Cybercriminals, now skilled in social networking, are targeting corporate users by luring them with fake emails purporting to come from the Microsoft Volume Licensing Service Center, informing the recipient that they have been granted administrative rights to manipulate sites and data on the network.
The message, which is supposed to be from Microsoft, includes a personalized greeting, which is a sign of trust and authenticity, since cybercriminals are less likely to have information about the customer.
Additionally, the victim customer's email address is available in the URL, adding credibility.
The URL is actually a hyperlink that, when the user hovers over it, reveals the real destination, which leads to a WordPress server. A total of four domains have been used to host the malicious file, as observed by Cisco security researchers.
To dispel suspicions of malicious activity, the hackers also added real Microsoft Volume Licensing Service Center pages to these sites, along with the malicious download.
Martin Nystrom, a senior director at Cisco, points out in a blog post published on Monday that the origin of the download reveals the scam, but most users won't notice this since the immediately visible elements appear to be legitimate.
Cybercriminals not only havesocial engineering, but they also seem to be good at coding malware. Detection of the malware in Microsoft Volume Licensing was quite low, Nystrom reports, saying that only 9 out of 57 software were able to detect it as a threat.

