Feeds

Pump-and-dump scammers issue German prospectus

PDF ruse attempts to smuggle junk past spam filters

Website security in corporate America

The fraudsters behind pump-and-dump stock spams are trying a new technique in a bid to fool spam filters. Junk mails promoting worthless stocks seen this week are appearing with an attached PDF file.

Typically titled "German Stock Insider", these PDF files purport to offer insider tips and contain more detail than is generally the case in typical pump-and-dump scams, even going to the bother of adding logos and the like for added "authenticity".

They even contain a disclaimer to make them more closely resemble genuine stock prospectus guides. This disclaimer typically reads: "This is not an offer to buy or sell any security. German Stock Insider discloses that they were paid ten thousand Euros for distribution of this report."

Pump-and-dump scams are email campaigns that seek to encourage armchair investors to sink their cash into particular firms' stock.

The goal is to quickly inflate interest in low-value stock with bogus insider info in order to ramp up share prices and sell at a profit before the inevitable crash and burn. Meanwhile, those duped are left holding possibly worthless shares.

Most (but by no means all) of these scams are thought to take place without the knowledge of firms that are the subject of the scams.

According to net security firm Sophos, pump-and-dump stock campaigns account for approximately 25 per cent of all junk mail, up from 0.8 per cent in January 2005.

Content security firm Marshal, however, reckons the tactic is in decline after reaching its high-water mark in February. One in two junk mails scanned by the Australian firm in February involved pump-and-dump scams, a figure that nose-dived to just five per cent in June, according to Marshal's figures.

Earlier this year, the US Securities and Exchange Commission (SEC) suspended trading in 35 firms as a punishment after the companies were frequently referenced in pump-and-dump stock email campaigns. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.