MySpace
Malicious MySpace profiles are hosting a new malware attack

MySpace page pushes fake Microsoft update

Dodgy profile hosting 'malware cocktail'

Written by Shaun Nichols in California

A bogus profile on MySpace is being used to push a new malware attack.

Researchers at McAfee found malicious pages on the social networking site which spawn pop-up windows attempting to spoof Microsoft's automatic update service.

The pop-up tells the user that an official update, identified as 'updateKB890830.exe', is ready to be installed.

The attacker has further tried to confuse users by using a URL which includes 'winxpupdate.microsoft' in the address.

A McAfee spokesperson told vnunet.com that the software is "a true malware cocktail".

A remote-control tool and several Trojan programs attempt to download other malicious packages. The various downloads have been traced to servers in China, Malaysia and Ukraine.

McAfee said that the malicious profiles were still active on Friday afternoon, and that MySpace and Microsoft had been notified of the incident.

The security firm recommends users not to accept friend requests from unknown parties, and to avoid visiting suspicious profiles.

This is not the first worm to spread via MySpace. In late 2006 a flaw in QuickTime was used to launch a phishing attack which altered user profiles and hijacked friend lists.

Tags:

Further reading

Cambridge admissions tutor checks Facebook

'Discreetly' checking up on new applicants   More...

Police subpoena MySpace over Meier suicide

Wire fraud laws may have been broken   More...

Cyber-gangs gear up for 2008

Let's be careful out there   More...

Facebook backs down on Beacon plans

Service won't tell your friends what you buy   More...

Related articles

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware   More...

Malware writers exploit Bhutto killing

Hackers use assassination to push Trojans   More...

Cyber-crooks target chat platforms

Unique threats soar in 2007   More...

Hackers hit US stockbroker TD Ameritrade

Spam investigation uncovers database breach   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

08 Jul 2008

3.67 MBSafe browsing, voice recognition and cyber-criminals More...

07 Jul 2008

2.76 MBLaptops on holiday, gaming in Vietnam and 'unbreakable' encryption More...

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Firefox

Firefox users shown to be safer

Internet Explorer users the worst of the bunch   More...

Internet Corporation for Assigned Names and Numbers

Icann downplays recent site hacks

Redirects were 'limited', says organisation   More...

Advertisement

DNA

Boffins build artificial DNA

Could be used in the ultimate computer   More...

Microsoft

Microsoft outlines appeal against EU fine

Two sides back in court   More...

Advertisement