Subscribe

Fake MSNBC news alert used in latest spam campaign

CNN gang changes tactics to bypass more spam filters, warns Sophos

Johannesburg, 14 Aug 2008

IT security and control firm Sophos is reminding computer users to exercise diligence when checking their e-mail in the wake of a new widespread wave of dangerous spam messages that claim to be breaking news alerts from MSNBC.

Samples intercepted at SophosLabs, Sophos's global network of virus, spyware and spam analysis centres, have revealed that rather than containing a link to the story on MSNBC, unsuspecting users that click on the URL in the e-mail will be redirected to a malicious Web page which will then attempt to infect computers with a Trojan horse.

According to Sophos, the e-mails contain a variety of subject lines, including:

msnbc.com - BREAKING NEWS: Mary-Kate Olsen responsible for Heath Ledger's death
msnbc.com - BREAKING NEWS: Google launches free music downloads in China
msnbc.com - BREAKING NEWS: McDonald's found to breach FDA regulations, suspended from trading

The messages are the latest from the spam gang that recently distributed e-mails claiming to be from CNN's breaking news alert service.

"The latest salvo of spam hitting inboxes is likely to trick unsuspecting e-mail users with its topical headlines and the seemingly trusted source," says Brett Myroff, CEO of regional Sophos distributor, Sophos South Africa. "But, by now, everyone should be well aware of this kind of dirty trick and should never click on links in unsolicited e-mails."

Customers using Sophos's e-mail and Web gateway solutions are automatically protected against the attack. Those using other vendors' products are advised to check if they are protected, or if an update is available.

For more information and an image of the MSNBC spam e-mails, please visit http://www.sophos.com/blogs/gc/.

Sophos South Africa

NetXactics, trading as Sophos South Africa, is a South African-based company focused on the provision of security solutions. It is the master distributor for UK-based Sophos Plc, one of the leaders in the provision of network access control and endpoint, e-mail and Web security and control solutions for the corporate environment. For more information, visit Sophos South Africa at www.sophos.co.za.

Sophos

Sophos enables enterprises worldwide to secure and control their IT infrastructure. Our network access control, endpoint, Web and e-mail solutions simplify security to provide integrated defences against malware, spyware, intrusions, unwanted applications, spam, policy abuse, data leakage and compliance drift. With over 20 years of experience, we protect over 100 million users in nearly 150 countries with our reliably engineered security solutions and services. Recognised for our high level of customer satisfaction, we have an enviable history of industry awards, reviews and certifications. Sophos is headquartered in Boston, MA and Oxford, UK.

Editorial contacts

Adriaan du Plessis
Me Talk Pretty
(011) 447 3785
metalkpretty@telkomsa.net
Brett Myroff
Sophos South Africa
(011) 444 4000
brettm@netxactics.co.za