Sophos tap into phone tapping spam

Sophos is warning users of a tricky new spam message containing an MP3 file attachment of what is claimed to be a recording of the user’s personal phone conversations.

The security vendor said the attachment actually contains the Troj/Dorf-AH Trojan horse, an executable program that installs malware. Furthermore, the sender claims it’s a "detective" who will reveal who has paid for the phone tapping at a later date, but attempts to persuade its victims to open the attachment and listen to the recording.

The email reads: “I am working in a private detective agency. I can't say my name now. I want to warn you that I'm going to overhear your telephone line. Do you want to know who is the payer? Wait for my next message.

"P.S. I'm sure, you don't believe me. But i think the record of your yesterday's conversation will assure you that everything is real."

According to Graham Cluley, senior technology consultant at Sophos: "It's a case of from defective to detective for this attack. The first spam-run of this Trojan horse failed for the malware authors because they made fundamental mistakes in their code. Now their emails are capable of infecting the unwary, while posing as a private investigator."

Sophos experts note that a hacking gang has been making different attempts to infect people with this ruse for a couple of weeks, however initial attempts failed to work properly.

"It may seem hard to believe that anyone would fall for a trick like this, but it wouldn't be a surprise if people tried to run the attachment just out of curiosity,” Cluley said.
Sophos tap into phone tapping spam
Keywords

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read