HomeSecurityBeware of malicious emails titled Boston Marathon bombing

Beware of malicious emails titled Boston Marathon bombing

A few hours ago, Oracle released its April security updates attempting to patch over 40 Java vulnerabilities. However, it's likely that many people haven't upgraded to the latest version yet, giving hackers "open windows" to gain access to their computers.

Boston-Marathon-Emails MalwareA perfect example is the latest malicious campaign that leverages the recent Boston Marathon bombings to distribute malware.

According to experts at security firm Avira, it all starts with an email titled: “Boston Marathon Explosion.”

The messages contain links to files named “boston.html” or “news.html,” which are hosted on unsafe websites. These websites are designed to distribute malicious .JAR files that first check if the victim’s computer does not have the latest version of Java installed and then start downloading other executable files.

"JAR files exploit a vulnerability in Java. The first part of the attack even affects Apple Macs," Avira's Sorin Mustaca told Softpedia.

“The second part of the attack continues by executing the downloaded file. It is a Windows PE and thus only affects Windows computers.”

The file is identified by Avira as TR/Crypt.ZPACK.Gen.

It is worth noting that there are many variations of this malicious campaign that is currently circulating very widely. There are reports from Kaspersky, Conrad Longmore of Blog Dynamoo, from Trend Micro and Sophos. They have analyzed many emails and in each case they found many differences.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS