[Full-disclosure] Fwd: "Sex Scandal" Spam Campaign Targeting US Presidential Election

n3td3v xploitable at gmail.com
Tue Sep 9 14:48:53 BST 2008


Is Marcus Sachs responsible?

Websense(R) Security Labs™ ThreatSeeker™ Network has discovered an
emerging email campaign which uses the US presidential election as a
social engineering mechanism to install information-stealing code on a
victim's machine. With less than 2 months before the start of the
election, emails are circulating with fake news of a sex scandal
affecting one of the candidates. Recipients of the email are
encouraged to view a video supposedly involving the Democratic
candidate Barack Obama. Users who click the link are shown a
pornographic video taken from hxxp://homemade*snip*.com/. While the
video plays for 14 seconds, malicious applications are installed on
the victim's machine.

Screenshot of example email:

http://securitylabs.websense.com/content/Alerts/3177.aspx




Full-Disclosure is hosted and sponsored by Secunia.