Chunkylover53 is away.. and Homer is back with a botnet

A malware spreading through AIM network using as screen name “Chunkylover53″, which was the username registered by one of the writers of “The Simpsons” episodes, is infecting Simpsons fans.. In one of the old episodes “Chunkylover53@aol.com” was Homer’s e-mail address, many of the fans added the username to their AIM contact lists. The writer who registered this account also was answering e-mails from fans.. Now, after long inactivity “Homer” is back with an away message linking to the “new internet-only exclusive Simpson’s episode”, yeah right.. The so called “new episode” is actually a file called Kimya.exe detected as a trojan. Running it will set you up with a couple of uninvited guests, a rootkit, some files related to a new Chinese infection, your PC will fall victim to a botnet of Turkish origin.

The “Homer” person spreading this infection, has already changed the away message a couple of times. The last message also advertises a link to a dating website, just in case you want to get laid..

There is an interesting write up with more detailed info at FaceTime Security Labs Blog

altiparmaks@gmail.com

One Response to “Chunkylover53 is away.. and Homer is back with a botnet”

  1. Maggie Says:

    Thank you, Snowhite14

    You saved my day :-)

    I was about to open it, when i got suspicious and started looking around,
    and ended up here.
    I immediately deleted the pdf file.

Leave a Reply