Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Yahoo Mail Worm/Virus?

This morning my Yahoo mail account sent out a series of Spam emails to random people from my address list. No one was logged into the account at the time this happened. My wife and I routinely access the account from a PC running Norton 360 and from two different Macs. So we're fairly confident none of these computers are infected with anything. I called AT&T/Yahoo tech support, and they indicated that the account appears to have been hacked by some sort of bot... and they thought the issue may be with my iPhone and the fact that it has no antivirus protection.

I took a look at the full headers of the Spam emails and was able to track the originating IP address to Sunnyvale, CA (Yahoo's headquarters). I then compared this with old emails sent from both my home PC and my iPhone. Only the iPhone generated emails went through the Sunnyvale IPs. The emails sent from all three computers on my home network originated from local IPs.

So, bottom line... this leads me to believe that it was indeed my iPhone that somehow triggered the emails. I was driving at the time the emails were sent... so I know I didn't click anything, open any emails, or take any other actions that would have triggered the Spam.

Any idea what's going on here? Should I be concerned that my iPhone has a worm or virus that is triggering these messages? I'm particularly trying to determine if this is just a worm or if an actual person has hacked my account. I changed the password... but that password was also used for some other accounts of mine too. My biggest concern at this point is the potential for identity theft.

iPhone 3Gs

Posted on Mar 5, 2010 4:04 PM

Reply
17 replies

Mar 16, 2010 3:39 PM in response to Scott614

(Not an iPhone problem:)

I don't believe it is necessary for your Yahoo! Mail account to be hacked. I believe the way this "infection" works is you click on a url in an email (bad) and some kind of script is immediately run (not downloaded) which harvests your Yahoo mail contacts -- accessible because you are, after all, logged into Yahoo! Mail -- and forwards those to the hackers for later use -- at their convenience. Nothing left behind on your computer for virus-checkers to detect, and no need for hackers to log into your Yahoo account to subsequently send the spam (simple email spoofing).

What only the Yahoo! mail engineers and the hackers know is how that script works -- and apparently Yahoo isn't talking...

Variations of this have hit both my wife and I. I actualy recall the moment I accidently clicked the email's url while I was trying to move the IE browser window on a laggy computer. In my case, my contact list was also deleted (easily recovered via Yahoo! mail settings). We were only made aware of the problems via the returned mail messages. Fortunately, there seems to have been only a single wave of spammings in our names...

Yahoo Mail Worm/Virus?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.