Back to Forums








View Full Version : Worm variant targets PayPal users


Reverend
November 15th, 2003, 00:00 AM
A new variant of the MiMail worm, MiMail I, is spreading around the world. The worm attempts to trick people out of their credit card details by purporting to be from online payment services company PayPal, which is owned by eBay.

An email with the headline 'YOUR PAYPAL.COM ACCOUNT EXPIRES' claims that the company is implementing a new security policy. The email is especially sneaky in that it correctly advises people not to send out credit card details by email.But when the attachment in the email (www.paypal.com.scr) is opened the software displays a PayPal-branded window requesting all credit card information.The worm then mails itself out to all email addresses on the infected hard drive.

"It seems to be following the sun," said Graham Cluley, senior technology consultant at antivirus vendor Sophos. "Australia, New Zealand and South Africa are all getting hits, and here in the UK of course.It's not very widespread at the moment; hopefully people are getting smarter about this worm. What we don't know, however, is how many people are falling for it."

MiMail A, the original worm, was first detected in the wild in August and was originally used to harvest email addresses for spammers.

Removal utilities and virus identity files are available from major antivirus companies.

vnunet (http://www.vnunet.com/News/1148819)

Big Booger
November 15th, 2003, 13:06 PM
Good to know as I am an avid Paypal user.. I cannot believe the level that this con artists are going to to get your money..

It is getting to the point where no email can be considered legitimate... spam, crooks, and their ilk are making a toliet out of email and the internet alike.

cash_site
November 18th, 2003, 10:48 AM
Originally posted by Big Booger
Good to know as I am an avid Paypal user.. I cannot believe the level that this con artists are going to to get your money..

It is getting to the point where no email can be considered legitimate... spam, crooks, and their ilk are making a toliet out of email and the internet alike.
I agree, the weakest link in all security measures is the human element, "social engineering" the art of getting information, akin to "con job"

Just never! give out personal details, especially financial... was my pin 1111 or 2323 ?? :P