Sophos tap into phone tapping spam

By
Follow google news

Sophos is warning users of a tricky new spam message containing an MP3 file attachment of what is claimed to be a recording of the user’s personal phone conversations.

Sophos tap into phone tapping spam
The security vendor said the attachment actually contains the Troj/Dorf-AH Trojan horse, an executable program that installs malware. Furthermore, the sender claims it’s a "detective" who will reveal who has paid for the phone tapping at a later date, but attempts to persuade its victims to open the attachment and listen to the recording.

The email reads: “I am working in a private detective agency. I can't say my name now. I want to warn you that I'm going to overhear your telephone line. Do you want to know who is the payer? Wait for my next message.

"P.S. I'm sure, you don't believe me. But i think the record of your yesterday's conversation will assure you that everything is real."

According to Graham Cluley, senior technology consultant at Sophos: "It's a case of from defective to detective for this attack. The first spam-run of this Trojan horse failed for the malware authors because they made fundamental mistakes in their code. Now their emails are capable of infecting the unwary, while posing as a private investigator."

Sophos experts note that a hacking gang has been making different attempts to infect people with this ruse for a couple of weeks, however initial attempts failed to work properly.

"It may seem hard to believe that anyone would fall for a trick like this, but it wouldn't be a surprise if people tried to run the attachment just out of curiosity,” Cluley said.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Health and Aged Care CISO retires

Health and Aged Care CISO retires

Log In

  |  Forgot your password?