CERT mailing list archives
Current Activity - Malicious Code Circulating via Social Security Administration Phishing Messages
From: Current Activity <us-cert () us-cert gov>
Date: Tue, 24 Nov 2009 14:48:02 -0500
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 US-CERT Current Activity Malicious Code Circulating via Social Security Administration Phishing Messages Original release date: November 24, 2009 at 2:42 pm Last revised: November 24, 2009 at 2:42 pm US-CERT is aware of public reports of malicious code circulating via phishing email messages that appear to come from the Social Security Administration. The messages indicate that the users' annual Social Security statements may contain errors and instruct users to follow a link to review their Social Security statement. If users click this link, they will be redirected to a seemingly legitimate website that prompts them for their Social Security number. If users enter their Social Security number and continue to the next page, they will be given an option to generate a statement. If users attempt to generate a statement, malicious code may be installed on their systems. This malicious code attempts to collect online banking traffic to gain access to the users' bank accounts. US-CERT encourages users and administrators to take the following preventative measures to help mitigate the security risks: * Install antivirus software, and keep the virus signatures up to date. * Do not follow unsolicited links and do not open unsolicited email messages. * Use caution when visiting untrusted websites. * Use caution when entering personal information online. * Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams. * Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks. Users are encouraged to contact the Social Security Administration to verify the authenticity of any messages. Additional information will be provided as it becomes available. Relevant Url(s): <http://www.us-cert.gov/cas/tips/ST04-014.html> <http://www.us-cert.gov/reading_room/emailscams_0905.pdf> ==== This entry is available at http://www.us-cert.gov/current/index.html#malicious_code_circulating_via_social -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iQEVAwUBSww4X9ucaIvSvh1ZAQLpXggAjHQPUURyT2H5M1oFmBjwK4j30PHxboCA PZBEodaIrJcvslEs5h4611nPngMD5YVmZQRKA0JZrSLwPq3877GUHBN00PLN707Y HARXK7+YjkTgr4WMc+bq1WSdzgLW/G09eKSKvb6xc072ynsx9ovys/U1hCirKwaN owZL5U/Sl9Y4wd4qgl1FnDCgIzJroi7HVwhKT5s0sOLGP2mI8or/2cw397opl4ru GkewGaupTKd52cdddm16DpHOXFqh0Qayr1S1zajxOymsgjIrQ6sbGO37Tw+QHBMO l/Z3S0xYbNPUOaJ6uUC/ZOZqlcG5JkmmNzHuabXQ4U2RnW7w6QwS6g== =Cdvp -----END PGP SIGNATURE-----
Current thread:
- Current Activity - Malicious Code Circulating via Social Security Administration Phishing Messages Current Activity (Nov 24)