MySpace
Malicious MySpace profiles are hosting a new malware attack

MySpace page pushes fake Microsoft update

Dodgy profile hosting 'malware cocktail'

Written by Shaun Nichols in California

A bogus profile on MySpace is being used to push a new malware attack.

Researchers at McAfee found malicious pages on the social networking site which spawn pop-up windows attempting to spoof Microsoft's automatic update service.

The pop-up tells the user that an official update, identified as 'updateKB890830.exe', is ready to be installed.

The attacker has further tried to confuse users by using a URL which includes 'winxpupdate.microsoft' in the address.

A McAfee spokesperson told vnunet.com that the software is "a true malware cocktail".

A remote-control tool and several Trojan programs attempt to download other malicious packages. The various downloads have been traced to servers in China, Malaysia and Ukraine.

McAfee said that the malicious profiles were still active on Friday afternoon, and that MySpace and Microsoft had been notified of the incident.

The security firm recommends users not to accept friend requests from unknown parties, and to avoid visiting suspicious profiles.

This is not the first worm to spread via MySpace. In late 2006 a flaw in QuickTime was used to launch a phishing attack which altered user profiles and hijacked friend lists.

See also:

reader comments

related articles

Cambridge admissions tutor checks Facebook

'Discreetly' checking up on new applicants 11 Jan 2008

 

Police subpoena MySpace over Meier suicide

Wire fraud laws may have been broken 10 Jan 2008

Cyber-gangs gear up for 2008

Let's be careful out there 24 Dec 2007

Facebook backs down on Beacon plans

Service won't tell your friends what you buy 03 Dec 2007

Facebook flooded with fake profiles

Spammers and malware writers exploiting site to infect users 07 Oct 2008

Spammers deliver bogus invoices

Beware phoney package receipts 28 Jul 2008

Malware writers go for your gold during the Olympics

Attacks exploit news, target organisations 07 Aug 2008

latest news

Ingram loses commercial director

Bhavesh Patel set to leave at the end of the month 09 Jan 2009

Ramesys plays IT sheriff of Nottingham

Reseller secures first contract under Primary Capital Programme 09 Jan 2009

Acquisitive Acraman snaps up Ipitomi

Buy-and-build model alive and well as private equity-backed Acraman adds voice specialist Ipitomi to VAR portfolio 09 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation