MySpace
Malicious MySpace profiles are hosting a new malware attack

MySpace page pushes fake Microsoft update

Dodgy profile hosting 'malware cocktail'

Written by Shaun Nichols in California

A bogus profile on MySpace is being used to push a new malware attack.

Researchers at McAfee found malicious pages on the social networking site which spawn pop-up windows attempting to spoof Microsoft's automatic update service.

The pop-up tells the user that an official update, identified as 'updateKB890830.exe', is ready to be installed.

The attacker has further tried to confuse users by using a URL which includes 'winxpupdate.microsoft' in the address.

A McAfee spokesperson told vnunet.com that the software is "a true malware cocktail".

A remote-control tool and several Trojan programs attempt to download other malicious packages. The various downloads have been traced to servers in China, Malaysia and Ukraine.

McAfee said that the malicious profiles were still active on Friday afternoon, and that MySpace and Microsoft had been notified of the incident.

The security firm recommends users not to accept friend requests from unknown parties, and to avoid visiting suspicious profiles.

This is not the first worm to spread via MySpace. In late 2006 a flaw in QuickTime was used to launch a phishing attack which altered user profiles and hijacked friend lists.

Tags:

Further reading

Cambridge admissions tutor checks Facebook

'Discreetly' checking up on new applicants   More...

Police subpoena MySpace over Meier suicide

Wire fraud laws may have been broken   More...

Cyber-gangs gear up for 2008

Let's be careful out there   More...

Facebook backs down on Beacon plans

Service won't tell your friends what you buy   More...

Related articles

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware   More...

Malware writers exploit Bhutto killing

Hackers use assassination to push Trojans   More...

Cyber-crooks target chat platforms

Unique threats soar in 2007   More...

Spammers deliver bogus invoices

Beware phony package receipts   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement