Connect with us

Hi, what are you looking for?

HEADLINES

Zika virus outbreak concerns used to spread malware

The country most notably affected by cases involving the Zika virus is Brazil, so it comes as no surprise that one of the first cases involving Zika-related malicious spam would focus on Brazilian citizens.

On February 1, the World Health Organization (WHO) declared a Public Health Emergency of International Concern (PHEIC) in response to the outbreak of the Zika virus and its associated birth defects in the Americas. Since this declaration, Symantec Security Response has observed a malicious spam campaign seeking to capitalize on the global interest in what the director of the WHO calls an “extraordinary event.”

The country most notably affected by cases involving the Zika virus is Brazil, so it comes as no surprise that one of the first cases involving Zika-related malicious spam would focus on Brazilian citizens.

Description: SymMacToolkit:Users:satnam_narang:Documents:SRBlogs:ZikaVirus:brazil_zika.png
Figure 1. Malicious spam email in Portuguese, delivered to Brazilians

The malicious spam email claims to be from Saúde Curiosa (Curious Health), a popular website in Brazil. The subject of the email says, “ZIKA VIRUS ! ISSO MESMO, MATANDO COM ÁGUA!” which translates to: “ZIKA VIRUS ! THAT SAME KILLING WITH WATER !” The email itself uses imagery and text taken from a real article on Saúde Curiosa, but includes buttons and attachments to try to capture the recipient’s attention, such as “Eliminating Mosquito! Click Here!” and “Instructions To Follow! Download!” as well as a file attachment.

Description: SymMacToolkit:Users:satnam_narang:Documents:SRBlogs:ZikaVirus:bitly_zika_js.png

Figure 2. Links in malicious spam email lead to a file hosted on Dropbox

Advertisement. Scroll to continue reading.

The links behind these buttons lead to the URL shortening service Bitly, which redirects to the file hosting service Dropbox. Symantec products detect both the file hosted on Dropbox and the file attached to the email as JS.Downloader. Once a user is infected with JS.Downloader, it will attempt to download additional malware onto the compromised computer.

Newsworthy events on a regional or global level often provide fertile ground for cybercriminals seeking to capitalize on the interest in these events. In this case, the Zika virus’ impact in countries like Brazil is being leveraged, while the potential impact in other countries make it a prime candidate for more malicious spam.

Symantec Security Response warns users to be aware of unsolicited messages about the Zika virus and to follow best practices.

For instance, for information about the Zika virus, visit the World Health Organization’s website. Also, always look for trusted news sources, regionally and globally, for additional information. Avoid clicking on links or opening attachments in unsolicited email messages. Lastly, run security software on your computer and ensure that it is up to date.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

PLDT and Smart’s full support for the recent Fiesta Señor and Sinulog Festival 2025 aligns with the PLDT Group’s commitment to fostering Cebuano faith...

HEADLINES

Acer secured a 34.2% market share in the consumer notebook category and a 40.6% market share in the gaming notebook category. This means that...

HEADLINES

Through the collaboration, OPPO will be the official mobile partner of CCP in its upcoming CCP University Roadshow, giving students an opportunity to enhance...

HEADLINES

Data from Packworks reveals over 175,000 stores actively transacted through its Sari.PH Pro app in 2024, representing a 32% increase from about 133,000 stores...

White Papers

According to the report, Iloilo stands out for its strong government support, with local policies and initiatives designed to foster startup growth, a model...

HEADLINES

In addition to providing grants and resources, the initiative will host activities and create platforms to foster innovation and collaboration in the local blockchain...

HEADLINES

Creativity and experience is a common AI activity theme among Filipinos with 48% using it for photo editing and 42% for both entertainment and...

HEADLINES

Converge will leverage Ribbon’s advanced Muse Multilayer Automation Platform (MAP) designed to maximize the value of IP Optical network investments through comprehensive control, analysis,...

Advertisement