Stay Smart Online Stay Smart Online

Malicious spam emails with CNN in the subject - SSO-AL2008-008

11 August 2008

Software and platform/s affected

The following operating system platform is affected:

Microsoft Windows (Any version)

What is the problem?

A new email is circulating which is designed to infect your computer with a program that could steal your passwords and other personal information (identity theft) and may use your computer to send out large volumes of spam. Antivirus software may not detect these programs.

The subject lines of the email include, but are not limited to:

CNN.com Daily Top 10
CNN Alerts: My Custom Alert

The "from" field also includes CNN.

What we recommend you do

If you receive an email similar to the above emails, do not click on the web link in the email. Delete the email straight away.

If you have already clicked on the email web link, it is quite possible your computer may now be infected.  It is recommended you seek professional assistance in helping detect and remove the malware.

Where you can find more information

The following links provide more information about the malicious software in these spam emails:

http://www.us-cert.gov/current/#rise_in_spam_messages_circulating
http://blog.trendmicro.com/new-trojan-bait-cnn-videos/
http://cyberinsecure.com/massive-spam-campaign-spreads-false-cnn-news-items-with-fake-flash-player-malware/
http://www.spywareremove.com/security/cnn-com-daily-top-10-email-contains-malware/

Disclaimer

This Alert has been prepared by AusCERT for the Department of Broadband, Communications and the Digital Economy.

The information is intended for used by home users and small to medium sized businesses and is general information only and not intended as advice and was accurate and up to date at the time of publishing. The material and information in this Alert is not adapted to any particular person's circumstances and therefore cannot be relied upon to be of assistance in any particular case. In any important matter, you should seek professional advice relevant to your own circumstances.

The Commonwealth, AusCERT, and all other persons associated with this Alert accept no responsibility or liability for information either included or referred to in the Alert. No responsibility or liability is accepted for any damage, loss or expense incurred as a result of the information contained in the Alert, whether by way of negligence or otherwise.

The listing of a person or organisation in any part of this site or Alert does not imply any form of endorsement by the Commonwealth of the products or services provided by that person or organisation. Similarly, links to other web sites have been inserted for your convenience and do not constitute endorsement of material at those sites, or any associated organisation, product or service.

Please note that material in this Alert, as the case may be, includes views or recommendations of third parties, which do not necessarily reflect the views of the Commonwealth, or indicate its commitment to particular course of action. Material on this site or in this Alert may also include information provided by third parties. The Commonwealth cannot verify the accuracy of information that has been provided by third parties.


 

Back to top