Simple clear advice in plain English

Spammers hijack websites to peddle pills

Counterfeit drugs warning to online shoppers using legitimate pharmaceutical stores

Pill peddlers are hijacking legitimate websites to send spam in order to fool consumers into buying fake pharmaceutical products online.

According to security firm Sophos, spam campaigns that advertise internet pharmacies are directing users to web pages hosted on legitimate websites that have been compromised by the spammers.

Once the victim has been lured to the site, the pages automatically redirect surfers to a fake online store.

The dangers of buying medicines this way was highlighted last month by the Canadian authorities after a 57-year-old woman died after purchasing pills through an online source. Marcia Bergeron who lived on Quadra Island in British Columbia apparently died of poisoning.

Vancouver Island regional coroner Rose Stanton said the toxicology report showed the anti-anxiety medication and sedative she had bought were laced with dangerous mineral traces.

"The pills had traces of uranium, strontium, selenium, aluminum, arsenic, barium and boron," said Stanton.

While these current spam attacks are not new, it is becoming harder to filter the spam messages and track the original source. Consumers' anti-spam software will often use the links in an email to determine whether the message is spam.

If someone gets frequent emails from favourite websites, because these appear frequently in their inbox, if that website were to be hacked then any spam sent from there is almost certain to get through.

This is because their spam filters do not recognise the emails as spam because the source web address is legitimate.

Graham Cluley, senior technology consultant at Sophos, said people are tricked into clicking on the link in the spam email because the web address is genuine. He pointed out the website owner is probably completely unaware that spammers have hacked their site, and are using it to redirect visitors to an online pharmacy.

"Website owners have a duty to properly patch their sites against the latest vulnerabilities, or face being exploited by spammers," said Cluley.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

malware

Sophos warns fake Adobe upgrade contains Zeus Trojan

Attached ZIP file in emails could con people into downloading banking Trojan

Google Plus

Sophos warns spammers are sending out fake Google+ invites

First Google Plus-related scam identified by security company Sophos

PlayStation Network logo

Hackers put Playstation Network users' credit card details at risk

Sony has confirmed that credit card details may have been stolen by hackers

Question & Answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Q.How do I stop Windows 7 search?

> Read the answer

Q.How can I turn Autoplay back on?

> Read the answer

Best deals on the web

img

Apple MacBook Pro (MC724LL/A)

£999.99- Buy it now

img

Samsung 300E5A-A01DX

£449.99- Buy it now

img

Sony Vaio VPCF23P1E/B

£679.98- Buy it now

Great benefits for subscribers!

Most popular articles

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

CPU

Central Processing Unit. Another term for a computer processor.

Great shopping deals from Computeractive