All the latest UK technology news, reviews and analysis

iPhone scammers start digging for gold

by Shaun Nichols

03 Jul 2007

Be the first to comment

  • Tweet this
Apple iPhone
An email scam is luring users with the promise of a free iPhone

Online criminals have wasted no time in exploiting Friday's much-hyped launch of the iPhone

The Sans Internet Storm Centre has warned of an email scam that lures users with the promise of a free iPhone. 

Recipients who click on the link in the message are guided to a webpage that attempts to exploit several known flaws in Microsoft's Internet Explorer browser to recruit the victim to a botnet.

A second attack uses a mixture of social engineering, malware and cross-site scripting to defraud victims.

The attack is launched when a user visits a specially crafted web page that attempts to exploit a number of previously disclosed vulnerabilities in Internet Explorer 6 and 7 to install a Trojan application. 

The Trojan activates every time the user visits Yahoo.com or Google.com, at which point a pop-up is launched advertising a site named iPhone.com. 

Normally, www.iphone.com will redirect to Apple's iPhone page, but the Trojan spoofs the iPhone.com domain name and directs users to a fake retail site claiming to be iphone.com and using Apple's logo and iPhone images. 

After filling out the fake order forms, users are instructed to send payment via wire transfer to an address in Latvia in order to receive the iPhone.

Eric Sites, chief technology officer at Sunbelt Software, urged users to install the latest security updates for their browser and operating system, and use firewall and antivirus software. 

The attack currently targets Internet Explorer, but Thomas said that Firefox users should also be vigilant, as the group believed to be behind the attacks has used Firefox exploits in the past.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

26%

1%

12%

61%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

X2 PMO lead, Investment Banking, London up to £495 per day

X2 PMO lead, Investment Banking, London up to £495 per...

SEO analyst - Retail ecommerce - Hertfordshire. £35-55k

SEO analyst - Retail E-commerce - c35-55k - Hertfordshire...

ICT Technician

ICT Technician Leicester £10,000 per annum...

Oracle Performance Tuning, Oracle, Engineering

Oracle Performance Tuning, Oracle, Tuning, Engineering...

To send to more than one email address, simply separate each address with a comma.