17 Jan 2005
Criminal virus writers and phishers are attempting to exploit the tsunami disaster in the Indian ocean with two previously undocumented scams emerging over the weekend.
A newly discovered worm, VBSun-A, is currently in circulation pretending to offer details of how to contribute to those left homeless or orphaned by the disaster. Infected emails have the header 'Tsunami Donation! Please help!' and the worm is contained in an attachment called tsunami.exe.
Once activated the worm harvest email addresses and mails itself on. It also attempts to launch a denial of service attack against a German hacking website.
"Duping innocent users into believing that they may be helping the tsunami disaster aid efforts shows virus writers stooping to a new low," said Graham Cluley, senior technology consultant at Sophos.
"This gruesome insensitivity is a despicable ploy to get curious computer users to run malicious code on their computers.
"Everyone should be wary of unsolicited email attachments, and visit the established charity websites instead if they wish to assist those suffering as a result of the disaster."
This is the second worm to attempt to exploit the tragedy. The VBS/Geven-B worm released at the start of the month came in an email claiming that the tsunami was "God's punishment".
In a second scam a very convincing fake Red Cross website was set up on www.american-redcross.org by phishers intent on collecting credit card information. The site has since been taken down, but it is not known how many people fell victim.
The site not only asked for credit card numbers but for Pin numbers, a sure sign of illegal activity. The real site for those who want to donate money can be found at www.redcross.org.
Last week the FBI arrested unemployed painter Matthew Schmieder after he sent out over 800,000 emails in which he claimed to be raising money for disaster relief.
He apparently told agents that he thought he would not be doing anything wrong if he used some of the money to pay bills and gave the rest to charity.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Premier Consulting Firm - Procurement/P2P Transformation...
Premier consulting firm - IT Strategy and Cloud Consulting...
Software developer/ C# developer, (ASP.NET, C#, MVC...
Oracle Developer/ Programmer- Oracle ebusiness suite...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?