WARNING: Google, LinkedIn, Skype, Mass Effect 3 linked to malware attacks

Updated happygeek 2 Tallied Votes 508 Views Share

The latest VIPRE report, detailing the ten most prevalent malware threat detections spotted by GFI Labs and the ThreatNet Detection System, reveals that Google, LinkedIn, Skype and Mass Effect 3 were amongst the big brands being exploited by cybercriminals in order to leverage trust whilst distributing malware-laden emails. As a consequence, GFI software is urging users to question absolutely any and every unsolicited message regardless of the subject matter or purported origin.

masseffect The research labs team has documented a high number of spam and malware distribution campaigns during the month of March which have successfully infiltrated users' systems disguised as communications from well-known companies or pretending to be promotions for their services and products.

Christopher Boyd, the senior threat researcher at GFI Software, warns that Internet users are "bombarded with countless emails every day" and these campaigns are exploiting the "reflex-like tendency to click on links and open emails that look like they’re coming from a company we know and trust."

Take Google, for example, which was linked to such malware campaigns by being used as the hook for a couple of nasty scams that Google systems had detected malware on their computer and then, you guessed it, did the old rogue-antivirus thing and directed them to a site where the payload product could be downloaded. There were even emails being sent that claimed to come from Google Pharmacy, which doesn't exist, and offering services as a pharmaceutical interface for the search engine. This being image spam meant it could circumvent many spam filters, and if the user visited the URL shown in that image they were re-directed to an online pharmacy with a historical link to spam tactics dating back to 2004 according to GFI Labs.

LinkedIn, meanwhile, was exploited by scammers using fake invitation reminders which re-directed unsuspecting users to a blackhole exploit which infected their computers with a banking and social networking Trojan called Cridex. Skype found itself caught up in the malware mess after a spam campaign was launched that targeted Skype users with free credit and directed them to a malicious Java exploits host site instead.

One of the most targeted brands though was Mass Effect 3, with fake alternative ending downloads being the scam of choice and leading to marketing surveys and other ad-revenue raking sites. “If something seems off, users should trust their instincts and investigate further” Boyd advises “The important thing for everyone to remember is that the Internet provides us with the ability to easily double check every link or attachment that we come across with a simple web search. Pay attention to details such as link URLs and scrutinise where they are directing you if there is any doubt. This may sound like common sense, but having this mind set can often be the difference between avoiding a stressful attack and losing valuable time, money and personal information.”

Dani AI

Generated

Good summary from — the VIPRE/GFI write‑ups described a classic pattern: convincing, brand‑looking lures that lead to compromised pages and exploit chains. That combination (social engineering + drive‑by exploits) keeps working because it targets human trust and unpatched browser plugins. ’s instinct to remove or disable Java is exactly the kind of risk‑reduction that helps. GFI/VIPRE summary (coverage) · [industry writeups on drive‑by/exploit trends].(https://securelist.com/monthly-malware-review-march-2012/36064/)

Why it succeeds: attackers use image‑based spam or “fake update/download” pages to bypass filters, then redirect browsers (iframes/JS) to exploit kits that weaponize outdated plugins. Java was a frequent target and browser vendors and security teams advised disabling the Java browser plugin until patched. That is a structural weakness, not just a single campaign. Mozilla security note on Java risk · [Kaspersky analysis].(https://securelist.com/monthly-malware-review-march-2012/36064/)

Practical, immediately usable advice:

  • Remove or disable any browser plugin you do not need (Java/Flash); use click‑to‑play or a script‑blocker for untrusted pages.
  • Keep OS, browser and plugins patched, run reputable endpoint protection, and enable multi‑factor authentication on important accounts.
  • Don’t click links in unsolicited messages; verify invites/attachments through the service UI, and check suspicious URLs with services like VirusTotal or urlscan before visiting. Mozilla on disabling plugins · VirusTotal · urlscan.io

If a link was clicked or infection is suspected: take the machine off the network, run an offline/bootable scan (Microsoft Defender Offline or a rescue disk), then change all critical passwords from a known‑clean device and notify banks or affected providers; report identity/fraud issues via the FTC/IdentityTheft.gov workflow. Quick containment and clean‑device password resets limit downstream damage. Microsoft Defender Offline · Kaspersky Rescue Disk

Member Avatar for Member #949455
Member #949455

LinkedIn, meanwhile, was exploited by scammers using fake invitation reminders which re-directed unsuspecting users to a blackhole exploit which infected their computers with a banking and social networking Trojan called Cridex. Skype found itself caught up in the malware mess after a spam campaign was launched that targeted Skype users with free credit and directed them to a malicious Java exploits host site instead.

I read about it last year but I didn't think it would go to that extreme.

I don't have Java installed on my computer because of those malicious Java exploits websites popping up.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.