Trojan preys on victims fearful of missing a FedEx delivery

Share this article:

Researchers are noticing an uptick in trojan-laced spam designed to look like it is a delivery receipt from FedEx.

Symantec's Shunichi Imano said in a Tuesday blog post that the security company is witnessing a rise in the spread of Smoaler, an information-stealing trojan first detected in 2011.

The malware makes its way to victims through emails that appear to be from FedEx. The emails read, “Dear Customer, your parcel has arrived at the post office… Our courier was unable to deliver the parcel to you.”

The recipient is then directed to go to their nearest FedEx location to claim their package, after following a link to print their receipt. Instead, victims that follow the link download a zip file, called “PostalReceipt.zip,” which contains the malicious executable. Symantec can confirm that the spam was sent at least three days last week – on Monday, Friday and Saturday, Imano said.

“All the fake FedEx emails delivering this malware are almost identical except for the order numbers and the website the zip file is hosted on,” Imano wrote. “One sign of laziness, or perhaps an oversight on the part of the malware author, is a consistent order date."

The global courier posted a notice on its website, saying it has received reports of an increase in fraudulent emails claiming to come from FedEx.

Smoaler is merely the payload of a tried-and-true method: Online fraudsters prefer sending phishing emails that force their victims to believe they have to take immediate action.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Florida Supreme Court rules warrants a must for real-time cell location tracking

Florida Supreme Court rules warrants a must for ...

The Florida Supreme Court put the kibosh on warrantless real-time tracking using location data obtained from cell phone providers.

Modular malware for OS X includes backdoor, keylogger components

Modular malware for OS X includes backdoor, keylogger ...

The modular malware was named "Ventir," by researchers at Kaspersky.

Fake Dropbox login page nabs credentials, is hosted on Dropbox

Fake Dropbox login page nabs credentials, is hosted ...

Symantec researchers received a phishing email linking recipients to a fake Dropbox login page that is hosted on Dropbox's user content domain and served over SSL.