Phishers use compromised websites from China to host their malicious webpages

Oct 24, 2012 19:41 GMT  ·  By

Lloyds TSB customers should be on the lookout these days for two particular phishing emails. One of them is entitled “Error on your account” and the other one “Account payment review notification.”

“We have encountered a generic error on our database server which compromised some of our customers account due to the circumstance of the error. We implore you to make sure your account was not compromised due to this error. Kindly verify your information for safety purpose,” the first one reads.

The second one looks something like this: “You Have An Incoming Payment. Payment Cannot reflect due to difficulties in verifying your Account. The payment can be delayed for a variety of reasons. For example submitting invalid records or applying after the deadline. Click here to verify your account in other for us to credit your account immediately.”

In both cases, users who take the bait and click on the links are directed to compromised websites that host cleverly designed fake Lloyds TSB webpages.

At the time of writing, the hijacked sites’ owners – one of the sites belongs to an educational institution from China and the other one is a Ukrainian site – had removed the phishing pages.

However, internauts must still be cautious when receiving such messages since the cybercriminals can easily hijack other websites and resume their operation.