Bogus Skype ‘Password successfully changed’ notifications lead to malware


By Dancho Danchev

Skype users, beware!

Cybercriminals are currently spamvertising millions of emails impersonating Skype, in an attempt to trick Skype users that their password has been successfully changed, and that in order to view their call history and change their account settings, they would need to execute the malicious attachment found in the emails.

More details:

Screenshot of the spamvertised email:

Detection rate for the malicious attachment: MD5: 0e78d3704332c59b619f872fd6d33d25 – detected by 32 out of 43 antivirus scanners as Trojan-Downloader.Win32.Andromeda.qw. Upon execution, the malware opens a backdoor allowing the cybercriminals behind the campaign complete access to the affected user’s host.

We’ve already seen the same MD5 used in the recently profiled “‘Your UPS Invoice is Ready’ themed emails serve malware” campaign. Clearly, they’re both launched by the same cybercriminal/gang of cybercriminals.

Webroot SecureAnywhere users are proactively protected from this threat.

You can find more about Dancho Danchev at his LinkedIn Profile. You can also follow him on  Twitter.

2 thoughts on “Bogus Skype ‘Password successfully changed’ notifications lead to malware

  1. Pingback: Προσοχή Spam email αναφέρει ότι ο κωδικός του Skype σας άλλαξε

  2. Pingback: Indagadores |Seguridad informatica |Seguridad en internet » Correo spam afirma cambiado su contraseña de Skype, conduce a la infección de malware

Join the Conversation

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s