Amazon shipping update email spreads malware attack in time for Christmas

Filed Under: Malware, Spam

With Christmas just around the corner, plenty of people will be buying last minute presents from online stores like Amazon. As you buy presents for loved ones online, you're always slightly nervous if the gift is going to arrive on time.

And that's just what malicious hackers are preying on today.

Researchers at SophosLabs have intercepted a malware campaign that has been spammed out, pretending to be a notice from Amazon.com.

Shipping update for your Amazon.com order

The emails, whose headers are forged to pretend to come from order-update@amazon.com, have the following characteristics:

Subject: Shipping update for your Amazon.com order
Message text: Shipping update for your Amazon.com order [number]
Attached file: Shipping documents.zip

Whatever you do, however, don't open the attached ZIP file as it contains malware. Sophos detects it as W32/AutoRun-BHY and the ZIP file as Troj/BredoZp-BD.

Remember that cold-hearted cybercriminals don't give a fig about it being Christmas. For them it's just another opportunity to fleece the unwary by infecting their computers, stealing data and taking over PCs for their own devices.

, , ,

One Response to Amazon shipping update email spreads malware attack in time for Christmas

  1. Robert Wurzburg says:

    This one or a variation of it is making the rounds again, May 2012:
    http://nakedsecurity.sophos.com/2010/01/11/amazon...

    Do Not even open these types of emails. The order number is randomly generated to
    make it look as it is sent to only you. If your friends get these the order number will be
    different, everything else looks the same. Even multiple emails to you will have a new
    order number every time!

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <pre> <q cite=""> <strike> <strong>

About the author

Graham Cluley has worked in the computer security industry for more than 20 years, developing anti-virus software and doing quite a lot of talking about internet threats. He's won awards for his blogging, but is proudest of the text adventure games he wrote when he was still wearing short trousers. You can learn more about those (the games, not the trousers) at grahamcluley.com. Send Graham an email, subscribe to his updates on Facebook, follow him on Twitter and App.net, and circle him on Google Plus for regular updates.