Sophos has warned of a Trojan horse that has been spammed out in an email claiming to come from an organization fighting child pornography on the web.
The emails claim that the recipient's email address has been found in a child porn database discovered by the Association of Sites Advocating Child Protection (ASACP), but really contain a Trojan horse.
The Troj/Agent-CPK Trojan horse has been spammed out in the email messages, with the subject line "CP investigation was started."
Part of the email reads:
I'd like to inform you that investigating activity of the one of child porno sites; we found e-mails data base, in which was your e-mail
Attached to the email is a file called asset576.zip, which unzips to a file called asset.txt
"The danger is that people may panic when they think their email address was found on a child abuse website, rush to open the attached file and become infected by a malicious Trojan horse," said Graham Cluley, senior technology consultant for Sophos. "The ASACP are an entirely innocently party in this attack, it is simply their name which is being spoofed by the hackers in their attempt to infect innocent computer users."
The ASACP, who have described the incident as a "massive spoof email attack", has published a warning on its website, informing unfortunate recipients of the message that they may be at risk of infection.
