ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Blackhole malware spreading as Traffic Ticket Spam

Paul by Paul
July 26, 2012
in Malware
Reading Time: 2 mins read
blackhole exploit kit
Share on FacebookShare on Twitter

 blackhole exploit kit

Don’t be too quick to believe that the New York State police are charging you with a traffic offence – that email you just opened in your inbox could actually be an attempt to infect your computer.

The team at SophosLabs have been intercepting a malicious spam campaign today which tries to trick the recipient into believing that they were caught speeding.

Here’s what a typical email used in the attack looks like:

Traffic ticket malware spammed out

Subject: NYC Traffic Ticket [id number]

Message body:

New York State * Department of Motor Vehicles
UNIFORM TRAFFIC TICKET

NEW YORK STATE POLICE * POLICE AGENCY

Local Police Code

THE PERSON DESCRIBED ABOVE IS CHARGED AS FOLLOWS

Time: 7:18 AM
Date of Offense: 09/12/2011

IN VIOLATION OF
NYS V AND T LAW DESCRIPTION OF VIOLATION:
SPEED OVER 55 ZONE
TO PLEAD, PRINT CLICK HERE AND FILL OUT THE FORM

Of course, if you have your head on straight you might ask yourself how the New York police could possibly have your email address (or at least how they would have connected it to your car). Or you might realise that the message is clearly spam as you weren’t anywhere near New York on the day in question.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

But plenty of people won’t have their head on straight, and – in their fluster – might click on the link without thinking. That’s what the cybercriminals are banking on.

Malware authors have used a very similar disguise in the past, tricking users into opening a dangerous attachment.

On this occasion, however, there is no attachment. Instead, a link takes users to a website playing host to the Blackhole exploit kit – within seconds visiting computers can be infected via Adobe Flash and PDF exploits, detected by Sophos products as Troj/SWFExp-AI and Troj/PDFEx-GD.

We’ve certainly seen lots of attacks involving the Blackhole exploit kit lately, including rejected wire transfer notifications and fake Facebook photo tag notifications.

Keep your anti-virus software up-to-date, your operating system and applications patched, and – essentially – your wits about you.

Source: http://nakedsecurity.sophos.com/2012/07/25/nyc-traffic-ticket-spam-is-really-blackhole-malware-attack/

Tags: blackholeemailmalwarenewspamspreading
Previous Post

Trojan Dropper Creates Backdoor on Macs and Survives Reboots

Next Post

Demonoid hit by massive DDoS attack

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024
Please login to join discussion

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.