• On UrbanBaby: Is it OK to breastfeed in public?
The Download Blog
advertisement
May 10, 2007 5:26 PM PDT

Yahoo 360's gone phishin'

by Jessica Dolcourt
  • Font size
  • Print
  • 2 comments

A new phishing scam is circulating through Yahoo IM lists, sending emoticon-laden links to contacts on an infected account. Indeed, CNET's own Yahoo Messenger users have not been immune.

Dangerous phishing link

Phishing link sent through Yahoo IM.

(Credit: CNET Networks)

The link reads as a Geocities.com URL, but spoofs a Web page advertising Yahoo 360, a social-networking service.

Spoofed Yahoo 360 langing

Spoofed landing page for rigged Yahoo 360 service.

(Credit: CNET Networks)

Phishing schemes simulate legitimate Web sites to trap users into giving up their account information. With that information harvested, security fraudsters can sell your passcodes or exploit them directly by breaking into your bank or personal account. From there, the possibilities for fraud are varied.

While many phishing schemes are poor approximations of the real deal, with sketchy graphics and spelling and grammar errors, this Yahoo 360 spoof is more believable. Moreover, spoofs are successful when users follow the automatic reflex to sign-in to their account, or buy into the sense of urgency and doubt created by a doomsday phishing e-mail, for example, that the victim's account is about to expire.

Yahoo 360 home page

Legitimate home page for Yahoo 360.

(Credit: CNET Networks)

Social conditioning may also play a role in the success of IM phishing for contacts who are accustomed to click links sent by their colleagues and friends. While CNET has extensively covered e-mail phishing on CNET Download.com, CNET News.com, and on CNET Security, IM phishing is a newer approach to illegal data harvesting, and perhaps one that many users don't regularly question.

So keep those senses sharp, and make sure your PC is fully patched.

Jessica Dolcourt reviews the latest and greatest smartphone apps, in addition to a healthy dose of Windows software. E-mail Jessica and follow her on Twitter.
Recent posts from The Download Blog
Apple updates Safari for security
Google plans Chrome Mac beta for December
Mozilla releases second Firefox 3.6 beta
Google cuts Picasa photo storage prices
Is Mozilla's contributions program working?
Panda's Cloud Antivirus leaves beta behind
Sneak peek: Xobni e-mail app for BlackBerry
Louvre iPhone app: Quelle horreur!
Add a Comment (Log in or register)
Phishing on Yahoo IM
by happygirlt June 23, 2007 3:06 PM PDT
This phish is not only sending people to 360 but also to a site that says look at my pic. It will hit you with a trojan horse when you think you are just going to see a pic of a friend.
Reply to this comment
Yahoo Messenger Menace
by cactusbud July 16, 2007 11:49 PM PDT
It is pretty surprising that almost everybody is aware of this Mal Ware. I was infected by it before even though I already have Norton Internet Security Suite installed on my PC.

Unfortunately, I am not aware if anybody (especially Yahoo Inc.) is doing anything to rectify this problem?
Reply to this comment

Search Download Blog posts

About The Download Blog

Download.com editors cover the world of downloadable software and beyond.

Add this feed to your online news reader

The Download Blog topics