Bogus Yahoo accounts
Bogus Yahoo accounts
R E L A T E D   C O N T E N T
ADVERTISEMENT

Spam scam creates Yahoo zombies

Junk mail fraudsters dupe users into setting up bogus Yahoo accounts

Robert Jaques, vnunet.com 01 Nov 2004
ADVERTISEMENT

Yahoo members have been warned of a scam in which spammers try to take over their email accounts by sending out fraudulent emails asking for verification of Yahoo account login details.

The email request, which claims to help Yahoo prevent automated registrations, tries to dupe users into creating email accounts from which spammers can then distribute large quantities of unsolicited email.

IT security firm MessageLabs warned that the emails contain a fake Yahoo.com URL that leads to a completely different site, but redirects through a Google URL three times to obfuscate the link.

It then redirects to another fake Yahoo web address that loads a real Yahoo help page with legitimate information explaining the code verification process.

This is followed by a fake pop-up window which shows the user a Yahoo picture ID and asks them to enter the code.

Alex Shipp, senior antivirus technologist at MessageLabs, said: "This scam is another demonstration of how spammers and fraudsters attempt to manipulate computer users into doing their dirty work for them.

"Not only do they try and turn innocent users' machines into zombies for spam distribution, but they want them to set up new email accounts for them as well.

"The advantages for a spammer include increased capacity and flexibility when sending spam, as well as making it harder to trace the spammers themselves."

According to MessageLabs, the Yahoo scam emails are currently being detected in relatively low volumes, possibly because the scammers are trying to maintain a low profile.

Email characteristics:

Subject: Automatic Yahoo identifier completion

Body text: Dear Yahoo! Member, We must check that your Yahoo! ID was registered by real people. So, to help Yahoo! prevent automated registrations, please click on this link and complete code verification process: [URL removed] Thank you.

See also:

Zombie PCs are used to send spam or launch denial of service attacksQuarter of all PCs infected with zombies located in EU  27 May 2005
Social engineeringStudy reveals junk mail tactics becoming ever more sophisticated  10 Nov 2004
419 scammer stole £2mDo not pass go, do not collect £2m  08 Nov 2004
Jail sentence for US spammerNorth Carolina man amassed $24m through bulk email scams  04 Nov 2004
Can-Spam lawsuitsSoftware giant joins AOL, EarthLink and Yahoo!  29 Oct 2004

All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities