Online criminals are wasting no time in tagging onto the hyped launch of the iPhone.
The SANS Internet Storm Centre is warning of an e-mail scam that lures in users with the promise of a free iPhone. Recipients who click on the link in the spammed email message however are guided to a webpage that attempts to exploit several known flaws in Microsoft's Internet Explorer browser to recruit the victim to a botnet.
A second attack uses a mixture of social engineering, malware, and cross-site scripting tactics to defraud victims.
The attack is launched when a user visits a specially crafted web page that attempts to exploit a number of previously disclosed vulnerabilities in six and seven to install a Trojan application.
The Trojan activates every time that the user visits either Yahoo.com or Google.com, at which point a pop-up is launched advertising a site named "iPhone.com".
Normally, www.iphone.com will re-direct to Apple's iPhone page. The Trojan however spoofs the iPhone.com domain name and directs users to a fake retail site claiming to be "iphone.com" and using Apple's own logo and iPhone photos.
After filling out the fake order forms, users are then instructed to send payment via wire transfer to an address in Latvia in order to receive the iPhone.
Sunbelt Software chief technology officer Eric Sites recommend that users install the latest security updates for their browser and operating system, and use firewall and antivirus software.
Though the attack currently only targets Internet Explorer, Thomas noted that users should also be vigilant, as the criminal group believed to be behind the attacks has also used Firefox exploits in the past.
iPhone scammers start digging for gold
By
Shaun Nichols
on Jul 4, 2007 7:00AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

Kaseya Dattocon APAC 2024 is Back

Tech For Good program gives purpose and strong business outcomes

Channel can help lead customers to boosting workplace wellbeing with professional headsets

Secure, integrated platforms enable MSPs to focus bringing powerful solutions to customers

Build cybersecurity capability with award winning Fortinet training from Ingram Micro
Sponsored Whitepapers

Easing the burden of Microsoft CSP management
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management