FDIC notification malware attack spammed out

Filed Under: Malware, Spam

Sophos's worldwide network of honeytraps are intercepting a large amount of malicious email, claiming to come from the Federal Deposit Insurance Corporation (FDIC). The emails are designed to infect recipients' computers.

Malicious FDIC notification email

Subject line:

FDIC Notification

Message body:

Dear customer,
Your account ACH and WIRE transaction have been temporarily suspended for security reasons due to the expiration of your security version. To download and install the newest installations read the document(pdf) attached below.

As soon as it is setup, you transaction abilities will be fully restored.

Best Regards, Online Security departament, Federal Deposit Insurance Corporation.

Attached to the emails is a file called FDIC_document.zip.

Sophos proactively detects the file, calling it Mal/BredoZp-B. Our advice is that you should not open the attachment as it will attempt to infect your Windows computer.

Take care folks, and remember to keep your security software up-to-date and your wits about you. You should always be suspicious of unsolicited email attachments.

, , ,

5 Responses to FDIC notification malware attack spammed out

  1. Sreekar Saha says:

    What about those who use web-based email like gmail or hotmail in their browsers?

  2. GordoK says:

    Bad grammar, punctuation, spelling are regular clues to bogus stuff like this. In this instance,

    "you transaction abilities" as opposed to "YOUR transaction abilities".

    "As soon as it is setup" as opposed to "set up".

    "Online Security departament" as opposed to "Online Security DeparTMENT".

  3. Keonyn says:

    Just got one of these, seemed like a pretty obvious malware attempt. They also apparently forgot to even attach the attachment to the e-mail; so double-fail on their part.

  4. Maybray Digital says:

    Good tip GordoK. Thanks.

  5. waydaws says:

    The attachment contained FDIC_Document.exe whic was somekind of Trojan downloader. Was there any followup analysis of what it downloaded?

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <pre> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

About the author

Graham Cluley is senior technology consultant at Sophos. The readers of Computer Weekly voted him security blogger of the year in 2009 and 2010, and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which was nice. He was also named "Best Security Blogger" by the readers of SC Magazine in 2011. You can subscribe to Graham's updates on Facebook, follow him on Twitter and circle him on Google Plus for regular updates.