13 January 2009 | 3,806 views

Fake CNN Site From Phishing E-mail Serves Trojan

Check For Vulnerabilities with Acunetix

The latest Phishing E-mails going round are leveraging on people’s need to digest the latest information, in this case about the Israel-Hamas conflict.

They set up a fake CNN site which prompts you to upgrade your flash player to view the video, of course it’s not Flash but a Trojan targeting your sensitive financial information.

I don’t think anyone reading this site would fall for this, but it’s good to be aware of it so you can let others know.

A new e-mail that is circulating looks like it comes from CNN and links to a fake CNN Web page offering “graphic” video related to the Israel-Hamas conflict but instead hosts a Trojan that steals sensitive data, RSA said on Thursday.

When someone clicks on the video link on the fake CNN site an error message pops up urging the visitor to download the latest version of Adobe Flash Player. Clicking on the download link installs an “SSL stealer” Trojan that captures financial and other sensitive information, RSA said in a blog.

The Trojan looks for encrypted communications between the computer and known financial institutions and when it sees data being sent it diverts it to a malicious third-party, said Sam Curry, vice president of product management and strategy at RSA.

It’s an interesting piece of malware, it seems to go after SSL communications and carries out some kind of man in the middle attack by redirecting the valuable SSL traffic to a malicious 3rd party website.

Not as simple as the usual crap which just infects the computer as a spam zombie or infests it with pop-up adverts for casinos and viagra.

The social-engineering attack is different in that the e-mail pretends to come from a media company and then tries to steal financial data, he said. “Normally when you get phished they send you an e-mail pretending to be from a bank or other financial institution,” he said.

RSA discovered the attack early on Wednesday and has worked with others to get the fake site shut down. At a peak on Thursday as many as 80,000 of the phishing e-mails were being sent out, according to Curry.

It seems to be reasonably wide spread, but not huge. It does pose some kind of a threat and I think organizations should perhaps send out some kind of memo about this as I’m sure there’s a lot of legitimate CNN Articles being forwarded around so this one might slip through and land someone in trouble.

As always – be vigilant!

Source: Cnet (Thanks Navin)



Recent in Malware:
- ParanoiDF – PDF Analysis & Password Cracking Tool
- Windows Registry Infecting Malware Has NO Files
- FakeNet – Windows Network Simulation Tool For Malware Analysis

Related Posts:
- Fake Microsoft Patch – BeastPWS-C
- Phishing Attacks Hits Twitter Users – Utilising Direct Messages
- Phishing Sites Getting More Advanced with SSL

Most Read in Malware:
- Nasty Trojan Zeus Evades Antivirus Software - 77,323 views
- Hospital Hacker GhostExodus Owns Himself – Arrested - 47,470 views
- US considers banning DRM rootkits – Sony BMG - 44,930 views

Low-cost VPS Hosting

2 Responses to “Fake CNN Site From Phishing E-mail Serves Trojan”

  1. navin 13 January 2009 at 8:32 pm Permalink

    cheers!! :)

  2. victor 11 February 2009 at 10:31 am Permalink

    well i wanna know how this work any to help?