Spammers use Boston bombing, Texas fires and other human tragedy to spread malware

Screen Shot 2013-04-22 at 10.51.50 AMAnd in this week’s edition of “Dirtbags of the Internet,” malware spammers are using the Boston Marathon bombing to spread malicious programs. 

How are they doing it? They send messages out with subject lines promising a video of the explosions. And if you click on them, you do see genuine footage of the blasts – while a Windows Trojan Horse infects your computer. Security experts Sophos’ Naked Security blog details how the malware works – and  Betabeat counseled readers to pass this information along to AOL-using aunts and forward-enthusiast uncles.  

Watch out for emails labeled “Aftermath to explosions at Boston Marathon” and “Explosions at Boston Marathon” – even if they appear to be normal, working links, they may still liberally douse your computer in malware. 

Malwarebytes.org reported that the Boston explosion wasn’t the only horrible thing to happen last week that scammers exploited. They also used the large-scale factory fire in West, Texas as bait for digital rubberneckers, promising footage of the blaze but secretly infecting people who clicked.

We talked to Malwarebytes’ Senior Security Researcher Jerome Segura, who confirmed our suspicions that the same people behind the bombing malware are behind the Texas bait. “It is correct to assume the same guys are behind the Boston Marathon and Texas explosion fake emails. The spam emails came from at least two botnets: Kelihos and Cutwail which sent an unusual amount of spam following each event. It’s worth noting that both of these botnets had been previously shutdown but have come back to life. There are many different groups behind these attacks, but most of them are located in Eastern Europe.”

And there’s more dirtbaggery afoot: According to Boston Magazine, someone is trying to sell a Facebook page memorializing the Boston bombing for $1,000, an example where greed completely tramples good taste and human decency.

“When users click the link to view these videos, they get redirected to a site that contains the Redkit exploit kit, a platform used to run multiple exploits on the victims’ machines and take advantage of one of many vulnerabilities in the browser and its plugins,” Segura explains. 

“Once the machine is compromised, malware is downloaded and run. In this particular case we observed fake antivirus as well as the ZeroAccess Trojan. The former scares the victim into thinking their PC is infected and blocks access to many programs. The goal is extort between $30 to $80 out of their victims. The latter is more discrete and uses the computer’s resources to mine bitcoins, a digital currency obtained by conducting digital computations requiring a lot of computing power and therefore slowing down to a crawl the victim’s PCs.”

People have always tried to capitalize on tragedies, and the Internet just makes it a lot easier. Although news like this can be seriously disheartening, it’s important to remember that for every fake Boston Marathon Twitter account trolling for RTs, there were more people seriously looking for ways to help victims. 

And if you’re still bummed out, read the wise words Patton Oswalt posted on his Facebook page after the incident: Screen Shot 2013-04-22 at 11.13.37 AM

Smart Home

Can new laws protect you from smart home security breaches?

To help combat smart home data breaches, state and federal lawmakers are exploring ways to protect consumers. California, Oregon, and members of the U.S. Senate all have proposals to protect people's data.
Deals

Ultra Wideband is here, and you can use it with the 5G Moto Mod (and save $150)

5G is rolling out in the U.S., and Motorola’s Moto Z3 is one of the few phones that can use it. Select people can take advantage of Verizon’s 5G service and enjoy a $150 discount with the purchase of a Moto Z3 and 5G Moto Mod bundle.
Cars

21 charged in Chicago carsharing heist; 100+ cars stolen, many still missing

More than 100 Mercedes-Benz vehicles belonging to carsharing service Car2Go were stolen in Chicago. Police are still working to recover all of the cars, which are equipped with GPS, and 21 people have been charged.
Emerging Tech

Drown out noisy neighbors and rest easy with these white noise machines

Some people are more sensitive to sound during sleep than others. Luckily, there are a number of white noise machines on the market to mask the noise. Here are our five of our current favorites.
Social Media

Looking to officially rid your inbox of Facebook messages? Here's how

Deleting messages from Facebook Messenger is almost as easy as scrolling through your News Feed. Here, we show you how to delete an entire conversation or a single message, both of which take seconds.
Social Media

LinkedIn: Now you can express love, curiosity, and more with new Reactions

LinkedIn is following in the footsteps of Facebook (three years later!) with the rollout of new reactions that give users more ways to express themselves when responding to posts in their feed.
Social Media

Twitter’s experimental Twttr app is even more popular than the real thing

Twttr, the new app that lets regular Twitter users test new features, is proving more popular than the main app, according to the company. The revelation suggests some of the innovations may land for all Twitter users soon.
Social Media

Messenger and Facebook, together again? Facebook tests integrating chats

Longing for the old days where Facebook and Messenger were one app? Facebook is testing an integrated chat option. While Messenger remains more feature-rich, the test brings some chat functionality back into the Facebook app.
Social Media

How to download Instagram Stories on iOS, Android, and desktop

Curious about how to save someone's Instagram Story to your phone? Lucky for you, it can be done -- but it does take a few extra steps. Here's what you need to know to save Instagram Stories on both iOS and Android.
Social Media

Facebook, Instagram, and WhatsApp went down worldwide for 2 hours this morning

Chaos erupted on the internet this morning, as Facebook, Instagram, and Whatsapp all went down from 6:30 a.m. to approximately 9 a.m. Thousands of users were unable to access the sites or send or receive Whatsapp messages.
Mobile

Skype screen sharing for mobile will let you share your swipes on dating apps

Skype is prepping the launch of screen sharing for mobile so you can share your swipes on dating apps, shop with buddies, or, perhaps, show a PowerPoint presentation to coworkers. It's in beta just now, but anyone can try it.
Social Media

Facebook toys with mixing Stories and News Feed into one swipeable carousel

Facebook's News Feed could look a lot like Stories if a prototype the social media giant is working on rolls out to users. The design change mixes Stories and News Feed posts into a full-screen slideshow that users swipe left to navigate.
Social Media

No more moon showers as Facebook Messenger’s dark mode gets official rollout

Facebook Messenger launched a dark mode last month, but to activate it you had to message the crescent moon to someone. Now it's been rolled out officially, and it can be accessed in a far more sensible way — via settings.
News

Twitter has revealed a launch date for its handy hide replies features

Twitter has revealed a launch date for a feature that lets users hide replies to their tweets. The hope is that it will help the original poster filter out offensive or irrelevant content from conversation threads.