Phishing campaign touts fake 'Heartbleed removal' tool
The program attached to the emails is actually a keylogger, according to Trend Micro
IDG News Service - Trend Micro is warning of a phishing campaign touting a "Heartbleed removal" tool, a nonsensical product that is actually malicious software.
The scammers are hoping to trick people who vaguely associate the nickname "Heartbleed" with a computer problem that needs to be fixed.
Heartbleed in fact was a large problem, but not one for desktop computers. It was a vulnerability in older versions of OpenSSL, a crucial piece of open-source software that enables encrypted communications between a computer and a Web service, indicated by the padlock in most browsers.
The Heartbleed flaw was especially dangerous since OpenSSL is widely used in operating systems, routers and networking equipment. The flaw could allow an attacker to pull potentially sensitive data in 64K chunks from a server, including login credential and private SSL keys.
Fixing OpenSSL required applying a server-side patch. End users only needed to change their passwords on Web services that were affected.
The phishing emails seen by Trend Micro have an attachment that is supposedly a software tool that removes Heartbleed, wrote Trend Micro's Gary Davis, vice president for global consumer marketing. The tool is actually a keylogger, which records keystrokes and sends the content to the attackers.
The phishing emails are suspicious for other reasons, though, which may diminish their pool of potential victims.
Davis wrote the emails have a subject line "Looking for Investment Opportunities from Syria," a country that has seen civil unrest for several years. Further in the pitch is a warning that people should run the attached program to ensure they're not infected with the Heartbleed "virus," he wrote.
Send news tips and comments to email@example.com. Follow me on Twitter: @jeremy_kirk
- Top 10 Reasons to Strengthen Information Security with Desktop Virtualization Regain control and reduce risk without sacrificing business productivity and growth
- Preventing Sophisticated Attacks: Anti-Evasion & Advanced Evasion Techniques McAfee Next Generation Firewall applies sophisticated analysis techniques specifically to detect advanced evasion techniques (AET).
- The Security Industry's Dirty Little Secret The debate over advanced evasion techniques (AETs) This report summarizes the findings of a McAfee commissioned research group to determine the level of understanding IT security professionals have about AETs...
- Demand More, Get the Most from the Move to a Next-Generation Firewall Beyond the basics in a next generation firewall, to protect your investment you should demand other valuable features: intrusion prevention, contextual rules, advanced...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!