Experts at SophosLabs have warned of a new spam campaign that claims to offer free explicit images and videos, in an attempt to trick users into downloading a malicious Trojan horse. According to Sophos, a weblink to the Psyme-DL Trojan is being widely circulated within emails using a variety of subject lines, invariably containing the words 'free' and 'porn'.

The emails each contain a single sentence and a link to the malicious file. When clicked on, users are given a list of free content to choose from, while the Trojan attempts to download itself onto their machines. Sophos experts note that Psyme-DL exploits a Microsoft Internet Explorer vulnerability, MS06-014, and when the weblink is accessed using Firefox, a message is displayed requesting the user to change browser.

HackInTheBox