October 27, 2009, 11:36AM

Facebook Password-Reset Spam is Botnet Attack

Virus hunters are raising the alarm for a large-scale spam attack that uses fake Facebook password-reset messages to trick PC users into downloading a dangerous piece of malware.  The malicious executable is linked to the Bredolab botnet, which has been linked to massive spam runs and identity-theft related attacks.

 Here’s a sample of the Facebook password-reset messages hitting e-mail inboxes this morning:

 

 

 

 

 

 

 

 

 

 

 

 

According to Websense, the address of the sender is spoofed to display “support@facebook.com,” a trick commonly used to trick targets into believing it’s a legitimate e-mail from the popular social network.

The messages contain a .zip file attachment with an .exe file that connects to two servers to download additional malicious files and joins the Bredolab botnet which means the attackers have full control of the PC, such as steal customer information, send spam emails. One of the servers is in the Netherlands and the other one in Kazakhstan.


Shorten URL: http://threatpost.com/en_us/lsp. Click to copy to clipboard or post to Twitter

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
Please enter the two words below to help prevent spam.
Incorrect please try again
Enter the words above: Enter the numbers you hear:

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy