Bogus Microsoft security bulletin hides Trojan

Malware writers use Redmond to spread malware

Written by Iain Thomson

Experts are warning of a bogus Microsoft security bulletin that contains malware designed to take control of the user's PC.

The emails contain the header 'Microsoft Security Bulletin MS07-0065' and come with Microsoft logos and a layout very similar to the Microsoft web page.

Recipients are told that a zero-day flaw in Outlook has already been exploited to infect over 100,000 machines, and the email contains a link to the 'patch' for the problem.

"Security bulletins from Microsoft describing vulnerabilities in its software are a common occurrence, so it comes as no surprise to see hackers adopting this kind of disguise in their attempt to infect Windows PCs," said Graham Cluley, senior technology consultant at Sophos.

"The irony is that, as awareness of computer security issues and the need for patching against vulnerabilities have risen, social engineering tricks which pose as critical software fixes are likely to succeed in conning the public."

The link in fact downloads the Behav-112 Trojan, which allows the computer to be operated remotely to send spam or take part in distributed denial-of-service attacks.

The emails have been widely spammed out over the past few days.

Tags:

Further reading

Virus writers target Windows Powershell scripting language

Yet another point of caution, researchers warn   More...

New worm targets virus researchers

Malware takes aim at research community   More...

Malware writers turn to zero-hour viruses

Small stealthy attacks flying under the corporate radar   More...

Hackers turn to PowerPoint for virus infection

Slack patching leaves application open   More...

Related articles

Halloween 'skeleton' spam hides Storm Trojan

Don't let your PC be turned into a zombie   More...

Hacker spam poses as old school friend

Blonde with pigtails infects the curious with a Trojan   More...

Spammers exploit tragedies in China and Burma

Beware emails asking for donations   More...

Spammers announce World War III

Latest scam offers 'video' of US troops invading Iran   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement