The various spam campaigns leading to Blackhole
Posted on 14.09.2012
Bookmark and Share
At any given time, there is a considerable number of email spam campaigns that ultimately lead users to pages hosting exploit kits - more often then not the extremely popular Blackhole exploit kit.

Websense researchers warn about the ones that are currently hitting inboxes around the world: the first one takes the form of a voice mail notification from Microsoft Exchange servers, the second one poses as a ADP invoice reminder, the third one mimics a FDIC notification claiming the users' wire transfer ability was suspended, and the fourth one is a bogus thank you note that tries to trick the recipients into believing that they have somehow signed up for a premium service of accountingWEB.com (click on the screenshot to enlarge it):


"A lot of the email messages pretend to come from trusted sources (well-known establishments, or the victim's own infrastructure), and try to catch the reader off-guard by focusing their attention on something urgent, like money matters," the researchers point out.

The landing pages are different in all the attacks, but some look like they could have been set up since the recent advent of the new version of the Blackhole exploit kit.






Spotlight

Attackers use reflection techniques for larger DDoS attacks

Posted on 17 April 2014.  |  Instead of using a network of zombie computers, newer DDoS toolkits abuse Internet protocols that are available on open or vulnerable servers and devices. This approach can lead to the Internet becoming a ready-to-use botnet for malicious actors.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Apr 18th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //