A variation of spam is sliding past spam filters into inboxes. The messages, urging recipients to buy shares, have an MP3 audio attachment but no subject line or text.
"I think this is the first time we've seen this," said John Graham-Cumming, an antispam consultant and researcher, who tracks new kinds of spam.
The audio messages, which vary in length, contain a warbled, robotic voice with a British accent encouraging people to invest in Exit Only, a company that owns a Web site, www.Text4Cars.com. That site connects vehicle buyers and sells through SMS (Short Message Service). Exit Only says it's not involved in sending the spam.
Graham-Cumming said the spam falls into the category of "pump-and-dump" fraud. Scammers invest in a company with a low-priced stock and send out a round of spam, causing gullible investors to buy it and increase the stock's price.
As the stock price peaks, fraudsters cash out, which causes the stock to precipitously fall, burning other investors. The practice is illegal.
Exit Only was trading around $0.41 (20p) on 18 October. Not much detail is available on the company, but it issued a news release on Tuesday heralding the launch of its Text4Cars service in the Los Angeles area. The news release said the company hoped to be fully launched in the western part of the US in early 2008.
Exit Only's CEO, David Dion, said he learned of the spam around Wednesday morning. He has since notified the US. Securities and Exchange Commission and said his company has nothing to do with the spam run.
"I am very distraught by this," Dion said, adding that so far few people had been taken in by the scam
There are a variety of defences e-mail administrators and security companies can employ to stop this sort of spam, Graham-Cumming said.
Spam filters can be configured to cull messages with MP3s, since most companies don't have a business use for the file type, Graham-Cumming said. Administrators can also change their e-mail server settings to slow down the speed at which they receive messages with MP3 attachments, he said.
That method has been proven to frustrate spammers, who typically shut down the connection if the spam isn't going through quickly enough since the delay consumes valuable bandwidth.
E-mail security company MessageLabs said it was catching about 10,000 spam messages with MP3s per hour in the second half of this week.