Hussein SPAM Includes Banking Key Logger
Trojan horses
piggybacked on messages that claim to include video clips of Saddam Hussein's
execution are circulating. Taking advantage of such a highly publicized event
to draw attention to what would otherwise be just another SPAM message is not
such a surprise. The real surprise came to those individuals who were lured to
open and read the message, as they unknowingly had key logging software
installed onto their systems.
As part of our
Managed Security Service, BAI Security has been blocking multiple pieces of
malware worldwide that use a Saddam theme. Two of them—Banload.bsw and
Banload.bsx—try to disguise themselves by opening a YouTube search result page
that shows hits from a keyword in Portuguese: "enforcado" (execution). All
exploits are in fact Trojans that download spyware key loggers intending to
steal online bank account passwords.
Hussein has been
invoked several times by scammers in the past. Nearly two years ago, spam said
to include pictures of Saddam after he'd supposedly been shot dead while trying
to escape U.S. custody actually harbored the Bobax.h worm. Shortly after that,
Nigerian fraudsters tried to dupe recipients into parting with their money by
offering a share of the private fortunes of Hussein and his closest aids.
These events continue
to prove the importance of enhanced protection to stop SPAM and filter
particular email attachments, as well as non-business websites that can host
such scams. It is important to note that traditional firewalls and Intrusion
Detection systems would not usually detect this type of threat, while SPAM and
web filtering system likely would.
This is an excellent
example of why BAI Security uses a layered approach to our Managed Security
service that combines firewall, IDS/IPS, as well as Antivirus, Spyware/Malware,
Web/Email Filtering solutions in a combined solution. For more information on
our services – contact us today.
|