There's backfiring and then there's BACKFIRING!
Published: 8 December 2004 12:05 GMT
A malicious email purporting to offer a link to download Lycos' controversial spam busting screensaver is infecting users with a Trojan - proving that the fall out from the botched and now ditched service will continue to cause users pain.
The email, subject line "Be the first to fight spam with Lycos screen saver", includes a link which, when clicked, installs a Trojan on the infected PC, potentially surrendering control of that PC to the hacker behind the email scam.
The file attachment appears as 'Lycos screensaver to fight spam.zip' and as well as the Trojan the payload also contains a keystroke logger which notifies an Indonesian email address of its status.
Keystroke loggers are typically used to steal information such as usernames and passwords.
Graham Cluley, senior technology consultant at Sophos, said: "Recipients are encouraged to think they are volunteering for an anti-spam campaign when, in actual fact, they are unwittingly sending off confidential information to an unknown third party."
"The information could be used to find out a recipient's usernames and passwords for online banks or shops," he added.
Perhaps the cruellest irony of it being Lycos' ill-considered anti-spam initiative which is being abused is the fact machines which are infected by Trojans in this way are often used to send large volumes of spam.
Networks of these compromised machines - or botnets - are rented out to spammers by the gangs who control them. According to Paul Wood, chief information analyst at MessageLabs, such botnet capacity can be rented out for around $10 per hour and "provides enough combined computing power and bandwidth to spam almost every email address imaginable".
Yesterday silicon.com questioned whether the hastily scrapped service may actually have further empowered the spammers and today's news heaps further blame on Lycos who appears to have unwittingly breathed new life into spam campaigns and virus writing.
Back to The Spam Report Special Report
Virtual worlds under siege from cyber crime
A hiding place for scams, spam and phishing…
Spammers switching on to YouTube?
Video spam and PowerPoint slides next on the menu, warns MessageLabs...
Spam surge emanating from the Far East
Made in China...
US court upholds anti-spam law
Junks convicted spammer's appeal...
Spammers dust off their botnet passports
Targeting pastures new...
Stories from around the web...
Beware: You have mail Times Online
The economies of spam Global Politician
Special report: Fighting spam and cyberscams CNET News.com
Spam ain't dead yet PC Magazine
Slaying Spam-Spewing Zombie PCs PC World
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.
For more about the Research Panel and how to join, click here
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page