The attachment contains a Trojan identified as Backdr-HE

Aug 20, 2012 13:49 GMT  ·  By

Emails purporting to originate from Royal Mail Group Ltd have been found to contain a malicious attachment.

Experts from security firm Sophos are warning internauts to be on the lookout for emails entitled Royal Mail Shipping Advisory. Although they carry the official Royal Mail logo and they appear to come from a royalmail.com email address, they’re fake.

The attachment they carry hides an executable file – royal_mail_shipping.exe – identified as Troj/Backdr-HE.

Here’s what the emails read:

Royal Mail Group Shipment Advisory

The following 1 piece(s) have been sent via Royal Mail on Mon, 20 Aug 2012 10:39:54

SHIPMENT CONTENTS: Documents SHIPPER REFERENCE: PLEASE REFER TO ATTACHED FILE ADDITIONAL MESSAGE FROM SHIPPER: PLEASE REFER TO ATTACHED GILE Royal Mail Group Ltd 2012. All rights reserved.

While these types of schemes probably record a lower rate of success, there may still be some users who aren’t aware of the classic scams and open the attachments without giving it a second thought.