On mySimon: Oprah's Favorite Things
BNET Business Network:
BNET
TechRepublic
ZDNet

April 28th, 2009

Swine flu email scams circulating

Posted by Dancho Danchev @ 7:47 am

Categories: Spam and Phishing

Tags: Search Engine Optimization, Outbreak, Flu, Cybercriminal, SARS, Cyberthreats, Spam, Dancho Danchev, E-mail, Search

Opportunistic scammers and spammers are actively exploiting the swine flu buzz across the web by spamvertising links to pharmaceutical scams, and bogus ‘Swine Flu Survival Guides’ using search engine optimization of typosquatted domains related to the outbreak.

The event-based social engineering campaign is similar to the recent fake ‘Conficker infection alerts‘, the bogus Conficker removal tools pushed through SEO practices, and the timely spam campaign serving malware as a fake Microsoft patch Tuesday message.

Strangely, the massive spam campaign doesn’t seem to be targeting the specific market segment since upon clicking on the links the users are directed to the ubiquitous Canadian Pharmacy scam. Based on previous experience with related campaigns, cybercriminals are prone to diversify the traffic acquisition tactics, so consider keeping yourself informed on the issue by using the right sources.

This isn’t the first time that viral outbreaks are being used by cybercriminals in order to increase the trust factor of a particular campaign. According to Trend Micro’s researcher Ivan Macalintal, a similar event-based spam campaign took place in 2003 in the wake of the SARS epidemic with the mass-mailing Coronex worm campaign using SARS related messages to spread.

The bottom line - don’t bargain with your health, and drive the cybercrime economy in between.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 6 Talkback(s)
The header
Recipient info masked for privacy, but here is the header:



Return-Path:

Received: from cdptpa-mxlb.mail.rr.com ([10.127.255.88])

... (Read the rest)
Posted by: b_jenkins Posted on: 07/13/09 You are currently: a Guest | | Terms of Use
Swine Worms..  Steve KTG | 04/28/09
RE: Swine flu email scams circulating  BGCP | 04/29/09
Will Ad Execs realize that clicking an a link does NOT mean site visits?  No More Microsoft Software Ever! | 06/26/09
Malware?  epcraig | 06/27/09
RE: Swine flu email scams circulating  b_jenkins | 07/13/09
The header  b_jenkins | 07/13/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More