New BlackHole email campaign found

Share this article:

Attackers are delivering the popular crimeware kit BlackHole through “urgent” messages designed to look like emails from financial institutions and well-known companies like LinkedIn, Facebook and American Airlines. 

The emails include links to compromised sites where vulnerabilities in various operating systems, including Android and Windows, are exploited, according to Paras Gupta, a McAfee researcher who published a blog post Wednesday on the spam campaigns.

Notifications purporting to be about bills, pending wire transfers, completed orders and unread messages on social networking sites are among the email subject lines used to lure victims.

The malicious links often end in “/random_word.html” or “/random_word.php,” and the emails' unsubscribe links are usually missing or have been replaced with malicious URLs, Gupta said.

Share this article:
close

Next Article in News

Sign up to our newsletters

More in News

Instagram iOS and Android apps vulnerable to session hijacking

Two researchers wrote about the Instagram app for iOS and Android is vulnerable to session hijacking because both send unsecured information through HTTP.

Report: Hackers stole data from Israeli defense firms

A report by Brian Krebs detailed the intrusions, which occurred between Oct. 2011 and Aug. 2012.

Neverquest trojan targets regional banks in Japan

Symantec researchers found a new variant of the banking trojan.