Language Selection

English French German Italian Portuguese Spanish

Phishing Scam Targets Windows Update

Filed under
Microsoft
Security

A phishing scam emulating the Windows Update Service hit Australia yesterday, designed to not only emulate the update page perfectly, but circumvent current antivirus, spyware and adware programs.

The spam e-mail directs users to a page that pulls graphics from the Microsoft.com Web site and then recreates the page asking users to download a Windows update that is actually a malicious .exe file.

Director of SurfControl, Charles Heunemann, said the company discovered the virus late last night and that current heuristics and signatures used by core antivirus vendors are not picking up the malicious code.

"We are still trying to get to the bottom of it," Heunemann said.

"It is not a malicious attack for network resources but appears to send a message to the Internet advertising itself as a zombie machine - we think the .exe file pulls other code to turn the machine into a spamming server.

"The actual e-mail looks like a Microsoft e-mail but I don't think it is the practice for Microsoft to ask users to update their operating system by launching a link from an e-mail."

The virus, titled Wupdate-20050401, installs an executable file into the Windows directory and adds a startup service. When it is running the program takes up 100 percent of the CPU power, controlling the CPU by forcing it to perform continuous processes.

Microsoft security product manager Ben English said this is just one of many scams they are currently monitoring, adding that it is not unique.

"There are effective defences against these types of scams and we advise users to follow some simple guidelines," English said.

"Microsoft is aware of the SurfControl notice regarding the spoofing scam of Windows update and our advice to customers remains the same.

"Microsoft never attaches software updates to our security e-mail notifications; we never send notices about security updates or incidents until after we publish information about them on our Web site and if you suspect that an e-mail message is not legitimate, do not click any hyperlinks within it."

Sophos' Asia Pacific head of technology, Paul Ducklin, was aware of the program in question and said despite all the technology in the world, education and informed decisions by users will always be the best resort to stopping malware.

"Even if all other defences are down, with Trojan malware if a person doesn't click on it, it won't work - they all involve, to some extent, collaboration with users," Ducklin said.

"Three ways to block them include having software to prevent a suspicious program, using programs at the gateway to block .exe files and of course user education and information."

More in Tux Machines

today's leftovers

  • Comic-Con and FOSS Comic Book Solutions
    After whetting his appetite at this year’s Comic-Con, our resident Linux newbie discovers free and open source apps for reading digital comics, as well as a treasure trove of available sources for free comics online.
  • Linux Kernel 3.12.62 LTS Improves SPARC Support, Updates the Networking Stack
    Linux kernel developer Jiri Slaby announced the release of the sixty-second maintenance update for the long-term supported Linux 3.12 kernel series, which will receive support until 2017 because of SUSE Enterprise Linux. Linux kernel 3.12.62 LTS is a modest update, and looking at the diff from the previous maintenance release, version 3.12.61, we can notice that it changes a total of 96 files, with 1213 insertions and 1053 deletions. Among the changes, we can notice lots of fixes for the SPARC hardware architecture, but there are various other improvements for the ARM, MIPS, PA-RISC, and x86 instruction set architectures.
  • ‘Anatine’ Is a Simple Desktop Twitter App for Linux
    Anatine describes itself as a 'pristine Twitter app for Linux', but is it anything more than a wrapper around the mobile website?
  • Skype for Linux Alpha 1.3 Released With Small Bug Fixes
    A small bug fix update to Skype for Linux alpha is now available, and fixes, among many changes, errant close to tray behaviour on the Cinnamon desktop.
  • On the killing of intltool
    Say thanks to Daiki Ueno for his work maintaining gettext and enhancing it to make change practical, and to Javier Jardon for pushing this within GNOME and working to remove intltool from important GNOME modules.
  • On discoverability
    I've discussed elsewhere that usability is about real people doing real tasks in a reasonable amount of time. Some researchers also refer to "learnability" and "memorability" to define usability—this is very similar to discoverability. Can you discover the features of the system just by poking at it? Is the user interface obvious enough that you can figure it out on your own?
  • This is Lubuntu 16.10’s New Default Wallpaper
    The default wallpaper of Lubuntu 16.10 — yes, that's Lubuntu, with an 'l' — has been unveiled — but will fans of the lightweight Ubuntu spin like it?

today's howtos

Red Hat and Fedora

Android Leftovers