Articles by Brett Cove

About Brett Cove

Brett is a Technical Lead in the AntiSpam Operations team within SophosLabs. He has been working for Sophos since their acquisition of ActiveState in 2003.

One week later: Rustock and Pharmacy Express still flatlined

PharmacyExpressTitle-245x175

One week after the much publicized Rustock botnet command and control take down, and subsequent drop in spam volumes, SophosLabs can confirm Rustock has not come back from the dead.

Share

Targeted webmail phishing attacks

Man being phished

Targeted webmail phishing attacks are on the rise and are affecting more and more organizations.

Brett Cove, who works in the anti-spam operations team at SophosLabs, investigates why you should care about spearphishing, and how you can protect against it.

Share

Sue BP for damages resulting from the oil spill?

Default image

SophosLabs global network of spamtraps are now seeing "snow-shoe spam" promoting litigation services against British Petroleum (BP) relating to the Gulf of Mexico Oil Spill disaster. They are targeting anyone who may be negatively affected by the oil spill, and Read more…

Share

CNNIC changes have effect on spam tactics

Image (1) image001.png for post 24883

As was announced on Dec 11th, CNNIC (China Internet Network Information Center) now requires a "formal paper based application material when making the online application to the registrar." The motivation behind this seems more related to cracking down on porn Read more…

Share

Spam for the visually impaired

Default image

Starting at ~3:20pm GMT today, Canadian Pharmacy spammers began using attached MP3 files as the call-to-action for their latest campaign. The message had no subject, no "text" body content, just an attached "audio/mpeg" file with a random lower case file Read more…

Share

Conficker Infection Alert!!

Image (1) picture-26.png for post 23480

With all the hype around Conficker recently, it should come as no surprise that scammers are using this highly publicized threat to attempt to spread more malware. We've been seeing spam spreading fake AV malware for quite some time, typically Read more…

Share

Beyond the botnet

Beyond the botnet

As reported by Shara Grifenhagen over at Commtouch, spammers for the last week have been abusing not only Google Docs (again) but also what appears to be a "recommend this to a friend" mechanism at ZDNet's web site, somehow finding Read more…

Share

My spam run is bigger than your spam run

Image (2) picture-3.png for post 19873

For the past two weeks SophosLabs have been monitoring a specific spam campaign employing thousands of shocking subject lines, and a link to one of thousands of compromised hosts serving up malware. This campaign has also changed the filename the Read more…

Share

Critical Microsoft update via Amazon EC2?

This past weekend a fairly typical malware campaign started to arrive on our global network of spam traps, using the common technique of disguising itself as an "Important Windows Update". Its characteristics are mostly what you would expect from spammed Read more…

Share

April Fools Dorf

Image (1) picture-1.png for post 19745

April Fools Day is an opportunity for many to play practical jokes on each other. Unfortunately it's not just harmless pranks, but malware authors are also jumping on the bandwagon. Those behind the "Dorf" malware have decided to make use Read more…

Share

Side of spam with your Dorf?

Image (1) sample-dorf.png for post 19725

As we've blogged about previously, the current form of the constant flood of Dorf spam has been taking advantage of Valentine's Day which is quickly approaching. An interesting twist observed by SophosLabs this week is the same IP addresses used in Read more…

Share

Return Of The Dorfs: A Christmas Special

Image (3) picture-20.png for post 21545

Today spamtraps monitored by SophosLabs received samples of a malware campaign spammed out using the combination of the holiday season, and the promise of a "Personal Holiday Strip Show" in an attempt to infect computers. The format of the messages Read more…

Share

Become an honourable "Donation Collector"

Image (1) redcross_nigerian4.png for post 21516

In SophosLabs, we constantly observe a steady stream of money mule/Nigerian scam campaigns. Usually these emails offer some part-time position to "process money from our overseas customers" or that some grant/prize money from a charity/lottery is coming along. Today however, Read more…

Share

US Presidential candidate spamming?

Default image

We all know most involved in politics use email as a method to fund-raise, communicate with their supporters, garner more support, etc.. More often than not, these parties send to lists mostly consisting of people that asked for their mail Read more…

Share

PDF spam no more?

Image (1) pdf-hit-report.jpg for post 21082

Over approximately the past 2 months, PDF spam has exploded from a little used technique to making up close to 30% of all spam being sent during its peak (averaged daily). Due to spammers adjusting their campaigns, the volume of Read more…

Share

4th of July Ecard

Image (1) ecard-july3.png for post 19648

The current trend of spreading malware via "Ecards" (greeting cards that can be sent and read online via email) continued in huge volumes today (As previously reported here: A not so friendly Ecard, and here: Ecards continue to flood in). Read more…

Share

Bogus Microsoft Security Bulletin

Image (1) microsoft-update500.jpg for post 19639

A highly targeted fake Microsoft Security Bulletin is being spammed out today. The campaign is attempting to appear as a notification for a new "0-day vulnerability" for Microsoft Outlook, but in reality its purpose is to install a Windows-based Trojan. Read more…

Share

Endless phish targets

Image (1) yahoo-phish.png for post 19613

With widespread adoption of accurate spam filters, improved public awareness, and most big financial institutions implementing improved online security features, scammers are being forced to adjust their tactics. One such tactic SophosLabs is seeing, is a consistent flow of new brands being targeted in phishing Read more…

Share