iTunes Malware Kicks Off Christmas Scam Season

Scammers are taking advantage of the Christmas shopping season with a flood of malware-bearing emails disguised as iTunes gift certificates, according to security experts.

The email arrives on the eve of Thanksgiving in the United States, which customarily kicks off the Christmas gift-shopping season in that country and elsewhere.

Disguise

It appears to come from a legitimate email address – official@itunes.apple.com – and contains an attachment called Gift_Certificate_iT9581.zip that pretends to offer $50 (£32) of credit at the iTunes Store, according to German security firm Eleven Security. When the file is launched it deploys an malicious executable file, Eleven said.

The malware, which Sophos has identified as Mal/BredoZp-B, creates a backdoor into a user’s system that can be used to download more malicious code, according to security vendors.

The message contains plain text only, with no graphic elements, Eleven said. The company said about half of the emails it detected originated from US IP addresses, with another 10 percent from the UK.

“As the holidays ramp up, so do scams like this,” wrote Sophos blogger Lisa Vaas. “It’s understandable that cash-strapped holiday shoppers might be click-happy enough to try to lighten their holiday with $50 worth of free music, video and games.”

Mal/BredoZp-B has been used in several other spam campaigns, including fake notifications from the US’ Federal Deposit Insurance Corporation in August.

Fraud shutdown

Earlier this month the Metropolitan Police’s Central e-Crime Unit (PCeU) said it had shut down more than 2,000 fraudulent e-commerce websites ahead of the Christmas shopping season, the latest move in the unit’s long-running battle against counterfeiting and fraud.

The PCeU worked with registrar Nominet to identify and shut down the site, but said no arrests were made. The police and Nominet would not name the sites which were taken down – but hinted that a future change might bring in “name and shame” publication of the culprits, as a result of the Nominet’s current review of criminal takedown rules.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Apple iPhone Q1 Sales In China Fall 19 Percent, Says Counterpoint

Bad news for Tim Cook, as Counterpoint records 19 percent fall in iPhone sales in…

49 mins ago

President Biden Signs TikTok Ban Or Divest Bill Into Law

TikTok pledges to challenge 'unconstitutional' US ban in the courts, after President Joe Biden signs…

3 hours ago

UK CMA Seeks Feedback On Microsoft, Amazon AI Partnerships

British regulator invites feedback on major partnerships Microsoft and Amazon have struck with smaller AI…

19 hours ago

Google Fires More Staff Over Israel Protest

Another 20 staff have been fired by Google over Israel protest and their “completely unacceptable…

20 hours ago

Australian PM Hits Out At Elon Musk Over Knife Attack Video

Censorship row brewing down under, after the Australian Prime Minister calls Elon Musk an 'arrogant…

21 hours ago

US SEC Seeks $5.3 Billion Fine From Terra’s Do Kwon

Financial regulator asks New York judge to impose $5.3 billion in fines against Terraform Labs…

21 hours ago