Tuesday, January 20, 2009

Malware preys on Obama-mania

Today is an exciting and historical day in the United States (and the World). In just a few hours we inaugurate an African American man, Barrack Obama, as our 44th president. The nation feels a surge of hope, believing that the new administration will begin to correct some of the woes currently afflicting our country. Leave it to a few despicable malware authors to corrupt that hope, and twist it toward their ill-conceived purposes.

According to a ComputerWorld article, attackers have setup fake Obama/Biden campaign web sites, hoping to lure victims to a malicious drive-by download site. A blogger at MX Logix first noticed this attack. It arrives as spam email with Obama related subject lines. The subjects suggest that Obama has decided to decline the presidency. Some subject examples include:

  • Barack Obama abandoned sinking ship
  • Who will be our president now?
  • Obama doesn't wany anymore to be a president (The misspelling is the attackers, not mine)
If you click the links within these fake Obama emails, you end up at what appears to be the Obama/Biden campaign web site. However, every link on the web site points to a malicious executable file. If you download and install this executable, it infects your computer with the Waledec worm, which experts believe is the latest worm by the Storm authors. In other words, you'll become a botnet zombie.

It still never fails to amaze me how low these attackers will stoop to infect new victims. While I encourage you to celebrate Obama's historical inauguration, be careful where you go while doing so. That seemingly innocuous Obama web site could add you as a drone in another botnet army.

0 comments: