Swine flu spam could sicken your computer: security firms
Last Updated: Wednesday, April 29, 2009 | 4:59 PM ET
CBC News
Related
Internal Links
External Links
- Adobe: Information about the security patch
- Symantec: Malware security blog
- Symantec: Spam blog
- Symantec: Infostealer technical details
- Websense
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
Criminals are exploiting fears about swine flu in order to distribute malicious computer code and steal personal information, an internet security firm reports.
A document titled "Swine influenza frequently asked questions.pdf" is circulating on the internet as an email attachment and being used to drop malware on computers, Symantec Security Response reported on its malware security blog Wednesday. The document had been detected the day before.
When it is opened, it contains real questions and answers about swine flu.
"Unfortunately, if you get this far, you've been infected," the blog said.
This malicious .pdf file, which is known to security experts as Bloodhound.Exploit.6, takes advantage of an old Adobe vulnerability to drop a malicious "infostealer" file on the user's computer, Symantec said.
"We see so many of those and all they're doing is they're trying to steal your personal information, like you're credit card number, your online bank credentials," Marc Fossi, manager of security response at Symantec, said Wednesday.
The company's website describes infostealers as Trojans (malware disguised as legitimate files) that may log key strokes, capture screen shots or monitor internet activity in order to gather information.
Patch prevents infection
Infection can be prevented by applying an Adobe patch.
So far, samples of the document are "extremely limited," Symantec reported.
Fossi said that's largely because the type of malicious code involved cannot spread in an automated fashion like a worm. He said the problem is nothing to panic about at the moment.
However, the company is warning users to be cautious about unexpected emails and to avoid opening news alerts that they have not subscribed to, especially if they contain suspicious links or attachments.
Fossi said spammers and malicious code authors often use current events like the economic situation and the U.S. presidential election in the fall, holidays such as Christmas and Valentine's Day, or sports events such as the Beijing Olympics to catch the attention of computer users.
With swine flu, he said, "This is something that people are a little more anxious about so they might be a little more likely to check it out." They might sort of forget some of the good habits that they would normally have."
In recent days, both Symantec and the security firm Websense have reported that spammers have been taking advantage of the buzz over swine flu by distributing unsolicited emails with swine-flu-themed subjects.
According to the Symantec blog, some of them include the question: "Are you in Mexico or the US? Do you know someone who has been affected" and then prompt the recipient to click on a link and fill in a form or reply with personal information such as a name, email address, address and phone number.
Symantec suggested that might be "part of a harvest for their [spammers'] future campaigns."
Ads tout swine flu meds
Websense reported that it has detected tens of thousands of emails a day over the past few days with subject lines advertising swine flu medications and antibiotics. However, as of Tuesday afternoon, they did not include links or malware, just advertisements for pharmaceuticals.
"They're simply an annoyance," said Stephan Chenette, manager of security research at Websense.
However, he warned that new categories of spam often eventually end up carrying links to malicious websites that may be disguised as legitimate ones.
Symantec has also detected a lot of bulk swine flu emails that contain no links or malware and don't seem to even be selling anything.
"They're just trying to put some scare into people," Fossi said. "It's sort of rabble-rousing or something along those lines."
Chenette said that another trend Websense has noticed is that web domain names containing "swine flu" are being registered. The company said it is monitoring those.
"Right now they're not used for anything, but it leads us to believe that at some point, they're either going to be used for spamming purposes, perhaps advertisements or even greater malicious use."
Share Tools
Top News Headlines
- Markets gain after Greece approves austerity plan
- World stock markets rise after Greece's parliament approves a new set of austerity measures that were required by international lenders in exchange for an emergency bailout. more »
- Hit and run victim's family fears accused will walk
- The family of a young mother killed in a hit and run is outraged that the case against the alleged driver is among thousands in B.C. at risk of being thrown out because of a huge court backlog. more »
- Quebec town 'heartbroken' after killing of woman, sisters
- A small Quebec town is in mourning Sunday after a Quebec man was charged with killing his nieces and his mother, who were found dead in their family home. more »
- Neil Macdonald: The death penalty debate America isn't having
- Texas's death row archive is a troubling document, not the least for what it doesn't say about those who may be wrongfully convicted, Neil Macdonald writes. more »
Latest Technology & Science News Headlines
- Ancient Antarctic lake may harbour microbial life
- If scientists find microbes in a frigid lake 3.2 kilometres beneath the thick ice of Antarctica, it will illustrate once again that somehow life finds a way to survive in the strangest and harshest places, and it will offer hope that life exists beyond Earth. more »
- B.C. killer whale habitat protection ruled a legal duty
- The federal minister of fisheries has no discretion when it comes to protecting the critical habitat of B.C.'s southern resident killer whales, the Federal Court of Appeal has ruled. more »
- Create-your-own-app product to launch in Moncton
- A Moncton entrepreneur is hoping to revolutionize the way mobile applications are created by launching a new product that allows people to develop their own app within minutes. more »
- Game developer seeks $400K, makes $1M in a day
- Videogame studio Double Fine went on the website Kickstarter to raise $400K US in a month to develop a new game. They reached that target in a matter of hours. more »
Bob McDonald's Blog
Glacier Discovery Walk: Will the visitor centre enhance the view? Feb. 10, 2012 3:17 PM Environment minister Peter Kent has announced the construction of a new Glacier Discovery Walk and visitor centre on the Icefields Parkway in Jasper National Park. It raises the issue of how to balance commercial development in our National Parks against the preservation of the last refuges of wilderness.
Quirks & Quarks
- February 11: Inside the Mind of a Neandertal Feb. 10, 2012 4:01 PM Can we get inside the mind of a species that's been dead for 30,000 years? A new book, How to Think Like a Neanderthal, suggests we can. The authors reconstruct a creature like us in many ways, but with important differences.
Latest Features
- Adele wins best album, best record Grammys
- Houston autopsy results withheld by police
- Quebec town 'heartbroken' after killing of woman, sisters
- Greece passes new austerity deal amid rioting
- Pop queen Whitney Houston dies at 48
- Northern lights viewed from space
- Manitoba man dies after falling off moving SUV
- Doors blocked in fatal Manitoba trailer blaze
- Former Stanley Park petting zoo goats feared slaughtered

