Phishers angling for Web site administrators

December 5th, 2009 admin

Scam e-mail artists have launched a massive campaign to trick webmasters into giving up the credentials needed to administer their Web sites, targeting site owners at more than 90 online hosting providers. Experts say the attackers are attempting to build a distributed network of hacked sites through which to distribute their malicious software. The spam e-mails arrive addressed to users of some of the top Web hosting firms, from hostgator.com to yahoo.com and 50webs.com, and bear the same basic message: “Due to the system maintenance, we kindly ask you to take a few minutes to confirm your FTP details.” Recipients who click …


Originally posted on SecurityFix

 
  Related Posts
Nastygram: MySpace phish plants spy software
Nastygram: MySpace phish plants spy software
A new spam campaign targeting MySpace.com users once again illustrates the blended threat from junk e-mail attacks, experts warn. This latest run tries to lure recipients into giving up their MySpace credentials, and then attempts to trick victims into installing password-stealing malicious software. Attackers began blasting out the junk e-mails... 
Bit.ly to scour shortened links for badness
Bit.ly to scour shortened links for badness
Scammers and spammers soon will have a tougher time masking links to their malicious Web sites using bit.ly, one of the more popular link-shortening services out there: The company said this week it is teaming with three security firms to warn users when a shortened link looks like it leads to badness. Criminals increasingly are abusing URL-shortening... 
Nastygram: Bogus DHL e-mails harbor secret message
Nastygram: Bogus DHL e-mails harbor secret message
A recent spam run that tries to distribute malicious software disguised as a DHL package tracking number contains a poorly hidden message that insults the Security Fix author by name. According to an analysis by security firm Sophos, the messages arrive as a “Dear Customer” notification stating that the courier company was unable to... 
Microsoft plugs 15 holes in Windows, Office
Microsoft plugs 15 holes in Windows, Office
Microsoft on Tuesday released software updates to fix at least 15 security flaws in Windows, Windows Server and Microsoft Office. One of the patches addresses a flaw so serious that users could find their Windows PCs compromised just by visiting booby-trapped Web sites. Richie Lai, director of vulnerability research for patch management firm Qualys,... 
Nastygram: CDC ’swine flu’ vaccine scam
Nastygram: CDC ’swine flu’ vaccine scam
E-mail scam artists are impersonating the Centers for Disease Control with a bogus e-mail that claims to offer information about a state-run vaccination program for the H1N1 “Swine Flu” contagion. This highly topical and plausible e-mail message directs recipients to a fake CDC Web site that tries to foist malicious software. Recipients... 
Microsoft Takes Down Whistleblower Site, Read the Secret Doc Here
Microsoft Takes Down Whistleblower Site, Read the Secret Doc Here
Microsoft has managed to do what a roomful of secretive, three-letter government agencies have wanted to do for years: get the whistleblowing, government-document sharing site Cryptome shut down. Microsoft dropped a DMCA notice alleging copyright infringement on Cryptome’s proprietor John Young on Tuesday after he posted a Microsoft surveillance... 
New Password-stealing Virus Targets Facebook Users
Hackers have flooded the Internet with virus-tainted spam that targets Facebook’s estimated 400 million users in an effort to steal banking passwords and gather other sensitive information. The emails tell recipients that the passwords on their Facebook accounts have been reset, urging them to click on an attachment to obtain new login credentials,... 
Jobs and Money Mule Scams
Jobs and Money Mule Scams
With the unemployment rate rising, websites advertising job listings have been mushrooming. Some are the real deal, and some are not. We have also seen an increase in spam e-mails regarding job offers. We came across this particular spam e-mail that has been circulating, looking for someone to be a money mule: If you try going to the domain mentioned... 
A year later: A look back at McColo
A year later: A look back at McColo
A year ago today, the Internet community witnessed a remarkable event: The unplugging of McColo, a Web hosting facility in Northern California that for a long time controlled a majority of the spam-sending operations on the planet. McColo’s two main Internet providers abruptly yanked the cord after Security Fix presented them with scads of... 
Nastygram: Beware the NACHA gotcha
Nastygram: Beware the NACHA gotcha
Cyber thieves on Thursday began blasting out millions of e-mails impersonating NACHA – The Electronic Payments Association, a not-for-profit group that develops operating rules for organizations that handle electronic payments, from payroll direct deposits to online bill pay services. The missives in this latest scam arrive with various subject... 
  Related Tweets from Twitter

There was an error processing the Feed, if this is your page, please check the information provided in your profile.

  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP