The Spam Report

You are here: silicon.com > Research > Special Reports > The Spam Report

The Spam Report

Lycos email scam hides nasty Trojan

There's backfiring and then there's BACKFIRING!

By Will Sturgeon

Published: 8 December 2004 12:05 GMT

A malicious email purporting to offer a link to download Lycos' controversial spam busting screensaver is infecting users with a Trojan - proving that the fall out from the botched and now ditched service will continue to cause users pain.

The email, subject line "Be the first to fight spam with Lycos screen saver", includes a link which, when clicked, installs a Trojan on the infected PC, potentially surrendering control of that PC to the hacker behind the email scam.

The file attachment appears as 'Lycos screensaver to fight spam.zip' and as well as the Trojan the payload also contains a keystroke logger which notifies an Indonesian email address of its status.

Keystroke loggers are typically used to steal information such as usernames and passwords.

Graham Cluley, senior technology consultant at Sophos, said: "Recipients are encouraged to think they are volunteering for an anti-spam campaign when, in actual fact, they are unwittingly sending off confidential information to an unknown third party."

"The information could be used to find out a recipient's usernames and passwords for online banks or shops," he added.

Perhaps the cruellest irony of it being Lycos' ill-considered anti-spam initiative which is being abused is the fact machines which are infected by Trojans in this way are often used to send large volumes of spam.

Networks of these compromised machines - or botnets - are rented out to spammers by the gangs who control them. According to Paul Wood, chief information analyst at MessageLabs, such botnet capacity can be rented out for around $10 per hour and "provides enough combined computing power and bandwidth to spam almost every email address imaginable".

Yesterday silicon.com questioned whether the hastily scrapped service may actually have further empowered the spammers and today's news heaps further blame on Lycos who appears to have unwittingly breathed new life into spam campaigns and virus writing.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
The Spam Report News

Virtual worlds under siege from cyber crime
A hiding place for scams, spam and phishing…

Spammers switching on to YouTube?
Video spam and PowerPoint slides next on the menu, warns MessageLabs...

Spam surge emanating from the Far East
Made in China...

US court upholds anti-spam law
Junks convicted spammer's appeal...

Spammers dust off their botnet passports
Targeting pastures new...

The Spam Report Extra

Stories from around the web...

Beware: You have mail Times Online

The economies of spam Global Politician

Special report: Fighting spam and cyberscams CNET News.com

Spam ain't dead yet PC Magazine

Slaying Spam-Spewing Zombie PCs PC World

RELATED RESEARCH

Make your voice heard

silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.

Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.

Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.

For more about the Research Panel and how to join, click here



Quick Sitemap Links: