Westpac spam serves trojan to hundreds of thousands of Aussies

By
Follow google news

Huge phishing campaign hits inboxes.

Trojan-laden phishing emails bearing the Westpac name have deluged hundreds of thousands of Australian inboxes this morning.

Westpac spam serves trojan to hundreds of thousands of Aussies

The trojan backdoor slipped past almost all anti-virus engines placing victims at heightened risk of infection.

Specific details of the malware or its method of obfuscation are not yet known. However Fortinet and DrWeb today classified the sample as W32/Kryptik.KZ!tr and BackDoor.Slym.1498 respectively.

The phishing emails instructed victims to run the trojan via Microsoft's Internet Explorer browser.

Fortinet described the malware as a remote backdoor trojan.

At least some of the phishing emails bear the attachment SecureMessage.zip and the sender address secure.mail@westpac.com.au.

Aussie outsourcer Mailguard reported the scam and shared samples with virus analysts.

"The payload still being defined, but it is has been sent in different variations," chief executive Craig McDonald said.

Mailguard blocked 126,000 of the emails sent at about 9am this morning in "pretty much one go", McDonald said.

That number spiked into many hundreds of thousands of emails as of the time of writing, service delivery director Anwar Ibrahim said.

"This is the biggest fast breaking email the tech guys can remember," Ibrahim said.

Almost 2000 unique IP addresses were logged sending the spam using a single filter, pointing to the United States, Peru and Australia in descending order.

The attacks appeared to use a shotgun-approach in choosing victims and were not targeted at a specific industry nor Westpac customers.

Users should be cautious opening any email attachment and those sent by unknown addresses. Banking websites should be accessed by entering the URL directly or through trusted search engines, and never via unsolicited links within emails.

The malware's SHA256: 5450eea52c6e04bcae760c6181c6c79198daa6e969fca406e0f9dd3b49212d48

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

NSW gov contractor uploaded Excel spreadsheet of flood victims' data to ChatGPT

NSW gov contractor uploaded Excel spreadsheet of flood victims' data to ChatGPT

Age verification IDs taken in Discord data breach

Age verification IDs taken in Discord data breach

Microsoft to kill local account workarounds in Windows 11 preview builds

Microsoft to kill local account workarounds in Windows 11 preview builds

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

Log In

  |  Forgot your password?