Fake CNN Site From Phishing E-mail Serves Trojan

The New Acunetix V12 Engine


The latest Phishing E-mails going round are leveraging on people’s need to digest the latest information, in this case about the Israel-Hamas conflict.

They set up a fake CNN site which prompts you to upgrade your flash player to view the video, of course it’s not Flash but a Trojan targeting your sensitive financial information.

I don’t think anyone reading this site would fall for this, but it’s good to be aware of it so you can let others know.

A new e-mail that is circulating looks like it comes from CNN and links to a fake CNN Web page offering “graphic” video related to the Israel-Hamas conflict but instead hosts a Trojan that steals sensitive data, RSA said on Thursday.

When someone clicks on the video link on the fake CNN site an error message pops up urging the visitor to download the latest version of Adobe Flash Player. Clicking on the download link installs an “SSL stealer” Trojan that captures financial and other sensitive information, RSA said in a blog.

The Trojan looks for encrypted communications between the computer and known financial institutions and when it sees data being sent it diverts it to a malicious third-party, said Sam Curry, vice president of product management and strategy at RSA.

It’s an interesting piece of malware, it seems to go after SSL communications and carries out some kind of man in the middle attack by redirecting the valuable SSL traffic to a malicious 3rd party website.

Not as simple as the usual crap which just infects the computer as a spam zombie or infests it with pop-up adverts for casinos and viagra.

The social-engineering attack is different in that the e-mail pretends to come from a media company and then tries to steal financial data, he said. “Normally when you get phished they send you an e-mail pretending to be from a bank or other financial institution,” he said.

RSA discovered the attack early on Wednesday and has worked with others to get the fake site shut down. At a peak on Thursday as many as 80,000 of the phishing e-mails were being sent out, according to Curry.

It seems to be reasonably wide spread, but not huge. It does pose some kind of a threat and I think organizations should perhaps send out some kind of memo about this as I’m sure there’s a lot of legitimate CNN Articles being forwarded around so this one might slip through and land someone in trouble.

As always – be vigilant!

Source: Cnet (Thanks Navin)

Posted in: Malware, Phishing, Spammers & Scammers

, ,


Latest Posts:


Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.
Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
Insecure software versions are a problem Web Security Stats Show XSS & Outdated Software Are Major Problems
Netsparker just published some anonymized Web Security Stats about the security vulnerabilities their online solution identified on their users’ web applications and web services during the last 3 years.
CTFR - Abuse Certificate Transparency Logs For HTTPS Subdomains CTFR – Abuse Certificate Transparency Logs For HTTPS Subdomains
CTFR is a Python-based tool to Abuse Certificate Transparency Logs to get subdomains from a HTTPS website in a few seconds.
testssl.sh - Test SSL Security Including Ciphers, Protocols & Detect Flaws testssl.sh – Test SSL Security Including Ciphers, Protocols & Detect Flaws
testssl.sh is a free command line tool to test SSL security, it checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more.


2 Responses to Fake CNN Site From Phishing E-mail Serves Trojan

  1. navin January 13, 2009 at 8:32 pm #

    cheers!! :)

  2. victor February 11, 2009 at 10:31 am #

    well i wanna know how this work any to help?