O.J. Simpson guilty verdict could lead to malicious spam

06.10.2008
Users should be on guard for spam touting the guilty verdict of former professional football star O.J. Simpson, a security company warned Monday.

"Anytime there's a big news story, spammers latch on to it to get people to click on a link and download their malware," said , vice president of information security at

Although MX Logic has not yet spotted any Simpson-related spam, Masiello said that company researchers have found evidence of an impending campaign. "We've seen poisoned search results on ['s] Live Search that lead to some Live Spaces hosting fake video codecs," said Masiello. The tactic, dubbed "search engine poisoning," is frequently used alongside malware spam.

Hackers try to dupe search engines into ranking malicious sites at or near the top of the results list by flooding blogs and message boards with bogus entries added by automated bots. "They'll use anything they can to pump up the search engine results," said Masiello.

The most likely Simpson spam strategy would resemble the that lured users to malware-hosting sites by promising video clips from the and channels, Masiello said. At the time, criminals tricked people into downloading attack code by telling them that the file was a codec required to play the video.

"Based on the results we've already seen, I think [a spam campaign] is pretty imminent, and very likely," Masiello added.