Newsletter:

Skip Navigation LinksHome > News > Security > Faked CNN spam blitz pushes fake Flash

Faked CNN spam blitz pushes fake Flash

By INQUIRER Staff
8 August 2008 07:44AM
Tags: faked | cnn | spam | blitz | fake | flash

Bogus alerts purporting to be from CNN are luring victims to over 1,000 hacked websites pushing fake, malware-infested Flash Player software, Internet security watchdogs have warned.

Alerts pretending to have been sent from CNN are spam that lures wibblers to over 1,000 hacked websites.

The spam emails contain links to what are claimed to be CNN's Top 10 news stories and video clips.

However, clicking on any link launches a dialogue saying that the user has an obsolete version of Flash Player and needs to download an updated version, according to Sam Masiello, VP of MX Logic, a Denver security company.

MX Logic detected more than 160 million fake CNN spam messages transmitted within 48 hours earlier this week.

The dialogue goes into an endless loop if the user clicks the "Cancel" button to disallow the update, forcing victims to either kill their browser session or accept the download, he said.

If the user accepts the download of the fake Flash Player update, they don't get an updated version of that but instead receive a Trojan with any of several names, including Cbeplay.a, which then "phones home" to a malicious server to download and install yet more malware, according to Bulgarian security researcher Dancho Danchev.

On Tuesday, Danchev reported having discovered more than 1,000 hacked websites hosting the fake Flash Player malware.

Adobe is aware of the malware masquerading as a Flash Player update and it has warned users in a company security bog entry not to download updated versions of Adobe software from anywhere other than its own website.

theinquirer.net (c) 2008 Incisive Media

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Unified Communications Podcast Centre

TopTopics
(6917) -  microsoft
(6474) -  iinet
(6465) -  copyright
(6465) -  afact
(6349) -  internet
(5920) -  servers
(5920) -  mipi
(4082) -  phone
(4077) -  telstra
(3651) -  nvidia
(3330) -  broadband
(3274) -  nbn
(2430) -  avg
(1970) -  onecare
(1886) -  google