Spammers Automatically Creating Hotmail And Yahoo Accounts - InformationWeek
IoT
IoT
Business & Finance
News
7/9/2007
06:06 PM
50%
50%

Spammers Automatically Creating Hotmail And Yahoo Accounts

BitDefender researchers found that spammers are easily bypassing the "captcha" security system and automatically setting up new e-mail accounts that are used to send out waves of spam.

Spammers have a new trick up their sleeves.

According to researchers at BitDefender Labs, spammers are automatically creating Yahoo and Hotmail accounts and using a Trojan to help them send waves of spam. The spammers, according to the security company, have figured out how to outwit the "captcha" security system. That's the one that won't allow a new e-mail account to be created until the creator correctly types in the twisted letters depicted in an image.

A piece of malware, Trojan.Spammer.HotLan.A, actually has been set up to access the e-mail accounts, pull down encrypted e-mails from another site, unencrypt them, and then send them to e-mail addresses stored in yet another Web site.

"They've found a way to bypass the captcha system by using optical character recognition," said Vitor Souza, a manager at BitDefender, in an interview. "The software reads the images and transforms it into text. Once it bypasses the captcha system, it enables them to automatically create the e-mail accounts."

Souza said the automatic system creates accounts extremely quickly.

"It's beyond what we've ever seen before," he said, adding that it can create 500 new e-mail accounts every hour and up to 15,000 a day. "With this kind of speed, they can send spam from thousands of different accounts, and that's a lot more resources for them."

Companies "have to look at this new threat," said Souza. "The captcha system has become a norm in the industry for setting up e-mails and different kinds of accounts. Responsible companies, like Yahoo and Hotmail, will have to find a way to fight this through more sophisticated security systems or they're going to have to find a new system all together."

The spam is set up to lure unsuspecting users to a site that advertises pharmacy products, BitDefender researchers said.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
2017 State of the Cloud Report
As the use of public cloud becomes a given, IT leaders must navigate the transition and advocate for management tools or architectures that allow them to realize the benefits they seek. Download this report to explore the issues and how to best leverage the cloud moving forward.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on InformationWeek.com for the week of November 6, 2016. We'll be talking with the InformationWeek.com editors and correspondents who brought you the top stories of the week to get the "story behind the story."
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll