[Lowfer] News - Something Phishy

JD listread at lwca.org
Thu Apr 17 17:39:23 EDT 2014


Due to difficulties using his computer at present, Todd Roberts asked me to 
write to the group and let you know his e-mail got hacked recently, which 
accounts for the spurious message yesterday evening with the link to a bogus 
Web site in Spain.  It did not come from Todd's computer, nor even through 
his actual AOL e-mail account.  The spammers "spoofed" Todd's return address 
and apparently sent mail to a number of addresses they'd harvested from his 
contacts list.

The fake message actually originated from mijndomein.nl, a Dutch ISP that 
may (for all I know) cater to spam and phishing activities.  I would suggest 
to the qth.net administrators to block mail from that exchange, and 
encourage everyone to keep their virus scanners and malware removal software 
up to date to reduce the risk of this happening.

This is just one example of things the bad guys do when they hack your 
e-mail reader.  Another is to send spam with fake return addresses to people 
in the stolen contact list, but to include a subject line from a real 
discussion in which you had been a participant.  That way the unsuspecting 
target thinks it's a message from a trusted source, and blames the wrong 
party.  When they use this approach, the fraudulent mail may not even use 
the address of the person it was really stolen from.  It could appear to be 
from _anyone_ who was in that person's contact list, or even an e-mail 
reflector such as this one...even though it wasn't their computers that got 
hacked.

73
John 



More information about the Lowfer mailing list