Cybercriminals have launched a clever malware distribution that appears to be targeting businesses and their employees.
According to MX Lab, the malicious emails are titled "Important Update. Please Read" and inform recipients of a planned email service outage.
The messages state: "This is a planned outage for our MAIL Services Mon, 2 Dec 2013 11:30:14 +0300. Our MailServer is experiencing some issues today. It will be back up and running shortly. If you would like to keep your previously saved email you can download and save the backup from the attached file."
Beneficiaries believe that the notifications come from the IT department and may rush to open the attachment. This is a big mistake since the compressed file attached to the messages hides a Trojan.
Once it invades a computer, the malware begins the process of downloading other malicious components, including a piece of ransomware.
For more technical details about this campaign, see the MX Lab blog.

