Spammers use Angelina, Britney gossip as lures

Cybercriminals are playing off the interest in celebrity gossip by sending email that promises erotic pictures of stars such as Angelina Jolie and Britney Spears but are instead sending a trojan, Panda Security researchers have found.

The junk emails have subjects such as “Naked Shakira Clip” and include a link with the text “Download and Watch.”  

If the user clicks the link, she will actually download a copy of the Agent.IMB trojan, which copies itself to the system under the name CbEvtSvc.exe. It then creates a service with the same name to run whenever the system is started up.

“We believe the trojan is identity theft malware,” Ryan Sherstobitoff, chief corporate evangelist of Panda Security told SCMagazineUS.com on Friday. “The trojan will steal passwords, banking logins and other private information. It's a trend toward financial fraud.”

This is another mechanism of social engineering, Sherstobitoff added.

“They entice the users to open up the email by putting in very compelling language to get a higher click rate to open it,” he said.

Sherstobitoff said he expected to see a variance of this email in the coming days. Two to three percent of the people who receive the email are clicking on the malicious link, enough to encourage more, similar spam.

“The scary part of this type of spam is if it [causes machines to become] part of a botnet,” Sherstobitoff said. “That's a trend we're seeing, too. Spammers are using popular topics people might be interested in and exploiting it, and turning personal computers into bots.”

The main message Sherstobitoff stressed is that more cybercriminals are using things people are interested in, like celebrities, to get them to open and activate malicious code.

“People know better,” he said, “but they'll click on these links because they want the shocking gossip.”

Sign up to our newsletters

More in News

CISPA moves forward, but rejected amendments frustrate privacy advocates

The amendments to the threat intelligence sharing bill would have tightened controls around the corporate release of personally identifiable information to three-letter agencies, including the NSA.

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.