Newsletter:

Skip Navigation LinksHome > News > Security > Beware of new "piggyback spam" campaign

Beware of new "piggyback spam" campaign

By Negar Salek
2 July 2007 01:54PM
Tags: beware | piggyback | spam | technique

"Piggyback spam" is the lastest technique to lure users into opening a malicous file in an attempt to extend botnet networks, warns security vendor Marshal.

A new type of spam campaign is circulating around the globe - loaded with links to malicious files and the intension of building botnets - warns security vendor Marshal.

The campaign labelled ‘piggyback’ spam” is embedded with URL links that are completely unrelated to the spam being advertised and instead opens up a file rather than a website, according to Bradley Anstis, director of product management at Marshal.

“The link is not integral to the main message instead the links are inserted in odd places and essentially hitch a ride or “piggyback’ on otherwise normal spam messages,” said Anstis.

If users click on a link they are prompted to download a file, which, if executed, will lead to further malware such as key logging programs or spambots being installed onto their PCs. Anstis advised users that they should not save or download the file at any means.

Furthermore, Anstis said the spam was discovered about two weeks ago is targeted towards the US market place but is spreading around the world and increasing.

Researchers at Marshal’s security TRACE team said the piggyback spam may be an attempt by botnet syndicates to increase the size of their spam botnets and spread malware.

“They are trying to kill two birds with one stone hoping some users will click on the link and start a chain of events that ends up with the users PC being part of their botnet,” said Anstis.

According to Marshal, Botnets now perform multiple sophisticated tasks, including sending spam, performing distributed denial of service attacks (DDOS), detecting and disabling anti-virus software and detecting and removing rival spambots from competing botnet syndicates.

   


Ads by Google




Product Reviews

Star Rating
Lumension Security's PatchLink Scan is a fairly robust vulnerability scanner.
Star Rating
The Rapid7 NeXpose 4.6 appliance is a feature-packed vulnerability assessment and risk analysis tool that...
Star Rating
If we had to describe Core Impact in just a few words we would have to say: serious vulnerability and...
Star Rating
The GFi LANguard Network Security Scanner focuses into three areas of network security scanning.
Star Rating
BigFix Enterprise Suite (BES) 7 is a series of client server and web-based components designed to assist with...
TopTopics
(3561) -  apple
(2442) -  market
(2415) -  microsoft
(2387) -  iphone
(2346) -  online
(2052) -  telstra
(2028) -  google
(1993) -  windows
(1657) -  broadband
(1271) -  mobile
(972) -  silverlight
(950) -  smartphone
(847) -  computing
(833) -  software
(829) -  government