[Full-disclosure] Fwd: "Sex Scandal" Spam Campaign Targeting US Presidential Election
n3td3v
xploitable at gmail.com
Tue Sep 9 14:48:53 BST 2008
Is Marcus Sachs responsible?
Websense(R) Security Labs™ ThreatSeeker™ Network has discovered an
emerging email campaign which uses the US presidential election as a
social engineering mechanism to install information-stealing code on a
victim's machine. With less than 2 months before the start of the
election, emails are circulating with fake news of a sex scandal
affecting one of the candidates. Recipients of the email are
encouraged to view a video supposedly involving the Democratic
candidate Barack Obama. Users who click the link are shown a
pornographic video taken from hxxp://homemade*snip*.com/. While the
video plays for 14 seconds, malicious applications are installed on
the victim's machine.
Screenshot of example email:
http://securitylabs.websense.com/content/Alerts/3177.aspx
Full-Disclosure is hosted and sponsored by Secunia.