Janne Ahlberg and Graham Cluley have reported on the latest round of diet drug spam being advertised on sites like Twitter, Facebook, Pinterest, and Tumblr.
Sites involved with this spam campaign purport to be Women's Health
Magazine's site and use deceptive subdomains. The sites falsely imply endorsement by Dr.
Oz by auto-playing a video segment from his television show about "garcinia cambogia extract."
The following domains have been advertised via spam bots and hacked accounts. Note that these links lead to the Web of Trust report for each site, and that some of these domains have been blacklisted by SURBL.
https://www.mywot.com/en/scorecard/cnbc.com-ar2.info (added 29 June 2013)
https://www.mywot.com/en/scorecard/com-indexrx.us (added 29 June 2013)
https://www.mywot.com/en/scorecard/com-mo.com (added 29 June 2013)
Never attempt to buy products from spam-advertised sites. You wouldn't entrust your credit card information to a shady drug dealer on the street; spam sites are the online equivalent.
You may notice this spam campaign's use of the uncommon ".pw" top-level domain. Registration of .pw domains opened to the general public three months ago. According to Wikipedia, .pw was originally intended for sites from the island nation of Palau, and it is currently being branded as short for "Professional Web."
Please refer to Janne's article for further updates as this spam campaign continues.
Janne has also written a separate article about how he believes user accounts may have been hijacked (through phishing sites hosted on the same domains).
See also other articles I've written on the topic of spam, including an article about weight loss drug spam e-mails and an article about fake CNBC news sites spamvertized on Twitter.
For more from the JoshMeister on Security, please subscribe via e-mail or RSS, or follow me on Twitter or Google+.
Backdoors Found in Sony’s IP Cameras - Security researchers have discovered that a number of 80 Sony IP camera models come with backdoors that could be used by attackers to spy on users or laun...
51 minutes ago