Rogue LinkedIn Emails Direct Users to Zbot Drive-By Download

Recommended Posts

Rogue LinkedIn Emails Direct Users to Zbot Drive-By Download

Rogue emails posing as LinkedIn alerts directs users to a malicious page, which attempts to infect them with a variant of the ZBot information stealing trojan.

The spam campaign was launched yesterday and according to Cisco Security it was the largest such attack known to date, that targeted LinkedIn users. At one point, the fake emails accounted for well over 25% of the total spam traffic registered by the company's systems.

The messages come with a subject of "LinkedIn Alert" and have their header spoofed to appear as originating from a [email protected] address.

It appears that spammers have abused a legit LinkedIn email template in order to make the emails look more authentic, a technique we've seen used a lot this summer.

Recipients are reminded of an invitation from a friend and are informed that two pending messages await their response. All links present in the emails have been modified to point to a malicious page.

More detail here:

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.
