Cybercriminals rely on bogus wedding invitations to distribute a dangerous Trojan

Mar 28, 2013 07:11 GMT  ·  By

Cybercriminals resort to all sorts of techniques to trick users into installing malware and they never seem to run out of ideas. The latest malware-spreading emails invite recipients to a wedding.

ThreatTrack Security experts have come across emails entitled “Wedding Invite” or “Wedding Invitation,” which read something like this: “You are Cordially Invited to Celebrate the Our Wedding On Tuesday March the 29 at Four O’clock Followed by a Reception. Get Full Invitation Text”

Users who click on the link are served an archive file that’s hosted on a compromised website. The archive contains a file that appears to be a harmless Word document.

In reality, it’s an executable file that unleashes a new variant of Trojan.Win32.Kuluoz, a threat that’s capable of downloading other malicious elements such as fake antiviruses.

In the meantime, while the malware steps into play, a text document is opened to avoid raising any suspicion.

To protect yourself against such threats, make sure that your antivirus application is updated and fully functional. Also, avoid clicking on links that come in shady-looking emails.