ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Spammers launch MP3 pump-and-dump campaign

Liam Tung ZDNet Australia

Published: 22 Oct 2007 09:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Spammers have launched the first mass MP3-attached pump-and-dump spam campaign, which security experts say could be used to distribute malware.

The spam contains no text or subject header while the attached MP3 files, according to security firm Sophos, are named after popular artists such as Elvis Presley, Fergie or Carrie Underwood.

However, rather than the file playing music from the artist when opened, a message is read in a synthesised female voice, promoting the stocks of Exit Only Incorporated. Paul Ducklin, Sophos's head of technology, said the voice sounded like a female version of "Marvin the Paranoid Android", a character from The Hitchhiker's Guide to the Galaxy by Douglas Adams.

If the file is opened, listeners will hear: "Hello, this is an investor alert. Exit Only Incorporated has announced it is ready to launch its new text4cars.com website. Already a huge success in Canada, we are expecting amazing results in the USA."

Ducklin said the spammers had "not quite got it yet" with this iteration of MP3 spam.

"The problem with MP3 spam — as with image files and PDF — is the files tend to be much larger, so there are extra costs associated with carrying it," said Ducklin.

Read this

Comment
Comment: Getting the knack of NAC

Network Access Control could be the best way to manage the security risks associated with the recent explosion in mobile devices connected to corporate networks

Read more +

So far, the MP3 file has not been used to distribute Trojans or viruses, but this could change. Ducklin said JPEG and WMF (Windows Media Format) files are regularly exploited to deliver malicious executable files. "There was a time when Windows vulnerabilities allowed files to contain shell code — executable programs — and use buffer flows to enter the system… It's not impossible that vulnerabilities in some MP3 [software] would allow you target it with exploit code," said Ducklin.

However MessageLabs' product marketing manager, Philip Routely, said he would expect, if the MP3 was used to transmit malware, it would actually occur by renaming a file extension to make the recipient believe they are receiving an MP3 file.

"There's nothing to say that the same attacker can't make an [executable file] look like a MP3 file. If the attacker changed the file extension, a recipient could double click on it and, while nothing appears to be happening, it's downloading malware in the background," said Routely.

Kaspersky Labs' director of security outsourcing, Andrey Nikishin, said he expects MP3 mass mailings to increase in the future.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
5 out of 9 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Service Delivery Manager - Global B2B Supplier & Service Quality Manager

We create, market and distribute the products that people choose to feed their families and keep themselves and their homes clean and fresh. This may ...

Head of Information

Head of Information Dudley The Dudley Group of Hospitals is a newly opened PFI acute general hospital, based in the heart of the Black Country. To be ...

TWS Scheduling Specialist - UNIX AIX/TRU64, Windows O/S, MS Office, Shell - St Davids Park, Ewloe, Deeside

We create, market and distribute the products that people choose to feed their families and keep themselves and their homes clean and fresh. Provide ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment