Spam
Spam emails are arriving with subject lines including 'Third World War has begun'

Spammers announce World War III

Latest scam offers 'video' of US troops invading Iran

Written by Robert Jaques and Shaun Nichols

Hackers are deluging web users with malware-laden spam claiming that World War III has started following a US invasion of Iran.

Security experts warned today that spam emails with subject lines including 'Third World War has begun', '20000 US Soldiers in Iran' and 'US Army crossed Iran's borders' have been intercepted.

Advertisement

The emails contain links to a malicious webpage that displays what appears to be a video player showing the mushroom cloud of a nuclear explosion.

Text on the page reads: 'Just now US Army's Delta Force and US Air Force have invaded Iran.

'Approximately 20000 soldiers crossed the border into Iran and broke down the Iran's Army resistance.

'The video made by US soldier was made today morning. Click on the video to see the first minutes of the beginning of World War III. God save us.'

People may rush to watch the video without engaging their common sense

Graham Cluley Sophos

However, Sophos warned that users visiting the webpage and clicking on the 'video player' run the risk of being infected with the Troj/Tibs-UO Trojan and a malicious JavaScript hidden on the website as Mal/ObfJS-AY.

Graham Cluley, senior technology consultant at Sophos, said: "Hackers are taking advantage of the fact that many people today get their fix for breaking news via the internet.

"People, especially those with loved ones in the Middle East, may rush to watch the video without engaging their common sense.

"Everyone should ensure that they keep their antivirus protection up-to-date and never follow links in unsolicited email messages."

The latest round of attacks comes just four days after Storm launched a spam run offering fireworks movies from the 4th of July festivities in the US.

Though the botnet's creators normally try to capitalize on current events and holidays, Storm has made one previous venture into the realm of fiction. In June, the botnet sent out a wave of outrageous news stories in an attempt to infect new users.

Since its first appearance in early 2007, Storm has become one of the most successful social engineering malware campaigns in recent memory.

Rather than rely on browser exploits or covert installs, Storm relies almost exclusively on spam messages and phony web pages which trick the user into manually launching an executable file and setting off the infection.

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Ministry of Defence

MoD data loss total could hit 1.7 million

New figures far higher than initial estimates   More...

Sun Microsystems

Sun Sparc server shatters seven standards

T5440 sets new benchmark records   More...

Gary McKinnon

Home Office turns down latest McKinnon appeal

Home Secretary informs lawyers of arrangements for US extradition   More...

Network cables

Network Instruments touts nanosecond apps troubleshooting

Observer 13 offers upgraded performance and forensic network analysis   More...

Primary Navigation