Categorized | Antivirus

Newegg Password Reset Scam: a Harbinger of Threats to Come?

McAfee Labs has detected a new strain of spam in the wild that is not only a sophisticated forgery of a Newegg purchase receipt, but also appears to be abusing Newegg’s own password reset system to further the scam.

password reset

The spammers are taking advantage of the password reset option on the Newegg website to generate an email to the victim announcing that a password reset is required. This ruse cannot be used to determine if an account exists because the Newegg site returns the same text if you request a password reset on an actual or nonexistent account. So directory harvesting does not appear to be the attackers’ goal. Newegg’s password reset option is not protected by any sort of CAPTCHA authentication, so this process is probably being scripted as part of the spam campaign. The password reset request does not actually reset the password unless the recipient clicks on the email that is sent. In all likelihood this scam is designed to make the recipient anxious by suggesting an unauthorized individual has attempted to access the account.

forgery

Anxiety and frustration are common emotions used by spam and phishing messages to make a victim click on a malware link without thinking. One common trick is sending a purchase confirmation email to a recipient, who is likely to click on the attachment or the link because he or she is afraid or is convinced that someone has already hacked the account. To continue the scam: The victims receive a forged Newegg purchase receipt shortly after seeing the legitimate password reset notice. Because the reset notifications come from legitimate Newegg servers, they will likely not be stopped by spam prevention systems. If recipients are anxious about account tampering, they may be willing to release a quarantined spam message that claims to be a purchase receipt because they feel their accounts may have been compromised.

cutwail

This spam mail appears to be associated with the Cutwail botnet, which is the second-most prolific botnet in detected infections. (Rustock is the top.) Cutwail has the highest number of infections detected in Russia, India, and Brazil. We do not know if every recipient of a Newegg spam has received a password reset notification before the spam mail arrived, but McAfee TrustedSource™ has detected a 233 percent increase over the average mail flow coming from Newegg IP addresses today. This suggests that a significant percentage of these spams are preceded by a password reset notification from Newegg’s servers.

newegg.ts

The spam mail not only mimics the look and feel of a Newegg email, but also forges the RFC 821–received headers to pretend that it originated from Newegg servers. The email contains an HTML attachment that uses obfuscated JavaScript to forward the victim to a domain which attempts to deliver fake anti-virus software or other malware to the recipient.

This is a powerful scam: It combines forgery techniques to fool the victims, techniques to fool the filters, and outright abuse of the Newegg corporate infrastructure to scare the recipients of the malicious emails. Techniques like this are not new, but the combination of three in one package is rare. Administrators should be aware of this campaign and inform their users not to be fooled by the purchase receipt. Users who want to check their Newegg accounts should not use any links in an email but should go straight to newegg.com.

We made numerous attempts to contact Newegg about this issue but they did not respond.

View full post on McAfee Avert Labs

Related Posts
  • This is how hacker steal your Facebook password
    There's many attackers out there who want to steal your credential information. And no doubt, Facebook as one of the largest Social Networking sites in the world, always been a target of attack from t...
  • Web threats come and go … REALLY fast!
    Very interesting blog post from our esteemed colleagues from Trusteer. Based on their research, around 50% users get infected from phishing campaigns within the first hour. This is actually perfectly ...
  • The shape of threats to come
    Mark Gibbs ponders the uber malware called Stuxnet. View full post on Computerworld Security News...
  • Microsoft boosts Hotmail password reset security
    Microsoft on Monday added new security features to its Windows Live Hotmail Web mail service to help users regain control of hijacked accounts. View full post on Computerworld Security News...
  • Fake Facebook password reset leads to rogue AV
    There is no stopping the abuse of social networking sites and an endless reign of social engineering tactics in email campaigns, be it spam or malicious.  Facebook seems to be a favourite fo...
  • Reset your Twitter Password malicious spam
    Websense® Security Labs™ ThreatSeeker™ Network has detected a spam posing as a Twitter Password Reset Notification.  We have seen about 55,000 instances of this malicious spam ema...
  • Malware spreading via ‘Facebook Password Reset Confirmation’ email
    Facebook users are once again under attack. A new variant of Bredolab Trojan is spreading through spam email messages appearing to come from Facebook. The messages pretend to come from the &ld...
  • Facebook Password Reset Confirmation Spams
    Be careful of the new round of spams about Facebook Password Reset Confirmation. From: The Facebook Team <service@facebook.com>Subject: Facebook Password Reset Confirmation.Mail body:Hey gt ...
  • Protecting Against Password Reset Attacks
    As I previously blogged today, the hacker who broke into Sarah Palin’s Yahoo account was convicted on two charges. The way that David Kernall gained access to Palin’s email account was by ...
  • 2 FREE Southwest Airline Tickets!
    Scam Signature Message: 2 FREE Southwest Airline Tickets!Scam Type: Click-Jacking, Bogus OfferTrending: May 2011Why it's a Scam:Clicking the wall post link takes you to the  f...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago