Spammers bypass filters with SWF file redirects

Spammers are stepping up their use of Shockwave Flash (SWF) file redirects to avoid detection, security researchers said this week.

Alex Eckelberry, president of Sunbelt Software, a security software provider, said the SWF files embed a barely visible box that pushes the installment of a trojan.

“Previously what they have done was have a direct link to the trojan,” Eckelberry told SCMagazineUS.com on Thursday. “But because those URLs are now blacklisted so rapidly, the spammers needed a way to bypass the filters. They use these little SWF files.”

Like other spammer ploys, the purpose of the SWF redirect is to trick users into installing malicious software.

“In many instances the malicious software that is installed will be fake anti-spyware or fake anti-virus software that has infected the user, tells them they are infected, and suggests they pay for the full version of the product to clean their computer,” Randy Abrams, director of technical education at ESET, a threat protection provider, told SCMagazineUS.com.

Adam O'Donnell, director of emerging technologies at Cloudmark, a message security company, said Shockwave works because filters are not used to it.

“There are just not as many analysis tools as there are for Javascript or HTML, for example,” he said. “I will be interested in what comes next after Shockwave.”

More in News

Twitter begins rollout of two-factor authentication to limit account takeovers

Following a series of high-profile Twitter account hijacks, the microblogging service finally has delivered two-factor authentication.

Commission offers suggestions for stemming online spy threat from China

The 100-page report mostly addresses alleged Chinese cyber espionage operations, and suggests it's time for U.S. government agencies and corporations to consider more proactive approaches, possibly including hack-backs.

Researchers link "Sunshop" group to recent espionage attacks

The IE exploit was most recently used in watering hole attacks directed at the U.S. Department of Labor website.