HomeSecurityAsprox operators target a larger Botnet

Asprox operators target a larger Botnet

Asprox

New emails that appear in inboxes at this time of year asking for confirmation of an order do not arouse suspicion, and the creators of the Asprox botnet to expand their network.

The attackers are using bait that is likely to "persuade" unsuspecting users, as they rely on the names of major US retailers to trick them into clicking on malicious links.

The current email attack mimics order confirmation messages from HomeDepot, WalMart, Costco , and Target, according to researchers from Malcovery.

Although the emails purporting to be from these stores look different, researchers noticed that sometimes there was confusion with the sender name. So, in an email that appears to be from Costco, the scammers used a sender name from WalMart. Additionally, researchers found that in an email claiming to be from Target, the sender appears as Costco.

For users receiving the malicious emails, these are clear signs that something strange is happening and could warn them of the risk of clicking on the embedded link.

According to a blog post by Malcovery, the attack distributed two versions of the malware. One version of the malware is available as an attachment, and the other is available from a website, via the URL contained in the message, which belongs to websites that have been attacked with the aim of spreading the malware.

After analyzing the evidence, researchers concluded that two different command and control servers were used for each version of the malware. They also found that one of the versions was actually an older Asprox Trojan.

Malcovery researcher Gary Warner says the attack is expected to evolve, especially since more recent samples include other brands, such as Krogers and Walgreens.

Since this is the holiday season, users are more likely to fall victim to these emails claiming to be informational about product orders. Cybercriminals know this and will try to take advantage, but there are ways to determine whether a message is a scam or not.

In addition to checking the sender's address, an activity that is more difficult to perform on smartphones, users should first consider whether they really expect any information from the vendor from whom the email appears to come.

The best way to check if the message is legitimate is to visit the brand's website directly from the browser and not by following the link contained in the email.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS