Malicious emails appear to come from within the victim's organization

Oct 24, 2013 09:40 GMT  ·  By

In case you receive an email bearing the subject “Voice Message from Unknown,” be careful, since it’s likely part of a cybercriminal scheme designed to distribute a piece of malware.

Experts from MX Lab and Conrad Longmore of Dynamoo’s Blog have been analyzing the spam campaign.

The messages appear to come from an “Administrator” within the victim’s company and they read something like this:

“- – -Original Message- – - From: 785-553-4447 Sent: Wed, 23 Oct 2013 07:25:07 -0700 To: <caroline@victim_domain> Subject: Important: to all Employees”

The number in the “from” field, the date and the “subject” might be different from one email to the other. For instance, besides “Important: to all Employees,” experts have also spotted malicious notifications that contain the subject “Employees Only.”

The archive file attached to the emails appears to contain an audio file. However, in reality, it’s an executable that hides a Trojan.

Never open the attachment in such emails. If you already have, scan your computer with an antivirus to make sure it’s not infected. Since the version of the malware is new, it might be wise to re-scan the device after a few virus definition database updates.