Fake UPS tracking notification email carries malware

  • 27 October 2015
  • 2 replies
  • 2 views

Userlevel 7
Badge +54
Another airing of this menace. We may have posted this type of thing before but obviously as long as it is being successful for the crims, people still need reminding occasionally.
 
Graham Cluley | October 27, 2015
 
Windows users are advised to be on their guard, after a new malware campaign was spammed out posing as an email from UPS.
 
Of course malware being distributed disguised as notifications from delivery firms like UPS, Fedex and DHL are nothing new - but that's never going to stop criminals from using the technique to trick unsuspecting computer users into clicking on attachments.
 
After all, if it's working for them why should they change their tactics?
 
Simply receiving the email won't infect your computer, but if you open the .DOC file attached then your system could be put at risk from a Trojan horse embedded as an OLE object, which in turn attempts to download further malicious code onto your PC.
 
                    


 
Full Article

2 replies

Userlevel 7
Good article.....in the past I've used UPS and as you know they supply a tracking number and URL to track your package. Now what is important they DO NOT provide a DOC file when they send you a email, so this is the key to be suspicous of.
Userlevel 7
@Antus67 wrote:
Good article.....in the past I've used UPS and as you know they supply a tracking number and URL to track your package. Now what is important they DO NOT provide a DOC file when they send you a email, so this is the key to be suspicous of.
If I am not mistaken, UPS has now gone more secure in the tracking URL's.  The last time I had a package several months ago, I was not able to access the tracking information without an online account.  Of course as soon as I created the account to be able to track the package, the original email address to which the tracking URL was sent got a notification that the tracking details were being accessed.
 
I thought it was pretty cool.

Reply