Security Experts:

Ongoing "Invoice" Attack Campaign Delivers Booby-trapped PDFs

An ongoing malicious email campaign is masquerading as an unpaid invoice, a Kaspersky Lab researcher said Thursday.

In this recurring campaign, cyber-criminals are sending out emails with a malicious PDF attachment masquerading as notices and reminders to pay overdue bills, Ben Godwood, a researcher with Kaspersky Lab, wrote on the SecureList blog on Thursday. The email campaign appears to have been ongoing since November, and follow a set schedule, hitting victim inboxes either on the 4th or the 21st of the month.

Kaspersky Lab detected the latest batch of specially crafted PDF messages on March 4, Godwood said. Most of the emails were sent from German IP addresses, and appear to have been sent from compromised home computers, Godwood said. The attack emails were mostly sent from German IP addresses in the latest iteration of the campaign, Godwood said, previous messages appear to have been sent from infected bots in other countries.

Kaspersky blocked "a large number of emails" with the filename including the word "invoice" on Feb. 21, Jan. 4, and Nov. 21, Godwood said. The messages originated from various countries, including South Africa, United States, Australia, and Japan, and the attack code attempted to download additional malware from servers in Germany, United Kingdom, Sweden, and Israel.

"Looking back through our past feedback data, we noticed similar patterns on the 4th and 21st of several months," Godwood said.

The attack code in the booby-trapped PDF document triggered an old vulnerability in the image library for Adobe Acrobat (CVE-2010-0188), Godwood found. The actual exploit was "not easy to spot" because it was buried under two layers of JavaScript, he said. Based on the image samples posted on the blog, it appears the actual attack code was hidden inside binary data. The second layer of JavaScript code looks very similar to the code in various samples created by BlackHole exploit kit last year, Godwood said.

When the victim opened the file, the attack code downloaded an executable file. The Trojan regularly communicates with a remote server after it installs itself.

If you receive an invoice on March 21 or April 4, be extra cautious, Godwood said. However, since the criminals can always change the dates they run the scam, "it's better to be cautious all the time," he said.

Subscribe to the SecurityWeek Email Briefing
view counter
Fahmida Y. Rashid is a Senior Contributing Writer for SecurityWeek. She has experience writing and reviewing security, core Internet infrastructure, open source, networking, and storage. Before setting out her journalism shingle, she spent nine years as a help-desk technician, software and Web application developer, network administrator, and technology consultant.