Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

May 6th, 2010, 13:54 GMT · By

Spam Emails Masquerade as Adobe Update Notifications

SHARE:

Adjust text size:


Email spammers use Adobe update lure to trick users into visiting malicious links
Enlarge picture
Adobe warns that a spam campaign abusing its name and falsely notifying users about security updates for Adobe Reader and Acrobat is currently making the rounds. The rogue emails cite a real vulnerability and encourage users to download malware disguised as a security update.

In recent years, widespread Adobe products, like Reader or Flash Player, have been a constant source of high risk remote code execution vulnerabilities, many of which released as zero-day and actively exploited in the wild before seeing a patch. Such incidents have attracted so much media attention and public interest that it's understandable why cybercriminals would want to profit from them.

This latest email-based malware distribution campaign warns users about a vulnerability identified as CVE-2010-0193 in MITRE's Common Vulnerabilities and Exposures (CVE) database. The bug was publicly disclosed and addressed by Adobe on April 13 as part of its quarterly update cycle.

The emails instruct users to download an executable file named adbp932b.exe, which is in fact a variant of a backdoor known as Poison or PoisonIvy, depending on what AV vendor you ask. At the time of writing this article, 19 out of the 40 antivirus engines on VirusTotal detected this file as malicious.

The fake emails are signed by a made up Adobe employee named James Kitchin, of a similarly fictitious "Adobe Risk Management" team. "Please be aware that these emails have not been sent by Adobe or on Adobe's behalf. Customers should not click on any links, or open or download any attachments contained in any of these emails. Customers who subscribe to the Adobe Security Notification Service will receive email notifications that ONLY point to security advisories or security bulletins on the adobe.com domain [...], and that NEVER link directly to an executable for a product security update or contain attachments that must be opened," Adobe's Wendy Poland explains on the Product Security Incident Response Team (PSIRT) blog.

TELL US WHAT YOU THINK:

3,136 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Email Spam Run Impersonates Twitter Support Staff

Zbot Spam Claims Email Accounts Were Deactivated

Fake Windows Security Bulletin Notifications Link to Malware

Herbal King Ringleader Fined in Australia

Payment Request Spam Carries Malicious Attachments

READER COMMENTS:


Comment #1 by: carl greeno on 22 May 2010, 14:23 UTC reply to this comment

This article is so TRUE, I have already had my home pc CRASH, because of this malware, it not only slowed my pc down, it killed it. I am in process of reformatting it now. Beware of this Adobe masqarader.

Carl Greeno

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM