Fake CNN Site From Phishing E-mail Serves Trojan

The New Acunetix V12 Engine


The latest Phishing E-mails going round are leveraging on people’s need to digest the latest information, in this case about the Israel-Hamas conflict.

They set up a fake CNN site which prompts you to upgrade your flash player to view the video, of course it’s not Flash but a Trojan targeting your sensitive financial information.

I don’t think anyone reading this site would fall for this, but it’s good to be aware of it so you can let others know.

A new e-mail that is circulating looks like it comes from CNN and links to a fake CNN Web page offering “graphic” video related to the Israel-Hamas conflict but instead hosts a Trojan that steals sensitive data, RSA said on Thursday.

When someone clicks on the video link on the fake CNN site an error message pops up urging the visitor to download the latest version of Adobe Flash Player. Clicking on the download link installs an “SSL stealer” Trojan that captures financial and other sensitive information, RSA said in a blog.

The Trojan looks for encrypted communications between the computer and known financial institutions and when it sees data being sent it diverts it to a malicious third-party, said Sam Curry, vice president of product management and strategy at RSA.

It’s an interesting piece of malware, it seems to go after SSL communications and carries out some kind of man in the middle attack by redirecting the valuable SSL traffic to a malicious 3rd party website.

Not as simple as the usual crap which just infects the computer as a spam zombie or infests it with pop-up adverts for casinos and viagra.

The social-engineering attack is different in that the e-mail pretends to come from a media company and then tries to steal financial data, he said. “Normally when you get phished they send you an e-mail pretending to be from a bank or other financial institution,” he said.

RSA discovered the attack early on Wednesday and has worked with others to get the fake site shut down. At a peak on Thursday as many as 80,000 of the phishing e-mails were being sent out, according to Curry.

It seems to be reasonably wide spread, but not huge. It does pose some kind of a threat and I think organizations should perhaps send out some kind of memo about this as I’m sure there’s a lot of legitimate CNN Articles being forwarded around so this one might slip through and land someone in trouble.

As always – be vigilant!

Source: Cnet (Thanks Navin)

Posted in: Malware, Phishing, Spammers & Scammers

, ,


Latest Posts:


testssl.sh - Test SSL Security Including Ciphers, Protocols & Detect Flaws testssl.sh – Test SSL Security Including Ciphers, Protocols & Detect Flaws
testssl.sh is a free command line tool to test SSL security, it checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more.
Four Year Old libSSH Bug Leaves Servers Wide Open Four Year Old libssh Bug Leaves Servers Wide Open
A fairly serious 4-year old libssh bug has left servers vulnerable to remote compromise, fortunately, the attack surface isn't that big as neither OpenSSH or the GitHub implementation are affected.
CHIPSEC - Platform Security Assessment Framework CHIPSEC – Platform Security Assessment Framework For Firmware Hacking
CHIPSEC is a platform security assessment framework for PCs including hardware, system firmware (BIOS/UEFI), and platform components for firmware hacking.
How To Recover When Your Website Got Hacked How To Recover When Your Website Got Hacked
The array of easily available Hacking Tools out there now is astounding, combined with self-propagating malware, people often come to me when their website got hacked and they don't know what to do, or even where to start.
HTTrack - Website Downloader Copier & Site Ripper Download HTTrack – Website Downloader Copier & Site Ripper Download
HTTrack is a free and easy-to-use offline browser utility which acts as a website downloader and a site ripper for copying websites and downloading them for offline viewing.
sshLooter - Script To Steal SSH Passwords sshLooter – Script To Steal SSH Passwords
sshLooter is a Python script using a PAM module to steal SSH passwords by logging the password and notifying the admin of the script via Telegram when a user logs in.


2 Responses to Fake CNN Site From Phishing E-mail Serves Trojan

  1. navin January 13, 2009 at 8:32 pm #

    cheers!! :)

  2. victor February 11, 2009 at 10:31 am #

    well i wanna know how this work any to help?