Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

New Spam Attack Exploits Edunet Servers

Exploit demonstrates creativity, but little damage caused so far, BitDefender says

Researchers have discovered a new, complex spam attack that uses a sophisticated ruse to fool users into downloading malware.

The exploit, which researchers at BitDefender call "a spam-sending scheme of Byzantine complexity," features spam messages that claim to contain links to videos. When users try to click and see the video, they are instead prompted to download a "media player.”

The download is in fact Backdoor.Edunet.A, a piece of malware that uses victims' computers as a channel for sending commands to a series of mail servers. The mail servers, which are used to spread spam, are mostly in the .edu and .mil domains, BitDefender says.

The list of servers is retrieved by the Trojan from a series of Web servers that are either compromised themselves or part of the attackers’ own network. The list of Web servers is continuously changing, but that of the targets has, so far, remained constant, the researchers say.

The Trojan sends the commands in the hopes of finding an open relay -- a misconfigured mail server that allows anyone to send messages -- which makes it appear that any mail originating from the Trojan has actually been sent from the open relay.

BitDefender researchers have determined that, at least currently, none of the servers in the current target list are actually vulnerable.

"It's not every day that you stumble on the workings of an honest-to-God hacking ring, let alone one that has a predilection for using military and university-run mail servers as spam relays,” declared Sorin Dudea, BitDefender’s head of antivirus research. “It would be interesting to identify what, if anything, the institutions that own the targeted servers have in common.”

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Secure Computing Corp. (Nasdaq: SCUR)

    Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 4/10/2020
    Zscaler to Buy Cloudneeti
    Dark Reading Staff 4/9/2020
    The Coronavirus & Cybersecurity: 3 Areas of Exploitation
    Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: Yes, I do have virus protection on my system, now what?
    Current Issue
    6 Emerging Cyber Threats That Enterprises Face in 2020
    This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
    Flash Poll
    State of Cybersecurity Incident Response
    State of Cybersecurity Incident Response
    Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-11669
    PUBLISHED: 2020-04-10
    An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMOR, aka CID-53a712bae5dd.
    CVE-2020-1801
    PUBLISHED: 2020-04-10
    There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could cause information disclosure. Affected product versions include:Mate 30 Pro vers...
    CVE-2020-3952
    PUBLISHED: 2020-04-10
    Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
    CVE-2020-4362
    PUBLISHED: 2020-04-10
    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
    CVE-2020-1802
    PUBLISHED: 2020-04-10
    There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently validate the integrity of certain file in certain loading processes, successful exploit could allow the attacker to load a crafted file to the device through USB.Affected product version...