::Trend Micro Threat Resource Center::

15 April 2010

Phishers Send Out Standard Chartered Spam

TrendLabsSM recently encountered a phishing email specifically targeting Standard Chartered Bank clients. The spammed message instructs recipients to log in to their online accounts and to visit the Secure Messages section to read a specific message. The email body includes an embedded link, which when clicked leads to a phishing page.

Sample spam email:

Phishing page:

The use of bogus login pages has become a typical attack vector that phishers continue to use. Similar phishing attacks via spammed messages have been documented here in the Malware Blog:

While this is an old trick, clients who visit the page may still unwittingly provide their bank credentials to cybercriminals’ waiting hands. Users are then advised to constantly exercise caution when opening email messages and when clicking embedded links. Standard Chartered Bank likewise reminds its clients to be wary of the reality of online threats, including phishing attacks.

Remember, when accessing you online banking account, never follow links from an email. Type in the address of you bank directly into the browser's address bar and go on from there.

And, if you get an email that supposedly comes from your bank, it's best to check on their official website for information about the issue or to call them directly.