Taiwan bank scam rides on Adobe flaw

By Vivian Yeo, ZDNet Asia
Friday, August 07, 2009 04:30 PM

An e-mail scam making its rounds in Taiwan, attempts to trick users into downloading malware, Symantec has warned. Systems without up-to-date patching for Adobe products are vulnerable to the attack.

Appearing to be a credit card promotional e-mail sent from a Taiwanese commercial bank, the spam message has a deliberate void in the content which gives users the impression that it failed to load properly, according to a Symantec blog post on Thursday night. Users are then instructed to click onto a link if they are unable to view the images.

Clicking on the link brings users to a Web page containing malicious code, which then redirects them to at least one other site. At this stage, it attempts to drop a shellcode--an exercise that targets systems without up-to-date patching for Adobe software. Successful exploitation could allow attackers to gain control of the machine.

Adobe last month released a patch for the vulnerability, which affects products including Flash Player, Adobe Reader and Adobe Acrobat.

When contacted by ZDNet Asia, a Symantec spokesperson declined to name the spoofed bank but noted that it had already been notified of the matter. Spam activity has been limited to Taiwan, the Singapore-based spokesperson added. Symantec was, however, unable to provide the number of infections.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary Part 4: Using OpenAmplify via SOAP

Web Development

Justin James walks you through the process of using the SOAP interface to OpenAmplify from Visual Studio 2008.


Read more »



When technology costs more than human

Blog thumbnail

Movie director James Cameron waited 15 years for technology to catch up before it was sufficiently advanced for him to create the much-anticipated upcoming film, Avatar.

To be released in..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web