Apple iPhone
An email scam is luring users with the promise of a free iPhone

iPhone scammers start digging for gold

The email scams begin ...

Written by Shaun Nichols in California

Online criminals have wasted no time in exploiting Friday's much-hyped launch of the iPhone

The Sans Internet Storm Centre has warned of an email scam that lures users with the promise of a free iPhone. 

Recipients who click on the link in the message are guided to a webpage that attempts to exploit several known flaws in Microsoft's Internet Explorer browser to recruit the victim to a botnet.

A second attack uses a mixture of social engineering, malware and cross-site scripting to defraud victims.

The attack is launched when a user visits a specially crafted web page that attempts to exploit a number of previously disclosed vulnerabilities in Internet Explorer 6 and 7 to install a Trojan application. 

The Trojan activates every time the user visits Yahoo.com or Google.com, at which point a pop-up is launched advertising a site named iPhone.com. 

Normally, www.iphone.com will redirect to Apple's iPhone page, but the Trojan spoofs the iPhone.com domain name and directs users to a fake retail site claiming to be iphone.com and using Apple's logo and iPhone images. 

After filling out the fake order forms, users are instructed to send payment via wire transfer to an address in Latvia in order to receive the iPhone.

Eric Sites, chief technology officer at Sunbelt Software, urged users to install the latest security updates for their browser and operating system, and use firewall and antivirus software. 

The attack currently targets Internet Explorer, but Thomas said that Firefox users should also be vigilant, as the group believed to be behind the attacks has used Firefox exploits in the past.

See also:

reader comments

related articles

Apple iPhone

Special Report: Apple iPhone

All the latest news on Apple's iPhone 18 Dec 2007

 

iPhone launches to great fanfare

Customers finally get their hands on Apple smartphone 29 Jun 2007

Hundreds queue up for 'iPhone day'

'Putting the circus back in media circus' 29 Jun 2007

vnunet.com analysis: will iPhone ring up the sales?

Industry analysts get to the core of Apple's mobile phone 29 Jun 2007

Expert warns of new Mac malware

Fake security app may be on the way 17 Oct 2008

Malware writers spoof Firefox plug-in

Phony add-on attack attempts to steal bank details 05 Dec 2008

Malware creeps into LinkedIn

Fake profiles act as bait for attack sites 07 Jan 2009

latest news

Ballmer highlights aims for New Year

Ballmer announces Windows 7 beta and future alliances designed to improve information sharing 08 Jan 2009

Active Storage completes UK Jigsaw

Jigsaw unveiled as Raid vendor's first non-US Platinum partner as it launches in Europe 08 Jan 2009

Dell quits Irish production

Vendor to slash 1,900 jobs in Limerick as it migrates assembly for EMEA customers to Poland 08 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation