PDF Spam Returns
Filed in archive Spam News by Sue Walsh on November 01, 2007

"When opened, the PDF file uses the CVE-2007-5020 vulnerability via Acrobat Reader and [Internet Explorer 7.0] and downloads further malware from a server in Malaysia," according to security vendor F-Secure's recent blog post. "The target of the malware seems to be to create a botnet of infected machines to be used for further malicious activity."The PDF spam attack from this summer showed that spammers have a creative side, having figured out that most spam filters aren't able to read PDF attachments. That attack was harmless. The attachments sent then simply hawked various stocks. Now the attack is more dangerous because the attachments unleash malware.
Spammers will "exploit any vulnerabilities they can, which in Windows is about a quadrillion different places," says John Levine [stet], president of consulting firm Taughannock Networks and co-chair of the Internet Engineering Task Force's Anti-Spam Research Group, adding that he believes this PDF spam blast to be the latest incarnation of the Storm malware. "Using Acrobat has the added advantage that it works regardless of what mail program you use, so even people who use Eudora or Thunderbird could get bitten."Adobe released a security update for Acrobat and Adobe Reader on October 22.
Permalink: PDF Spam Returns
Tags:
spam spammers malware PDF spam malicious attachments 2007 spam+returns
Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/100060
















