Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

September 8th, 2011, 08:36 GMT · By Eduard Kovacs

Financial Services Company Impersonated in Malware Spreading Campaign

SHARE:

Adjust text size:


Spam message
Enlarge picture
The Automated Clearing House, a financial service offered by the U.S. electronic payments association NACHA, was impersonated in a campaign of spam messages sent out to unsuspecting users with the purpose of spreading malware.

The samples investigated by MalwareCity were pretty convincing, especially because they seemed to be sent from a legitimate NACHA email account.

After a quarterly report in which McAfee informed us on the record breaking minimum in spam campaigns, it looks like things took a wrong turn somewhere as a new wave of malicious operations has been witnessed in the past week.

This specific message, named “ACH Transfer Review,” informs the victim that a transaction has failed and that he needs to review the input data for the payment.

He is then asked to fill the application form attached to the email and send it back to the expeditor.

The attachment is represented by a zip file, which contains what seems to be a pdf document that needs to be reviewed by the recipient. On a closer look, the pdf file is actually an executable that installs a downloader on the soon-to-be infected computer. The downloader's purpose is to get other malware from the web and onto the computer.

A few moments later, the Zeus bot, also known as Trojan.Generic.6152125, is installed on the machine, closely monitoring all electronic financial transactions and sending out username and password information for a variety of services which might be of interest to the hackers.

Even though this online theft attempt looks like it really came from the payment association, Websense Security Labs gives us the real address from which the messages have been sent. The routing details from the message seem to come from a domain called “digitalskys.com”, the website of a wireless solutions company, probably used by the cybercriminals to mask their true identity.

TELL US WHAT YOU THINK:

1,437 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Test & Keep an iPhone 5 Spam Campaign

ShareSafe - Facebook Safe Sharing Application

Volume of Malware Increases According to McAfee's Second Quarter 2011 Report

Phishers Target Students in Spam Campaign

Fake Facebook Emails Lead to Pharma Spam

READER COMMENTS:


Comment #1 by: John on 08 Sep 2011, 21:42 UTC reply to this comment

Yikes!


Comment #2 by: Norman on 08 Sep 2011, 21:45 UTC reply to this comment

it should me mandatory for everyone above 50 to use linux :))

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM