Spamvertised American Airlines themed emails lead to Black Hole exploit kit


By Dancho Danchev

American Airlines customers, watch where you click! Cybercriminals are currently spamvertising millions of emails impersonating the company in an attempt to trick end and corporate users into clicking on the malicious links found in the spamvertised email.

Upon execution, the campaign redirects users to a Black Hole exploit kit landing URL, where client-side exploits are served against outdated third-party software and browser plugins.

More details:

Continue reading

Spamvertised ‘DHL Express Parcel Tracking Notification’ emails serving malware


By Dancho Danchev

Remember the “Spamvertised ‘DHL Package delivery report’ emails serving malware” campaign profiled earlier this month?

It seems that another cybercrime gang has started impersonating DHL in an attempt to serve malware to the millions of spamvertised end and corporate users.

More details:

Continue reading

Spamvertised ‘Confirm PayPal account” notifications lead to phishing sites


By Dancho Danchev

PayPay users, beware! Phishers have just started spamvertising hundreds of thousands of legitimately-looking PayPal themed emails, in an attempt to trick users into entering their accounting data on the fraudulent web site linked in the emails.

More details:

Continue reading

Spamvertised ‘Your UPS delivery tracking’ emails serving client-side exploits and malware


By Dancho Danchev

Cybercriminals are currently spamvertising millions of emails impersonating United Parcel Service (UPS) in an attempt to trick end and corporate users into clicking on exploits and malware serving links found in the malicious emails. What exploits are they using? How widespread is the campaign? Is it an isolated incident, or is the campaign linked to more malicious activity?

More details:

Continue reading

Spamvertised ‘Your Paypal Ebay.com payment’ emails serving client-side exploits and malware


By Dancho Danchev

Remember the ‘Your Amazon.com order confirmation’ client-side exploits and malware serving campaign which I profiled earlier this week?

It appears that the gang behind it is back with another campaign, this time impersonating PayPal. For the time being, another round consisting of millions of malicious emails is circulating in the wild, enticing end and corporate users into clicking on malicious links found in the emails.

More details:

Continue reading

Spamvertised ‘Your Amazon.com order confirmation’ emails serving client-side exploits and malware


By Dancho Danchev

Everyone uses Amazon! At least that’s what the cybercriminals are hoping.  Cybercriminals are currently spamvertising millions of emails impersonating Amazon.com Inc. in an attempt to trick end and corporate users into clicking on the malicious links found in the emails.

More details:

Continue reading

Spamvertised ‘DHL Package delivery report’ emails serving malware


By Dancho Danchev

Cybercriminals are currently spamvertising millions of emails impersonating DHL in an attempt trick end and corporate users into downloading and executing the malicious .zip file attached to the emails.

More details:

Continue reading

Spamvertised ‘UPS Delivery Notification’ emails serving client-side exploits and malware


By Dancho Danchev

Think you received a package? Think again. Cybercriminals are currently spamvertising millions of emails impersonating UPS (United Parcel Service) in an attempt to trick users into downloading the viewing the malicious .html attachment.

More details:

Continue reading

‘Windstream bill’ themed emails serving client-side exploits and malware


By Dancho Danchev

Cybercriminals are currently spamvertising millions of emails impersonating the Windstream Corporation, in an attempt to trick end and corporate users into clicking on links found in the malicious email.

Upon clicking on the links hosted on compromised web sites, users are exposed to client-side exploits served by the BlackHole web malware exploitation kit.

More details:

Continue reading

Pop-ups at popular torrent trackers serving W32/Casonline adware


By Dancho Danchev

Everyone knows that there’s no such thing as free lunch. The same goes for freely distributed pirated content online.

Recently, Webroot decided to sample malicious activity within some of the most popular Eastern European torrent trackers, based in Bulgaria, Ukraine, and Romania for starters. The results? Countless backdoored key generators and cracks for popular games and software, and most interestingly, monetization of the huge traffic by delivering pop-ups promoting the ubiquitous W32/Casonline adware, which in case you remember was recently spamvertised to millions of end and corporate users.

More details:

Continue reading