McAfee researchers have identified a malicious campaign targeting organizations in the United Arab Emirates (UAE), Oman, Bahrain, and Caribbean islands.
According to experts, scammers send targeted phishing emails that have been designed to distribute malicious software that steals data from the victims' computers.
The attack starts with an executable file (emiratesstatement.exe) that disguises itself as a harmless PDF. When someone runs the .exe, it begins to install malicious applications on the computer, including a keylogger, a tool for retrieving passwords from the victim's email as well as a tool for retrieving passwords from the web browser.
During installation, the malicious software disables the Windows firewall.
The passwords that are collected are sent to an FTP server.
Security firm McAfee has found that cybercriminals are trying to steal credentials for webmail, Facebook, Hotmail, internal CRM systems, travel booking systems, news sites, government e-services, and firewalls.
