Advanced Spam Sent via PHP Tool Hosted on Compromised Web Servers
Traditional Web hackers are increasingly landing their services to spammers by allowing them to run advanced mass mailing tools from the compromised servers.
Such a specialized Web-based application was located by security researchers from antivirus vendor Kaspersky Lab on hacked servers in Brazil, a country where spam and phishing are amongst the top cybercriminal activities.
"During my daily analysis, I found an interesting shell for mass mailing. The code shows it was developed locally in Brazil," Dmitry Bestuzhev, a Kaspersky Lab expert, writes. "By editing the original PHP code, the criminal can fake the 'original headers' of the messages they send," he explains.