More than 100 people have died and more than 190 are still missing after the sinking of the South Korean ship last week. As with all headline-grabbing stories, this incident, too, has been exploited by cybercriminals.
Trend Micro experts report that they have detected the first spam emails, just hours after the incident was reported in the media. What is interesting about the impact of this criminal enterprise is the fact that the ship is not mentioned in the content of the email, but at the bottom of the page.
The messages have the subject line “Notice of appearance in court” and inform recipients that they must attend a court hearing. These types of malicious notices have been circulating for months, which means that many spam filters are likely to detect and block them.
However, with the addition of the boat incident, cybercriminals are hoping to evade filters.
The malware attached to the messages is detected by Trend Micro as BKDR_KULUOZ.SMAL. Once it infects a computer, it can be used by cybercriminals to perform various tasks, including downloading other malware, such as fake antivirus programs and the infamous ZeroAccess Trojan.
