Syria bombing phishing emails serve exploits

By
Follow google news

Reader and Java targeted.

Malicious emails disguised as breaking news of a US bombing of Syria are making the rounds online.

Syria bombing phishing emails serve exploits

Kaspersky senior anti-virus researcher Roel Schouwenberg said the phishing campaign contained shortened links leading to an exploit kit that targeted vulnerable Adobe Reader and Java software.

More often, however, phishers prefer to use the “more reliable” Java exploits, he wrote.

Once users click malicious links in the fake CNN emails, they're led to the exploit kit, which downloads a trojan capable of distributing other malware on compromised machines. 

“If the US do[es] decide in favor of military action against Syria, we can expect a lot more Syria-themed malicious emails,” Schouwenberg warned.

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Supply chain attack hits 100 million-download Axios npm package

Supply chain attack hits 100 million-download Axios npm package

APRA pulls data submission system after security pentest

APRA pulls data submission system after security pentest

NAB is co-designing a SIEM with Databricks

NAB is co-designing a SIEM with Databricks

WA local gov entity lost $350,000 in phishing attack

WA local gov entity lost $350,000 in phishing attack

Log In

  |  Forgot your password?