Cybercriminals have spammed out a malicious Trojan horse, via an email claiming to offer season’s greetings and photographs of a woman wearing a bikini.
As many people return to their desks following the holiday break, there is a danger that they will find a dangerous email lurking inside their inbox alongside the regular mountain of spam.
In the following example, intercepted by SophosLabs, the malicious email claims to come from Selma. (Or is it Gretchen?)
Subject: HAPPY NEW YEAR
Ciao mia cara!
Come stai? Come promesso, ecco le mie foto bikini. Spero che sarà love it!
Questo è il mio umile dono per il nuovo anno! Ci vediamo più tardi 🙂
Il tuo amore Selma
01.01.2013 16:04:43
Here’s another example, claiming to be a belated Christmas greeting:
Subject: Merry Christmas
Hello my dear!!!
How are you? As I promised, here's my bikini photos. I hope you will be love it!
This is my humble gift for Christmas! See you later 🙂
Your love Ciara
28.12.2012
Although the emails are written in different languages (in the above examples, Italian and then English) the message is the same – here are the photographs of me wearing a bikini that I promised you.
Attached to the emails is a file called Bikini.zip, which contains a suspicious Windows screensaver – Bikini.scr, which contains a variety of encrypted strings.
Of course, a screensaver (.SCR) file is executable – so running the program can put your computer at risk.
Sophos products are being updated to detect the malware as the Troj/Agent-ZMO Trojan horse, but my advice would be to always be careful opening bikini screensavers, especially when they arrive via unsolicited emails from people you don’t know.
Bikini image from Shutterstock.
This proves hackers will never stop at anything to infect a user's computer.
Now if users would stop thinking of those 'bikini photos' for a second to notice all those grammar errors and the fact that the file is a `.scr`…
"I hope you will be love it" Do hackers ever learn grammar?
Opening an executable from someone you don’t know is a failure of your first line of security defense — your brain is off line.