New Malicious Spam Exploits Craigslist

Written by Sue Walsh on August 18, 2009

cl-logoA new malicious spam attack is exploiting the popular site Craigslist. The messages arrive with the subject line “Re: Car For Sale on Craigslist” and with a message that look like a reply to an inquiry about a car for sale on the site. A link within it claims to direct the recipient to photos of the vehicle on Picasa. The link instead leads to a malicious site that downloads a Trojan on to the visitor’s computer.

It’s not yet known who’s responsible for this latest wave of malicious spam, but experts are warning people to be very cautious. Only 13 out of 41 virus scanners caught the virus, meaning that having an up to date virus program may not be enough to protect you. Obviously if you or your company hasn’t inquired about a car for sale on Craigslist you should immediately delete any such messages.

This is only one of several new viruses discovered recently, including one that targets AutoCAD software, and experts say the amount of malware found on the net is only going to rise.

          “Criminals see a better bottom line with more files,” security researcher Sean-Paul Correll said, adding that there are more viruses because the malware writers have automated the creation of virus variants. They are releasing polymorphic engines to distribute a massive number of unique samples… They hope to subvert antivirus lab technology by releasing a large number of samples.”

This has led some virus researchers to proclaim that virus signatures, which are currently the best way to classify threats, will soon be useless. If that happens researchers will have to come up with new ways to find and fight threats.

Comments

George Saufley December 16, 2010

What were the names of the 13 companies that caught the virus and malicious spam attack is exploiting the popular site Craigslist?
Out of the thirteen companies had software that could be used to
stop the virus.

Darren Cook January 12, 2011

This issue I think is less about the virus being used or whether it is picked up by scanner, and more about educating people about common sense precautions on the net.

Terri Tyler October 19, 2011

Other spam topics fournd in the past week:
1. Subject: Househelp/Personal Assistant is urgently needed.

2. I saw your ad on Craigslist and thought we could work together.

Just in case you need a photographer for any reason I wanted to offer you my services.

I am also willing to trade services so let me know your offer if any.

I can photograph any event, person or products you need to promote your offer.

Sorry if this is the second time you recieved this email, just wanting to work with people like you.

Check out some of my work;
3: Subject: Craigslist – Your account is on hold

Craigslist – Your account is on hold

Your Craigslist account is temporarily suspended.

*Essentially you posted the same item to multiple cities or categories, or more than once in 48 hours .

*Your post contains a link or URL to a commercial website or auction.

*Your ad appears to contain a phone #, email address, or URL .

  • (required)
  • (required)