All the latest UK technology news, reviews and analysis

Halloween 'skeleton' spam hides Storm Trojan

by Robert Jaques

31 Oct 2007

Be the first to comment

  • Tweet this
Halloween
Halloween-themed spam messages are infected with the Storm Trojan

Surfers have been warned to be wary of malicious Halloween-themed spam messages infected with the Storm Trojan.

The Marshal Trace team has identified a run of Halloween spam that invites recipients to visit a website and download a program that purports to create a novelty 'dancing skeleton' on the user's desktop.

But victims will be exposed to vulnerability exploits and an executable file named 'halloween.exe'.

This is a copy of the Storm Trojan which compromises the user's PC and merges it into a network of computers that can be commandeered remotely by a controlling server.

The messages arrive with subject lines such as:

'For people with a sense of humour only'
'Halloween Fun'
'Happy Halloween'
'If your in your office, keep the speakers low, lol'
'Nothing is funnier this Halloween'
'Party on this Halloween'
'The most amazing dancing skeleton'
'This will make you laugh'
'You'll laugh your but off'

The Storm Trojan first appeared in January 2007 and quickly gained notoriety by masquerading as current affairs headlines.

More recently, the gang of criminals behind the Storm Trojan has used special events to draw unsuspecting users to infected websites.

The sites are set up specifically to use browser exploits to infect a visitor with a copy of the botnet program.

The gang has used topics ranging from the Fourth of July, the NFL season and greeting cards as hooks to lure spam recipients to the malicious sites.

The Storm botnet is a serious threat and is known to have control over many thousands of PCs. The Marshal Trace team estimates that the Storm botnet is the source of up to 20 per cent of all current spam.

"Today's run of the Storm Trojan using Halloween as its hook is the latest in a long line of social engineering cons used by these criminals," said Bradley Anstis, vice president of products at Marshal Trace.

"Halloween seems to be an increasingly popular holiday outside the US and is gaining global popularity. The Storm gang knows this.

"Many of the previous Storm campaigns have exploited distinctly American events, but this Halloween run will no doubt entice a much wider audience beyond the US."

Graham Cluley, senior technology consultant at Sophos, added: "The gang responsible are experts at choosing topical disguises and crafting alluring emails that the unwary may find difficult to resist.

"What's even more frightening is that when innocent users click to see the skeleton dance, the site also plays The Vengaboys song Boom boom boom boom.

"The good news is that advanced IT security defences are able to stop an attack like this dead in its tracks."

Sophos reported earlier this month that spammers had distributed Halloween-related emails with the intention of gathering personal information from recipients.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Support Analyst x 1/2 (Apple Mac OSX/Windows) - Bristol/Bath

Support Analyst x 1/2 Skills: Apple Mac OSX, Windows...

Network Consultant - London - 55-65k

Network Consultant - London - 55-65k My client are...

Web Graphic Designer

A leading global provider of critical information to...

Midweight UI Designer

Playstations and table football in the kitchen? Standard...

To send to more than one email address, simply separate each address with a comma.