X-Labs
May 6, 2010

Buying iTunes Gift Certificate Malware Spam

Tim Xia

Websense® Security Labs™ ThreatSeeker™ Network has discovered that a "Thank you for buying iTunes Gift Certificate!" themed malware spam is spreading quickly over the Internet. It disguises itself as a notification from iTunes Store, asking users to open the attached malware to confirm the the certification code it claims to contain. So far, we have received over 300,000 copies of the scam in the latter part of this afternoon.

Screenshot of the spam:

Spam

The malware attached to the spam email message has been detected by some heuristic AV engines; however the detection rate is still very low.

Websense Messaging and Websense Web Security customers are protected against this attack.

About Forcepoint

Forcepoint is the leading user and data protection cybersecurity company, entrusted to safeguard organizations while driving digital transformation and growth. Our solutions adapt in real-time to how people interact with data, providing secure access while enabling employees to create value.