Waledac worm sends no love to Valentine's Day spam victims

Cybercriminals behind the Waledac botnet are trying to capture more victims by using Valentine's Day-themed exploits, researchers from McAfee Avert Labs warned Monday.

Users are being spammed emails containing a link that when followed brings up a Valentines' Day-themed page with malicious executables. 

For example, one such page has a picture of two puppies holding a heart that says “Happy Valentine's Day.” The website reminds users that Valentine's Day is nearing and they should get their significant others a present. 

The site offers a “Valentine's Devkit” download to get started," but it actually is malware.

Micha Pekrul, author of an Avert Labs blog post on the attack, warned users not to click on the link in the spammed email, and also not to click on the executable contained on the website.

“This is a social-engineering trick to convince users to download the real threat," he wrote. "Don't click the link to the executable. Otherwise you will end up with malware."

This is not the first time cybercriminals behind the Waledac worm have used Valentines' Day as a means of tricking users.

In early January, PandaLabs researchers warned of a similar exploit. In that instance, spam arrived with the subject line: “love before Saint Valentine's day." If the user followed the link in the spam, they were taken to a page with a picture of 12 different hearts, above which read, “Guess, which one is for you.” If victims clicked, they downloaded the Waledac worm.

PandaLabs researchers said last month that once users are infected, their machines become part of a botnet that is used to send out other spam, and that worm spreads by sending the messages to all contacts in the victim's address book.
close

Next Article in News

Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.