IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Waledac spammers fake ‘bomb blast’ news story

Malware authors use geolocation technology to make the attack more convincing and persuade users to click on malicious links.

Security vendors have warned about a new social engineering attack that delivers fake news stories linking to malware.

The new attack tries to persuade users to watch a maliciously crafted fake Reuters video of a bomb attack' by downloading a version of Flash player, which is in reality malware.

The Waledac trojan had previously targeted users through Valentine's spam in February.

However, this attack appears to be particularly clever, as the malicious websites have been engineered using geolocation technology to report the location of the incident to correspond with the user's IP address. "Don't be fooled by the location. The site is running a couple of clever scripts," said Rik Ferguson of Trend Micro on the company's security blog.

"One of them will detect the location of your IP address and vary the location of the disaster accordingly. The other will vary the name of the downloaded file (news.exe, save.exe, run.exe etc.)"

He said it was further evidence that botnet authors were actively filling the void left behind by the fall of the Storm botnet and the McColo server takedown.

Security vendors Sophos and Websense also reported the attacks.

Featured Resources

The Total Economic Impact™ Of Turbonomic Application Resource Management for IBM Cloud® Paks

Business benefits and cost savings enabled by IBM Turbonomic Application Resource Management

Free Download

The Total Economic Impact™ of IBM Watson Assistant

Cost savings and business benefits enabled by Watson Assistant

Free Download

The field guide to application modernisation

Moving forward with your enterprise application portfolio

Free Download

AI for customer service

Discover the industry-leading AI platform that customers and employees want to use

Free Download

Recommended

The IT Pro Products of the Year 2021: The year’s best hardware and software
Hardware

The IT Pro Products of the Year 2021: The year’s best hardware and software

31 Dec 2021
Sophos Intercept X Advanced review: AI-powered protection
endpoint security

Sophos Intercept X Advanced review: AI-powered protection

30 Nov 2021
Hackers could use new Wslink malware in highly targeted cyber attacks
malware

Hackers could use new Wslink malware in highly targeted cyber attacks

1 Nov 2021
FBI raids Chinese POS business following cyber attack claims
malware

FBI raids Chinese POS business following cyber attack claims

27 Oct 2021

Most Popular

Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
The benefits of a hardware update for SMBs
Sponsored

The benefits of a hardware update for SMBs

2 Aug 2022