Wednesday February 10, 2010 2:35 AM AEST
 
Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Phishing scam targets Better Business Bureau

  • Email a Friend
  • Print Page
Phishing scam targets Better Business Bureau
By Jim Carr
May 31, 2007 12:50 PM
Tags: Phishing | scam | targets | Better | Business | Bureau
For the second time this year, the Better Business Bureau (BBB) is at the center of spam campaign.
The spoofed emails, claiming to be about complaints made to the BBB by unhappy customers, attempt to entice recipients into downloading malware that can collect personal information from unwary consumers.

The spam email, which appears to be from the BBB, contains a Microsoft Word attachment.

Although the email claims the attachment contains additional information about the alleged complaint to the BBB, it is a  trojan downloader that installs a keylogger on the recipient’s PC.

In this scam, the spoofed email's subject line refers to a "complaint case number," according to Websense. The message body says, "You have received a complaint in regards to your business services. The complaint was filled by Mr Mark Williams on 5/21/2007. Instructions on how to resolve this complaint as well as a copy of the original complaint are attached to this email."

Once opened, the attachment downloads the trojan and the keylogger, which can steal personal information such as bank, PayPal or eBay login information as well as all interactive data sent to every site the recipient visits, and sends the data to an IP address in Malaysia.

"The BBB ensures that despite the alarming amount of spoof emails that have been received, BBB database information has not been compromised," the organisation said on its website. "The BBB is currently working with the Electronic Crimes Task Force to track down the spoofers."

Although phishers continually change their tactics, the scammed addresses include complaints@bbb.org, compl-srv@bbb.org, complains-serv@bbb.org, consumercomplaints@bbb.org, and operations@bbb.org.

"This could be the work of the highly sophisticated loosely organised crime groups who basically wake up every morning trying to think of new creative ways to scam American consumers," said Avivah Litan, a vice president and research director in Gartner Research.

"They could very well be the same folks that launch highly technical attacks against retailers, like TJX.

"In our last consumer survey, we spotted a trend in which the scammers are using less conventional methods for phishing attacks that do not use well-known brands like banks, brokerages or PayPal," added Litan.

"This is due to the fact that the large known brands spend considerable resources identifying phishing sites and taking them down before they can do much damage."

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Messaging Whitepapers