Facebook porn chicks and Skype payment spam

Yesterday I blogged about a widespread spam campaign that posed as a message to “Reset your Facebook password”, but was really designed to redirect you to a Canadian pharmacy website instead. En route you can also be hit by an exploit which attempts to load a booby-trapped PDF and slap you with an infected EXE file via some Java exploits.

Today it looks like the same gang have changed their disguise, spamming out many messages with the subject line “Problem with your payment” pretending to come from [email protected].

Clearly the “from” address has been forged, as is common with spam messages, and your suspicions should be aroused by the fact that there is no text in the body of the message but just an attachment called Skype.html.

Skype payment spam

Sign up to our free newsletter.
Security news, advice, and tips.

Sophos detects the attachment as Troj/JSRedir-BO, meaning that your browser won’t be redirected to a third-party site as the cybercriminals would wish.

Skype spam messages

Although the vast majority of the spam messages we have seen in this campaign today have used the Skype disguise, I also stumbled across this example which pretends to be an X-rated Facebook message about “porn chicks” teaching a “rookie” about something to do with chickens:

Porn chicks message from Facebook

Again, we detect the facebook.html file attachment as Troj/JSRedir-BO.

It’s probably a sad reflection on society that there are many people on the internet who wouldn’t think twice of opening a file attached to an email with that subject line.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and is the co-host of the popular "Smashing Security" podcast. Follow him on Twitter, Mastodon, Threads, Bluesky, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.