Skip navigation

News spoof used as decoy to spread malware

BUCHAREST, Romania – July 10, 2008 – BitDefender researchers have identified a new wave of spam messages, using a spoof news report announcing an alleged attack of the US Army against Iran in order to trick users into downloading and installing malicious software onto their personal computers.

The webpage hosting the piece of malware – dailydotnews.com - is a simple, yet efficiently designed site with a top banner, a simple picture masquerading a YouTube player and three lines of text detailing the US operation in Iran. This spam approach is used on large scale as the spammer relies on a catchy heading and a link to the piece of malware in order to fuel users’ curiosity and trick them into downloading the piece of malware.

“The new spam wave relies on computer users’ curiosity regarding the conflict between the United States and Iran. Users are redirected to a fake news website, where they are shown a larger, inciting description accompanied by a movie player,” said Andra Miloiu, BitDefender Spam Analyst. “However, the alleged flash movie is an image depicting a movie player; when clicked, the image gives users a ‘Save image as’ option.”

Upon clicking on either the “movie” or the top banner, the user starts the download process of a binary piece of malware, called “iran_occupation.exe.” The file contains the same malicious code infecting the user with the Storm Worm. The authors have used timing as their advantage, as the recent tensions in the Middle East between the US and Iran have been escalating.

On the social side, the spam wave is targeting the increasingly worried US citizens looking for fresh news on Iran threatening to burn Tel Aviv down in response to possible US attacks on its nuclear facilities.

The BitDefender antivirus is currently filtering and detecting that both the spam message and the malicious code, “iran_occupation.exe” binary, are infected with Trojan.Peed.PM.


About BitDefender® http://www.bitdefender.co.uk
BitDefender is the creator of one of the industry's fastest and most effective lines of internationally certified security software. Since our inception in 2001, BitDefender has continued to raise the bar and set new standards in proactive threat prevention. Every day, BitDefender protects tens of millions of home and corporate users across the globe—giving them the peace of mind of knowing that their digital experiences will be secure. BitDefender solutions are distributed by a global network of value-added distribution and reseller partners in more than 100 countries worldwide. More information is available on our security solutions’ site.


Mike Ottewell
MJO Associates for BitDefender UK
Tel: 01538 361217
E-mail: mjo.associates@tiscali.co.uk

Nick Billington
BitDefender Country Manager(UK and Ireland)
Tel: 08451305096
E-mail: nbillington@bitdefender.co.uk
Fax:- 0845 130 5069



This press release was distributed by ResponseSource Press Release Wire on behalf of MJO Associates in the following categories: Consumer Technology, Personal Finance, Business & Finance, Computing & Telecoms, for more information visit http://pressreleasewire.responsesource.com/about.