Spam now arriving with virus attached
By Rene Millman,
Spam emails are flooding inboxes not only trying to sell users questionable pharmaceutical products but are also carrying viruses.
Research from email managed service provider MessageLabs has uncovered convergence between spam and viruses through intercepted cyber-criminal activity. The company said that it had intercepted emails that are spam and contain a virus.
The first such emails began trickling in on 14 April, according to the company and these emails mark the latest phase in activity from the Storm worm.
The latest variant of the worm, not only contained pump-and-dump spam but also links to new malware being hosted on websites under the control of the attackers. Purporting to be a screensaver, the malware then drops the Zhelatin MeSpam engine onto the compromised computer. Until now, new versions of Zhelatin have been distributed via botnets to create larger botnets for the purposes of spamming.
Experts said the latest attacks mean that spam should no longer be considered a nuisance but something more deadlier.
"Why use two emails when just one will do?" said Mark Sunner, chief security analyst at MessageLabs. "Now we are seeing the bad guys layer on the threats - as if it's not enough to just scam someone and fill their inbox with junk email, why not also infect and take control of their computer at the same time? These latest techniques are part of a new boldness being shown by certain criminal gangs we are tracking."
A report from the company also found that in April, the global ratio of spam in email traffic from new and unknown bad sources was 76.1 per cent (1 in 13.1), an increase of 0.9 per cent on the previous month. The ratio of viruses in email traffic from new and previously unknown bad sources destined for valid recipients was 1 in 145.5 (0.69 per cent), a decrease of 0.003 per cent since March.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Who to trust after the VeriSign hack?
Davey Winder questions what data was stolen from VeriSign and wonders why the company hasn't been more forthcoming.
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
- Are the cookie laws crumbling already?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Will someone rid me of these troublesome Macs?
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- Head to Head: Office 2010 vs Open Office 3.1
- Nokia Lumia 710 review
- Virgin 100Mbps rollout 'ahead of schedule'
- BT considering Ofcom price cap appeal
- A data shock warning for Orange customers
- Cisco announces 40GbE and 100GbE switching upgrades
- T-Mobile announces 'UK's first' fully unlimited deals
- BT announces FTTP 'on demand'
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





