Malicious HP scan notifications target employees
Posted on 09.04.2013
Users are once again being targeted with fake notifications about a scanned document, but instead of attaching a malicious file to the email, malware peddlers have opted for including a link to a site serving malware:

The email's headers have been spoofed to make it look like the message was sent by a printer inside the victim's enterprise, and the fact that the crooks chose the HP brand is accidental - they could have just as easily have used - and have in the past - Xerox, Lexmark or any other popular brand of printers, scanners, or photocopiers.

This type of malicious spam is constantly being recycled by cyber crooks, and I can easily see why: if you are at work, and busy doing your job, there is a high possibility that you will open the email and click on the link / download the attachment without thinking twice about it because your attention is focused on other things.

"If you work in a business environment, you might well be used to receiving dull-looking emails from printers and scanners in your workplace containing attachments of the scan that the device has just completed," points out Graham Cluley, and malicious emails such as this one simply blend in.


Pen-testing drone searches for unsecured devices

You're sitting in an office, and you send a print job to the main office printer. You see or hear a drone flying outside your window. Next thing you know, the printer buzzes to life and, after spitting out your print job, it continues to work and presents you with more filled pages than you expected.

Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.

Daily digest

Receive a daily digest of the latest security news.

Fri, Oct 9th