Kaspersky Lab has uncovered a scheme using a greeting card Web site to specifically target financial information from customers of a Mexican bank. The spam was first identified by Kaspersky Lab on the morning of February 19 in the form of <A HREF="http://www.kaspersky.com/">a Trojan masked to look like a standard greeting card email.</A> When recipients of the fake card click on the link, a malicious file is downloaded on to their computer.
Once this malicious file is launched, it modifies DNS entries on the user's computer, so that if they attempt to access the Mexican Banamex banking site through standard addresses like www.banamex.com, they will actually be redirected to a remote malicious user's site--and of course, if they enter their banking details on that site when prompted, their data will end up in the hands of the bad guys.