Cancer scare hoax email hits thousands

Sick message could plant virus on computer instead

Hacking

Thousands of email users have been sent a hoax message telling them they have cancer, the National Institute for Health and Care Excellence (NICE) has warned. The email marks a new low in spammers' tactics.

The email with the header "important blood analysis result", tells people that NICE has been sent a sample of their blood for further research.

Advertisement - Article continues below

The health watchdog said the contents of the email are likely to be distressing and have reported the incident to the police. Since the outbreak of the email hoax, NICE has been deluged by calls from worried individuals over the email.

The scam email, with the subject line "Important blood analysis result" tells recipients that NICE has been sent a sample of the recipient's blood for analysis.

"During the complete blood count (CBC) we have revealed that white blood cells is very low, and unfortunately we have a suspicion of a cancer," the sick message reads.

The message then asks the user to open an attachment claiming to be the test results. However, asking users to download and open attachments is a common way for for cybercriminals to plant viruses and malware on a victim's computer.

Sir Andrew Dillon, NICE Chief Executive: "A spam email purporting to come from NICE is being sent to members of the public regarding cancer test results.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"This email is likely to cause distress to recipients since it advises that test results' indicate they may have cancer. This malicious email is not from NICE and we are currently investigating its origin. We take this matter very seriously and have reported it to the police."

NICE advised people who receive the email to immediately delete it without opening in and not to click on any links within the email either.

UPDATE: Email verified as containing Zeus malware

An IT security firm had confirmed that the scam email purporting to be from Nice actually harbours the Zeus malware.

Fred Touchette, senior security analyst for AppRiver said that the attachment is a malicious zip file.

"If the attachment is unzipped and executed the user may see a quick error window pop up and then disappear on their screen," said Touchette.

"What they won't see is the downloader then taking control of their PC. It immediately begins checking to see if it is being analysed, by making long sleep calls, and checking to see if it is running virtually or in a debugger."

Advertisement - Article continues below

Touchette said that the malware also makes several duplicate instances of itself just in case someone was attempting to shut down the original process.

"Next it begins to steal browser cookies and MS Outlook passwords from the system registry. The malware in turn posts this data to a server at 69.76.179.74 with the command /ppp/ta.php, and punches a hole in the firewall to listen for further commands on UDP ports 7263 and 4400."

He added that this is all very common behaviour for the Zeus family of malware which is still very common in today's attacks. 

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/mobile/mobile-security/355889/parachute-introduces-superlock-feature
mobile security

Parachute's Superlock feature keeps your phone recording in an emergency

2 Jun 2020
Visit/security/encryption/355820/k2view-innovates-in-data-management-with-new-encryption-patent
encryption

K2View innovates in data management with new encryption patent

28 May 2020
Visit/software/business-software/355649/safesend-email-security-for-outlook-review-a-great-solution-for
business software

SafeSend Email Security for Outlook review: A great solution for security-conscious SMBs

14 May 2020
Visit/software/video-conferencing/355410/zoom-50-adds-256-bit-encryption-and-ui-refresh
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020

Most Popular

Visit/operating-systems/ios/355935/apple-confirms-serious-bugs-in-ios-135
iOS

Apple confirms serious bugs in iOS 13.5

4 Jun 2020
Visit/mobile/5g/355911/the-uk-pivots-to-japan-for-5g-equipment
5G

The UK looks to Japan and South Korea for 5G equipment

4 Jun 2020
Visit/security/ransomware/355945/new-ransomware-uses-java-to-target-software-organisations
ransomware

Tycoon ransomware discovered using Java image files to target software firms

5 Jun 2020