The notifications purport to come from Changzhou XNE Group

Nov 12, 2013 11:01 GMT  ·  By

Security experts from Cisco warn users about bogus “Payment Copy” emails designed by cybercriminals to distribute a piece of malware onto the devices of unsuspecting recipients.

The emails, which appear to come from the “Accounts Department” of a company called the Changzhou XNE Group, read something like this:

“Dear Sir, I've been waiting for your reply since last week after finally scheduled payment of the balance of your bank account. I attach back the payment copy to you. Please confirm your bank and proceed with shipping this week. We are waiting for confirmation of your payment.”

The messages come with an attachment named “SCAN COPY.rar.” The archive hides a piece of malware.

Users are advised to be on the lookout for such emails. If you come across these notifications in your inbox, delete them at once.

If you’ve already downloaded and executed the attachment, regularly scan your computer with an updated antivirus solution. The malware might not be identified right away, but it will surely be detected after a few virus definition database updates.