On CBS MoneyWatch: 5 Things You Should Buy at Walmart
BNET Business Network:
BNET
TechRepublic
ZDNet

June 26th, 2009

Michael Jackson's death themed malware campaigns spreading

Posted by Dancho Danchev @ 11:56 am

Categories: Anti Virus, Botnets, Browsers, Hackers, Malware, Passwords, Phishing, Spam and Phishing, Web 2.0

Tags: Malware, Social Engineering, Spam, Michael Jackson, Malware Campaign, Dancho Danchev, Spyware, Adware & Malware, E-mail, Viruses And Worms, Security

The sudden death of Michael Jackson quickly opened a window of opportunity for cybercriminals to capitalize on.

With a malicious spam campaign, blackhat SEO search results poisoning which is serving scareware within the first 100 search results for Michael Jackson’s death, and an opportunistic participant in Zango adware’s network using typosquatting, malicious activity is prone to increase during the next couple of days.

Here are more details on the campaigns currently in circulation:

The malicious spam campaign is enticing users to visit a compromised web site (Beatz radio beatzradio.com.au) where the bogus Michael.Jackson.videos.scr screensaver is served.

A second, non-malicious spam campaign using a Michael Jackson theme is being spammed from legitimate emails in a desperate and amateur-ish attempt to harvest the emails of those who reply back - a practice which became obsolete with the time due to the much more sophisticated email harvesting techniques spammers have in a Web 2.0 world for instance.

Several of the blackhat SEO campaigns serving scareware with a low generic detection rate, are already popping-up within the first 100 search results at Google.

Based on historical performance by this Ukrainian group of cybercriminals, the number of keywords and phrases using Michal Jackson as a theme will inevitably increase during the weekend.

Excluding the several registered typosquatted domains offered for sale, one exception (michael-jackson-is-dead (dot) net) is promoting a “shocking video” which in reality is a Zango adware toolbar.

Mixing social engineering tactics with different traffic acquisition tactics such as a combination of potentially popular keywords/phrases, next to pushing the malicious content through spam is opportunistic cybercrime as usual. However, with the Web feeling the “Michael Jackson effect” — Twitter killing features and Google issuing anti-worm activity CAPTCHA messages for related searches — even a badly structured and executed malware campaign will succeed due to the huge anticipated traffic unless a little bit of extra common sense is in place.

Whether it’s bad news or good news, for cybercriminals it’s always news items to hijack and serve malicious content through.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 24 Talkback(s)
check that
*you* may have molested a child, but I certainly have never entertained such a wicked thought. (Read the rest)
Posted by: mithraigor@... Posted on: 07/06/09 You are currently: a Guest | | Terms of Use
Leave it to the scum of the world...  Confused by religion | 06/26/09
yep  Badgered | 06/26/09
Profit from his death is par for the course for those in the arts.  Bozzer | 06/28/09
hmm... true. (nt)  Badgered | 06/29/09
Comment true. Title Is Unfortunately Not Worth Reply.  Seamus O'Brog | 06/29/09
Genuinely mourning?  nizuse | 06/27/09
There's already a joke circulating...  MGP2 | 06/27/09
Ok I feared for the worst  nizuse | 06/27/09
mourning?  Bozzer | 06/28/09
It is pity that humans are so evil.  phatkat | 06/29/09
Will Advertizers realize that clicking an a link does NOT mean site visits?  No More Microsoft Software Ever! | 06/26/09
What in the blue hell.......  Budman o Riverside | 06/26/09
Reminds me of the Gaia blog here.  nizuse | 06/27/09
You have to ignore her...  MGP2 | 06/27/09
Note to self...  dropmeoff | 06/27/09
RE: Michael Jackson's death themed malware campaigns spreading  newsradio | 06/27/09
RE: Michael Jackson's death themed malware campaigns spreading  webmonkeydc | 06/27/09
RE: Michaels DEAD Body Photo & Murdered....  VONDRASHEK@... | 06/27/09
wow  mithraigor@... | 07/06/09
Luckily MJ fans not running Windows are safe  whisperycat | 06/28/09
Finally something I am going to miss all together...  mikifinaz1@... | 06/29/09
Finally  EmperorDarius | 06/30/09
Everybody has made mistake  koicakep | 07/02/09
check that  mithraigor@... | 07/06/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here