Cybercriminals might be looking for a BlackHole exploit kit replacement

Nov 14, 2013 17:21 GMT  ·  By

Experts from Trend Micro have spotted an interesting malware distribution campaign which relies on bogus Microsoft Outlook emails that purport to carry a voice mail.

The emails, entitled “You received a voice mail,” contain a link, but they also carry an attachment. The spam run appears to be powered by the Cutwail botnet.

According to researchers, the links point to compromised websites that host code similar to the one seen in BlackHole exploit kit campaigns. This might indicate that cybercriminals are looking for an exploit kit that will take the place of BlackHole, but experts say they can’t be sure.

The attachment, on the other hand, hides a version of the Upatre Trojan, which downloads and installs ZeuS, the piece of malware that’s designed to steal banking information from infected computers.

Last week, Trend Micro warned that cybercriminals were using the Cutwail botnet and Upatre to distribute the notorious CryptoLocker ransomware.