A new attack campaign has recently been launched by cybercriminals, who are trying to expand the Asprox of infected computers, relying on forged emails that lead to malicious sites, also known as phishing emails.
The scammers use a signal that supposedly comes from Facebook as a lure to inform the recipient that their password for the social networking site has been changed.
To make this communication more believable, cybercriminals include in the email original graphics from Facebook, and even a brief report on the suspicious activity that triggered the password change mechanism.
The report, signed by “The Facebook Security Team,” claims that an unidentified individual used the Opera browser on an Android device to access Facebook without the account holder’s permission. It also provides a fake IP address and an estimated geographic location from where the attempt was supposedly made.
Every geoIP lookup tool shows that the location in the email and the address are not the same. On the other hand, these indications are not likely to be immediately noticed by a normal user.
With this trap, the victim can change their password through a link that leads them to a form where they are asked to fill in their details to complete the process.
Instead, a file with an executable script is downloaded to the victim's computer. Asprox, also known as Kuluoz, was discovered in 2008 and is used by cybercriminals for various activities.

