWALL, the resume spam campaign occurred in back in July 2010. A technical analysis shows the same file name as the one mentioned by the FBI.

The rogue CV is called Myresume.exe and bears a Word document icon in order to trick recipients, especially on systems where known file extensions are hidden by default.

"The FBI recommends that potential employers remain vigilant in opening the e-mails of perspective employees.

"Running a virus scan prior to opening any e-mail attachments may provide an added layer of security against this type of attack.

"The FBI also recommends that businesses use separate computer systems to conduct financial transactions," the IC3 writes in its intelligence note.

TELL US WHAT YOU THINK:

921 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


FBI Warns the Public About Work-At-Home Money Muling Scams

FBI Warns About the Scareware Threat

First Toolkit Resulting from ZeuS-SpyEye Merger Hits the Underground Market

Rogue Resume Emails Redirect to Scareware

New Wave of Zbot-Infected Emails

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM