Apple iPhone
An email scam is luring users with the promise of a free iPhone

iPhone scammers start digging for gold

The email scams begin ...

Written by Shaun Nichols in California

Online criminals have wasted no time in exploiting Friday's much-hyped launch of the iPhone

The Sans Internet Storm Centre has warned of an email scam that lures users with the promise of a free iPhone. 

Recipients who click on the link in the message are guided to a webpage that attempts to exploit several known flaws in Microsoft's Internet Explorer browser to recruit the victim to a botnet.

A second attack uses a mixture of social engineering, malware and cross-site scripting to defraud victims.

The attack is launched when a user visits a specially crafted web page that attempts to exploit a number of previously disclosed vulnerabilities in Internet Explorer 6 and 7 to install a Trojan application. 

The Trojan activates every time the user visits Yahoo.com or Google.com, at which point a pop-up is launched advertising a site named iPhone.com. 

Normally, www.iphone.com will redirect to Apple's iPhone page, but the Trojan spoofs the iPhone.com domain name and directs users to a fake retail site claiming to be iphone.com and using Apple's logo and iPhone images. 

After filling out the fake order forms, users are instructed to send payment via wire transfer to an address in Latvia in order to receive the iPhone.

Eric Sites, chief technology officer at Sunbelt Software, urged users to install the latest security updates for their browser and operating system, and use firewall and antivirus software. 

The attack currently targets Internet Explorer, but Thomas said that Firefox users should also be vigilant, as the group believed to be behind the attacks has used Firefox exploits in the past.

Tags:

Further reading

Special Report: Apple iPhone

All the latest news on Apple's iPhone   More...

iPhone launches to great fanfare

Customers finally get their hands on Apple smartphone   More...

Hundreds queue up for 'iPhone day'

'Putting the circus back in media circus'   More...

vnunet.com analysis: will iPhone ring up the sales?

Industry analysts get to the core of Apple's mobile phone   More...

Related articles

Four more fixes for Windows Safari

Security updates pile up for Apple browser   More...

Halloween 'skeleton' spam hides Storm Trojan

Don't let your PC be turned into a zombie   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Malware writers gear up for bumper 2008

Let's be careful out there   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement