Trojan moves to use Hotmail, Gmail as spam hosts

Bitdefender, a provider of antivirus software and data security solutions in Romania, announced that a joint effort between the Bitdefender and Yahoo security teams have stymied the criminals behind Trojan.Spammer.HotLan to generate and use Yahoo accounts to send spam.

However, the malware authors have switched to generating Hotmail and Gmail accounts to send their spam, apparently having found a way of bypassing the captcha systems of the two webmail providers.

The captchas are supposed to ensure that it is humans, not computers trying to create the account, in an effort to stem exactly this kind of service abuse.

Every active copy of the HotLan trojan tries to create an account, sending off the captcha image in an encrypted form to a spammer-controlled website, wherefrom a solution is sent back to it and entered in the appropriate field. Then, the trojan pulls encrypted spam e-mails from another website, decrypts them and sends them to (presumably valid) addresses taken from yet another website.

(Source: Digital Media Europe)