Simple clear advice in plain English

Spammers hijack websites to peddle pills

Counterfeit drugs warning to online shoppers using legitimate pharmaceutical stores

Pill peddlers are hijacking legitimate websites to send spam in order to fool consumers into buying fake pharmaceutical products online.

According to security firm Sophos, spam campaigns that advertise internet pharmacies are directing users to web pages hosted on legitimate websites that have been compromised by the spammers.

Once the victim has been lured to the site, the pages automatically redirect surfers to a fake online store.

The dangers of buying medicines this way was highlighted last month by the Canadian authorities after a 57-year-old woman died after purchasing pills through an online source. Marcia Bergeron who lived on Quadra Island in British Columbia apparently died of poisoning.

Vancouver Island regional coroner Rose Stanton said the toxicology report showed the anti-anxiety medication and sedative she had bought were laced with dangerous mineral traces.

"The pills had traces of uranium, strontium, selenium, aluminum, arsenic, barium and boron," said Stanton.

While these current spam attacks are not new, it is becoming harder to filter the spam messages and track the original source. Consumers' anti-spam software will often use the links in an email to determine whether the message is spam.

If someone gets frequent emails from favourite websites, because these appear frequently in their inbox, if that website were to be hacked then any spam sent from there is almost certain to get through.

This is because their spam filters do not recognise the emails as spam because the source web address is legitimate.

Graham Cluley, senior technology consultant at Sophos, said people are tricked into clicking on the link in the spam email because the web address is genuine. He pointed out the website owner is probably completely unaware that spammers have hacked their site, and are using it to redirect visitors to an online pharmacy.

"Website owners have a duty to properly patch their sites against the latest vulnerabilities, or face being exploited by spammers," said Cluley.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

screen-shot-2009-12-10-at-14

Users of porn site left exposed as names are published online

Sophos suggests password change after popular site is "caught with its pants down"

malware

Sophos warns fake Adobe upgrade contains Zeus Trojan

Attached ZIP file in emails could con people into downloading banking Trojan

Google Plus

Sophos warns spammers are sending out fake Google+ invites

First Google Plus-related scam identified by security company Sophos

Question & Answer

Q.Why are some of the keys on my keyboard doing strange...

> Read the answer

Q.Is my phone’s Bluetooth any use?

> Read the answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Best deals on the web

img

Apple iMac 21.5" (MC309)

£926.40- Buy it now

img

Dell Inspiron 620 ST Intel Core i3-2100 3.10GHz / 3GB / 500GB / DVDRW / Win 7 Home Premium

£329.00- Buy it now

img

ZooStorm 7877-1023

£386.38- Buy it now

Latest issue & subscription deals

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

CAD

Computer Aided Design. Software used to create 3D models.

Great shopping deals from Computeractive