Sergey Golovanov

Outlook Web Access Attack Using Pushdo Botnet

By Sergey Golovanov
Here are some technical details on the Outlook Web Access phishing scheme.
1. The Spam
According to our preliminary research, the spam emails which attacked OWA users, including Kaspersky, were sent using the pushdo botnet – which is based on malware from the Backdoor.Win32.NewRes family. These Trojans spread via spam, social networks (in conjunction with the Koobface family) and through hacked websites.