The Trojan downloads other threats onto infected systems

Dec 20, 2013 10:49 GMT  ·  By

On Thursday, researchers from Trend Micro revealed that cybercriminals had been using airline spam to distribute the Kuluoz malware. Now, MX Lab experts say that the same threat is also distributed with the aid of fake Adobe license emails.

The malicious emails have subject lines such as “Download your adobe software,” “Download your license key,” “Thank you for your order” or “Your order is processed.”

The emails are similar. They usually read something like, “Hello. Thank you for buying Creative Suite 6 Master Collection software. Your Adobe License key is in attached document below. Adobe Systems Incorporated.”

However, it’s worth pointing out that the name of the product can also be Director 11.5, Adobe Connect or other Adobe software.

The file attached to the notifications is not an Adobe product license, but a variant of the Kuluoz Trojan. Once it infects a computer, Kuluoz downloads other malicious elements such as ZeroAccess and fake antiviruses.