Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

March 21st, 2011, 07:58 GMT · By

Japan Quake Email Spam Leads to Java Exploits

SHARE:

Adjust text size:


Japanese disaster exploited to spread adware
Enlarge picture
Security researchers from Kaspersky Lab warn that the wave of spam emails taking advantage of the disaster in Japan continues with a new campaign that leads users to Java exploits.

The latest spam run claims to link to a news article about the quake being the costliest disaster in the world's history.

However, Kaspersky Lab's Nicolas Brulez warns that the links lead to Java-based exploits that use the OpenConnection method to download malware.

The exploits are detected by Kaspersky's products as Downloader.Java.OpenConnection.dn and Downloader.Java.OpenConnection.do, and drop a malicious VBS script file.

The VBS's purpose is to download and install even more malicious applications on the infected computers, adware in particular.

"Once infected, the computer starts displaying localized ads," the researcher notes, but points out that "on one successful infection, we counted as many as five malicious executables being run, one DLL being registered as a service, and a lot of task scheduler job files being created."

Java OpenConnection-based malware has become very prevalent in recent months and variants of such threats are constantly showing up at the top of monthly attack statistics released by antivirus vendors.

It's also a well known fact that cyber criminals are exploiting major news, especially those about natural disasters and tragedies, to spread malware.

Because of this, people are strongly encouraged to get their news only from reputable sources and discard any unsolicited emails claiming to lead to news stories.

Keeping popular software like Java, Adobe Reader, Adobe Flash Player, and the operating system itself up to date can help prevent a lot of attacks, while using an updated and capable antivirus solution at all times is equally important.

Other attacks capitalizing on the Japan earthquake include relief scams, poisoned search results and social networking worms.

TELL US WHAT YOU THINK:

1,136 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Facebook Likejacking Scams Lure Users with Japanese Tsunami Videos

Searching for Japanese Earthquake Carries Malware Risk

Adware and Java Trojans Dominated the Web Threat Landscape in December

Trojan Distributed in New Mass Injection Attack via Java Downloader

READER COMMENTS:


Comment #1 by: akif on 27 Mar 2011, 09:22 UTC reply to this comment

FROM TURKEY- TO JAPAN.declare that we are very sad as the people of our prayers are with you all the turkey. get past all the people of Japan would like to wish

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM