Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

Guest Blog // Selected Security Content Provided By Sophos
What's This?
6/26/2009
10:29 AM
Graham Cluley
Graham Cluley
Security Insights
50%
50%

Spammers Scramble To Exploit Michael Jackson's Death

It took a mere eight hours for cybercriminals to take advantage of the death of pop superstar Michael Jackson.

It took a mere eight hours for cybercriminals to take advantage of the death of pop superstar Michael Jackson.Many people were probably first only just learning about the King of Pop's passing when analysts at SophosLabs intercepted the first criminal attempt to exploit his name.

A wave of email messages, claiming to be from a secret correspondent who alleged he had "vital informations after the death of Michael Jackson's," were seen in spam traps worldwide

OK, so it's not the most grammatically convincing spam message ever sent, but in the whirlwind of interest in Jackson's demise, probably more than a few had their interest piqued.

Spam exploiting death of Michael Jackson

What's the purpose of this campaign? It's hard to say, but possibly the cybercriminals are hoping you reply, confirming your address is live, which, in turn, might result in you receiving more spam in future. Or maybe once they've won your confidence, they'll send you a link or attachment designed to infect your computer.

Either way, responding doesn't make sense.

In a related incident, the folks at WebSense have intercepted a Trojan horse that is being advertised via spam as a supposed link to a Michael Jackson YouTube video. In reality, it's designed to infect your Windows PC.

Cybercriminals have a long history of exploiting breaking news stories for their own financial gain. Attacks have varied from 419 scams claiming to offer inheritances from victims of the Concorde air crash or Western Virginia mining disaster, to the death of the Pope, and the recent demise of actresses Natasha Richardson and Farrah Fawcett.

Speed is everything for these hackers. They realize more people will be searching for information about Michael Jackson, and clicking on more links to news stories today than, say, in two weeks' time.

It's understandable that you may want to follow breaking news stories on the Internet -- but make sure you are not falling into a trap. Visit established news Websites rather than clicking on unknown links or using a search engine that might take you to a keyword-stuffed Website harboring malware.

Graham Cluley is senior technology consultant at Sophos, and has been working in the computer security field since the early 1990s. When he's not updating his other blog on the Sophos website you can find him on Twitter at @gcluley. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Browsers to Enforce Shorter Certificate Life Spans: What Businesses Should Know
Kelly Sheridan, Staff Editor, Dark Reading,  7/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17366
PUBLISHED: 2020-08-05
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate...
CVE-2020-9036
PUBLISHED: 2020-08-05
Jeedom through 4.0.38 allows XSS.
CVE-2020-15127
PUBLISHED: 2020-08-05
In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flip...
CVE-2020-15132
PUBLISHED: 2020-08-05
In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, along with a error message saying that th...
CVE-2020-7298
PUBLISHED: 2020-08-05
Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.