Categorized | DrWeb

Trojans spread over Google Groups

May 12, 2010

The Russian anti-virus vendor Doctor Web warns users as cyber-criminals start spreading malicious programs over the Google Groups service. In particular user systems may get infected with different modifications of Trojan.Fakealert.

First a user receives a spam message containing a link to a file that can be downloaded in a Google group created by criminals. Various social engineering tricks can be applied to lure the user into downloading this file. For instance, the message may inform you that e-mail access parameters have been changed and you need to download a manual before your proceed with editing your account information. You may also be notified that your e-mail account has been compromised and the instructions file will provide you with information on how to deal with this situation.

Once a user clicks on the link, he gets to the page containing a download link to the file. The file can contain modifications of Trojan.Fakealert (fake anti-viruses).

If you try to follow such a link in several hours after the bulk of spam messages has been sent out, Google Group will inform you that the page you are about to open may contain spam. However, choosing “I would like to view this content” will allow you to access the download page. Therefore access to the malicious file is not disabled.

Doctor Web recommends users of Dr.Web software to use caution whenever you get a message from an unfamiliar sender especially if such a message concerns your e-mail account information or other personal data.

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago