Fake CNN News Alerts Spreading Malware
August 12, 2008

Fake CNN e-mail alerts are circulating extensively around the Internet. Several varieties of the message have been reported and the From address is usually not CNN. These realistic looking HTML based e-mail messages appear legitimate, although in some cases the headlines have been sensationalized. The Subject line may be "CNN Alerts: My Custom Alert" or "CNN.com Daily Top 10". These messages contain URL's that launch a Popup asking the user to "get the latest version of Flash" to view the videos - something users may have encountered in the past with legitimate Flash upgrades. Our Ironmail system is blocking many of these messages but some of the messages are getting through. Ironmail is marking most of the ones that get through as SPAM 3 or 4 and they may end up in your Junk Folder. Regardless, these messages should be avoided. The web links contained in these messages try to get you to download a file named get_flash_update.exe. Don't do it. When in doubt go directly to the CNN website rather than trusting the legitimacy of an URL embedded in an e-mail message. Also, when clicking links on a web site, move your cursor over the link. In the bottom left panel you will see the linked web address. If this link does not look right to you, don't go there!


Return to IT News Archives