Sophos has added a new blog entry a few days ago about a video malware campaign that targets CNN breaking news service subscribers.

The email shows the top 10 stories and the top 10 videos, divided by a vertical line. If a user clicks on a link, the email will redirect him or her to a a compromised website. The website will ask the user to update their flash player. When a user agree to do this, he or she will receive a trojan called Mal/EncPK-DA.

The blog entry includes a screen shot of the email and an embedded Youtube video that demonstrates the campaign.

Source: Sophos