All the latest UK technology news, reviews and analysis

Spoof email tricks AOL users

by Ken Young

23 Sep 2005

Comments: 4

  • Tweet this
Phishing
Spoofed email purports to come from AOL's security department

An email scam is targeting AOL customers in an attempt to steal personal details, according to web monitoring company Websense.

Users receive a spoofed email purporting to come from the security department at AOL claiming that the company suffered a security breach over the weekend and that confidential information may have been compromised.

The email also requests users to connect to a website to download and install a new 'security patch', which will 'protect their information'. The spoofed message reads:

'Failure to download this security patch in the next 48 hours will result in the temporary suspension of your America Online account. At this point we will send you a Security Patch CD in the mail. Upon installing it, your account will be reactivated.'

When users click on the link, they are redirected to a website hosted in Scotland which downloads a piece of malicious code, named patch.scr, written in Visual Basic and using Yoda Crypt.

When the file is run, a wizard opens to guide users through the disclosure of their confidential account and billing information, including their account limit. Once this information is obtained, it is sent in a text file via FTP to an account at a hosting facility.

Ross Paul, product marketing manager at Websense, said: "This is a blended threat that we haven't seen before. It combines the threat of a security breach with a link to a download that masquerades as a patch but in fact requests sensitive user information.

"The kind of questions it asks should alert you to the fraud because your provider already has those details."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Software Development Manager

Software Development Manager - London, 12 Month Contract...

PROCUREMENT AND COMMERCIAL MANAGER

PROCUREMENT AND COMMERCIAL MANAGER BERKSHIRE...

Field Service Engineer Crawley

Hardware Engineer / Field Service Support Analyst £16...

Infrastructure / Implementation Support Windows

Infrastructure / Implementation Support Engineer (Windows...

To send to more than one email address, simply separate each address with a comma.